AI Tool Usage & Spend Limits
Every AI tool in use across the org — sanctioned or shadow — with spend measured against approved limits.
Correlated from
Okta SSO
Google Workspace
Browser telemetry
Finance / expense
Vendor billing APIs
— no single source sees all AI usage
Total AI Spend · MTD
$48.2K
AI Tools In Use
37
Active Users
612
Budget Used · This month
83%
Potential Savings
$12.4K/mo
① Spend vs. Approved Limit — by tool
Are we inside the limits we agreed to? Bars past the limit marker are over budget.
Spend (within limit)
Spend (over limit)
Approved limit
③ AI Spend Trend
Where is this heading vs. the $58K/mo budget?
Actual spend
Monthly budget
•••• Forecast
② AI Adoption — active users by tool
Who is using what? Shadow tools (no IT approval) shown in amber.
Sanctioned
Shadow / unsanctioned
Attention needed
Prioritized actions — what a governance owner should do next.
| Tool | Flag | Action |
|---|---|---|
| Microsoft 365 Copilotvia Okta SSO + vendor API | Over limit +24% | Review budget |
| GitHub Copilotvia vendor billing API | 160/300 seats idle | Reclaim ~$4.5K/mo |
| Cursorvia finance + OAuth grant | Shadow · 22 devs | Sanction or block |
| Perplexityvia browser telemetry | Shadow · data risk | Review & approve |
| Midjourneyvia finance (personal card) | On personal cards | Consolidate |
Prototype for CloudEagle.ai APM take-home · all figures are illustrative mock data · charts hand-rendered (no external libraries)
Data Sources
Connectors feeding the AI inventory. Each signal is normalized, attributed to a user & department, and de-duplicated into one record per tool.
5Sources connected
1Needs attention
37AI apps discovered · de-duplicated
1.24MSignals ingested · last 30 days
| Source | Category | Auth method | Status | Signals ingested | Sync cadence | Last sync | AI apps found | |
|---|---|---|---|---|---|---|---|---|
| Oktaokta-sso | Identity & SSO | OAuth 2.0 · SCIM | Connected | Sign-in events, OAuth app grants, user & group directory | Real-time webhook | 4 min ago | 21 | ⋯ |
| Google Workspacegsuite-admin-sdk | Identity & SSO | Service account · domain-wide delegation | Connected | Login audit, OAuth token grants, Marketplace apps | Hourly · Reports API | 38 min ago | 14 | ⋯ |
| Browser telemetrybrowser-plugin | Endpoint & Browser | Managed extension · MDM-deployed | Connected | AI-domain visits, in-app AI feature use, first/last seen | Real-time stream | 2 min ago | 33 | ⋯ |
| Finance & Expenseconcur · ramp · corp-card | Finance & Expense | OAuth 2.0 · API key | Connected | Card transactions, expense line items, vendor invoices | Daily · 02:00 UTC | 6 hrs ago | 9 | ⋯ |
| Vendor billing APIsopenai-billing-api · anthropic-admin-api · github-copilot-api | Vendor Usage API | API key · per vendor | Action neededAnthropic key expires in 6 days | Per-model token usage & cost, seat utilization, billing periods | Daily | 5 hrs ago | 6 | ⋯ |
Why more than one source? The five connectors report 83 raw app-detections
(21 + 14 + 33 + 9 + 6), which the correlation engine de-duplicates into 37 unique AI tools.
Each sees only a slice — SSO sees what it provisioned, the browser catches shadow web tools, finance catches
personally-expensed subscriptions, and vendor APIs add per-model cost. No single source sees all 37.
Prototype for CloudEagle.ai APM take-home · all figures are illustrative mock data