The platform · Read-only on Azure · Available now

Govern the AI you run in Azure. Read-only, in your tenant.

AI Pulse discovers AI systems across your Azure tenant — including the ones nobody registered — risk-tiers them, maps them to 45 frameworks, and produces evidence you can hand to an auditor or a supervisor. In this configuration it observes and never writes. When you need it to stop things too, that is a layer you add — not a different product.

01The one promise

It observes. It never writes.

In read-only deployment AI Pulse runs with zero write permissions in your environment. Not “write access you can turn off”, not “least privilege in practice” — no write permissions exist to grant. The managed identity it uses is read-only by design, so the strongest guarantee we can give you is also the simplest to verify: there is nothing in the permission set that could change, move or delete anything in your tenant.

This is the product's foundation, and we will never dilute it. When you need a platform that can actively stop an agent, you deploy the enforcement layer — separately, and with the authority you explicitly grant it. Where it is not deployed, this stays read-only.

What “read-only” means here

  • Write permissionsNone exist
  • Data residencyYour tenant
  • DeploymentAzure managed application
  • IdentityRead-only managed identity
YOUR AZURE TENANT Azure AI servicesMicrosoft 365Power PlatformCost Management READ-ONLY · NO WRITE PERMISSIONS AI Pulse MANAGED APPLICATION READ-ONLY MANAGED IDENTITY You, signing in ENTRA ID · MFA No asset data, telemetry or evidence ever leaves the tenant
Deployment boundary (schematic) AI Pulse runs inside your Azure tenant and reads from Microsoft surfaces. Nothing crosses the boundary out.

02What it does

Discovery, tiering, mapping, evidence

Discover

A continuous sweep across Azure AI services, Microsoft 365, Power Platform and related cost signals surfaces AI systems — sanctioned, experimental or shadow. What is found is registered; nothing stays dark.

Risk-tier

Each system is tiered by what it touches: data sensitivity, autonomy, customer impact. High-tier systems get closer attention and stricter evidence expectations.

Map

Controls map to 45 frameworks — MAS guidance and information papers, PDPC advisory guidelines, ISO/IEC 42001, NIST AI RMF, the EU AI Act and more. Map once, report many.

Evidence

Audit-ready packs: what exists, who owns it, what tier it sits in, which controls apply, when it was last reviewed. Produced for the review you actually face.

AI Pulse FinOps view: model cost attributed to each business unit with unmanaged AI on its own line, spend against value over six months, spend tied to models past their retirement date, and projected run-rate by model.
Cost attribution The cost signal that betrays an unregistered system: spend attributed to the business unit that owns it, with unmanaged AI on its own line and models past their retirement date flagged by date.

03The workspaces

Six lenses on one estate

AI Pulse is the observability layer for the estate it maps: what discovery finds renders as six executive dashboards, each answering a different owner's question — value for the board, posture for the CISO, spend for finance, readiness for audit.

Behind all six sits the AI Agent Registry — the system of record every view reads from: registration, named owners, acceptances, operations and lineage. One registry, six ways of looking at it, and no side spreadsheets.

Executive dashboards

  • AI Value & PortfolioEstate & maturity
  • SecurityAttack surface & safety
  • Architecture & QualityBuild health
  • Productivity & OpsUsage & operations
  • FinOps & ROISpend & value
  • Audit & AssuranceEvidence & readiness

04Why it holds up

An Honesty Engine, not a dashboard of wishes

The reporting is built on what we call the Honesty Engine: every figure it shows carries its provenance. A number is either live (read from your estate), derived (computed from live inputs, with the method shown), or plainly marked not connected when a data source isn't available. There are no silent estimates and no invented metrics — the “honest not-connected state” is a feature, because an auditor can trust what they see only when they can also trust what is marked as missing.

Live — read from your estateDerived — method shownNot connected — stated plainly

The same discipline runs through this website: every statistic we cite is verbatim from its source, with the source beside it.

Built for regulated estates

  • DeploymentAzure managed application
  • ScopeMicrosoft Azure only
  • Frameworks45 mapped
  • Sign-inEntra ID · MFA
  • AvailabilityNow

Coverage & prerequisites →

05The chain

One chain of custody, from boardroom to model

Effective AI governance keeps a single, traceable chain: the organisation's risk appetite, the applications that carry it, the agents that act inside them, and the models those agents use. Break the chain anywhere and an auditor's question — “why was this system allowed to do that?” — has no answer.

AI Pulse keeps that chain intact. Read-only, it is maintained observationally: every system registered, tiered, owned and mapped. With enforcement deployed it is also maintained operationally: every agent action proposed, checked and recorded.

What good looks like

  • InventoryComplete, incl. shadow AI
  • OwnershipNamed, per system
  • TieringRisk-based, revisited
  • ControlsMapped to 45 frameworks
  • EvidenceProduced, not assembled
AI Pulse agent lineage graph: divisions branch to business units, business units to named agents, and agents to the language models they call, drawn across the whole estate.
Agent lineage Division to business unit to agent to model, drawn from the estate itself. “Which model sits behind this decision” resolves to a path, not a guess.

06The path

Observe and prove — then, if you need it, enforce

Most estates start by looking: see what is running, tier it, evidence it. When some of those systems become agents that take actions — and you need the ability to stop an action before it happens — you deploy the enforcement layer. Same portal, same evidence model; enforcement added explicitly, where you authorise it, and nowhere else.