Understand AI use
See how employees, assistants, and agentic tools are actually using AI.
Solutions
AI governance is a runtime control problem, not a procurement problem. Your organisation owns the controls over reachable tools, credentials, shared state, and delegated authority—not the model vendor. 3LS supports discovery, classification, visibility, evidence, and policy evaluation across broader AI use.
See how employees, assistants, and agentic tools are actually using AI.
Find PII, secrets, and risky interactions in the observed evidence available to policy evaluation.
Turn observed evidence into an explainable policy evaluation and retain the result.
Review the AI and MCP inventory, managed action controls, cases, policy lifecycle, approvals, evidence, and enterprise integrations in one place.
Solutions
Start with one visual story on the homepage, then explore the capabilities that help teams understand AI use, detect sensitive data, and make defensible policy decisions.
Prompt classification
See whether AI is being used for drafting, coding, research, summarization, data handling, or tool-driven work.
Explore capabilityPII detection
Surface personal information, credentials, and restricted content inside prompts, tool inputs, and outputs.
Explore capabilityPolicy evaluation
Evaluate organisational policy with the context available. Pre-execution grant or deny is limited to a supported managed MCP stdio path.
Explore capabilityCompliance evidence
Collect runtime evidence for prompts, uploads, OAuth grants, tool actions, supplier exposure, and high-risk AI decisions.
Explore capabilityOperator view
Give security teams a readable trail of what was detected, how policy was evaluated, and which evidence supported the result.
Recent findings
Intent, sensitivity, and policy evaluation
Outcome
Give operators a clear picture of where AI is helping, where it is handling data, and where closer review is needed.
Capability
Detect risky content and suspicious AI behavior before it becomes a data exposure or a control failure.
Control
Turn observed AI use into policy evaluations, with decisions and evidence operators can explain.
From the blog
Articles mapped to the same themes as the solutions catalog: visibility, classification, sensitive-data handling, and action-oriented controls.

After an AI exposure, the hardest question is usually what your organization cannot answer: where AI is active, what was pasted in, and what was shared. That visibility gap turns shadow AI into an incident multiplier.

A single paste can become a breach. From Samsung's ChatGPT incident to training data extraction, 26% of organizations are feeding sensitive data to public AI.

Microsoft is adding native AI controls while OpenAI is turning ChatGPT into a shared agent workspace. Both trends point to the same requirement: one runtime governance layer across prompts, files, memory, tools, and actions.