CUSTOMER CASE STUDY
Shadow AI Visibility: From AI Blind Spot to Blueprint
New Resources Consulting is a management and technology consulting firm based in the Milwaukee area.
The Challenge
Like most mid-sized organizations, Generative AI was spreading through the business, faster than any policy could keep pace with.
- No visibility into which AI tools employees were actually using, sanctioned or not
- No way to see what company data was flowing into third-party LLMs
- Manual, after-hours research into individual tools and firewall-level blocking as the only line of defense
- A widening gap between assumed risk and provable risk — making it difficult to write policy or brief the business with confidence
How Portal26 Helped
Phase One: Establishing the Baseline
New Resources deployed Portal26 with no disruption to end users. Data began flowing within roughly 30 minutes; within the hour, the security team had its first real read on AI usage across the company.
Where manual research and firewall rules had offered only a partial, backward-looking view, Portal26 gave New Resources a continuous, real-time count of every AI tool in use — sanctioned and unsanctioned — and visibility into where company data was actually going. Within the first day, usage patterns surfaced that leadership hadn’t anticipated, immediately reshaping the security team’s priorities around data handling and staff training.
“You can’t govern what you can’t see. Get the visibility first.
Everything else — policy, training, controls — follows from there.”
Christopher Hippensteel, Director of IT, New Resources Consulting
Phase Two: From Visibility to Governed Adoption
With hard data in hand, New Resources shifted from reactive blocking to a governance program grounded in real behavior. Instead of writing policy on assumption, the security team could see exactly which tools employees gravitated toward, why they preferred them over sanctioned enterprise alternatives, and where prompting practices themselves needed coaching — turning a security exercise into an adoption and training program as well.
Business Outcomes
- Deployment and time-to-value measured in minutes, not weeks, with zero impact on end-user or system performance
- Consistent visibility across on-network and client-site staff, closing a gap manual, firewall-based controls couldn’t reach
- A real-time, continuous count of Shadow AI tools in use, replacing estimates and after-hours manual research
- Visibility into what data was leaving the company and through which tools, giving the security team evidence instead of a hunch
- A foundation for AI governance policy built on observed behavior rather than assumption
- Prompt-level insight that turned a security initiative into a targeted training program
- A defensible, data-backed story the security team could finally bring to leadership and the board
- A repeatable model New Resources is now sharing with peer organizations through its regional CIO community