Skip to content

Automation Setup Guide ​

Last updated: September 23, 2026

The Automation setup wizard connects approved organization metadata to Briard-AI. Its purpose is to minimize customer work: Briard performs connection verification, metadata discovery, matching, deduplication, inventory creation, and exception routing automatically. People are asked only for access consent or decisions that the approved metadata cannot prove.

What you need before starting ​

For Microsoft 365 and Entra discovery, have:

  • an authorized Microsoft administrator who can grant application permissions for the organization.

You do not need to find an organization ID. Microsoft identifies the organization during approval, and Briard verifies it through Microsoft Graph before activating the connection. People who already know the Tenant ID can still enter it under the manual option.

The workspace user configuring the connection must be a Briard-AI Owner or Administrator. Never paste a Microsoft client secret, password, MFA code, recovery code, or access token into Briard-AI.

For Google Workspace discovery, have:

  • the email address of a Workspace super administrator; and
  • that super administrator available to authorize Briard's displayed service-account client ID and two read-only scopes in Security > Access and data control > API controls > Manage Domain Wide Delegation.

You do not need to find a Google Workspace Customer ID. Briard uses Google's my_customer alias, then reads the canonical Customer ID from the already-approved read-only directory response before activating the connection. Manual Customer ID entry remains available under the advanced option.

Never paste a Google service-account key, OAuth token, password, MFA code, or recovery code into Briard-AI.

Run the wizard ​

Open Automation setup from the application navigation.

1. Plan ​

Briard automatically prepares the current discovery plan. The wizard separates four coverage paths:

  1. Microsoft 365: automatic, scheduled metadata discovery after administrator consent.
  2. Google Workspace: automatic, scheduled Gemini and OAuth audit-metadata discovery after super-administrator authorization.
  3. This browser: the opt-in Briard Browser Check notices supported AI websites without reading page content. Each noticed tool still goes to a person for confirmation. Approved endpoint collectors can cover managed devices under the organization's policy.
  4. Cloud AI platforms: metadata-only GitHub Copilot, Azure AI, and AWS Bedrock observations can be accepted after the organization authorizes the applicable collector; local, embedded, and undisclosed use still requires guided confirmation.

The coverage count reports active paths. It is not a claim that Briard has found every AI use.

2. Connect ​

Select Connect Microsoft 365. Microsoft asks an administrator to sign in and identifies the approving organization for Briard.

No organization value needs to be copied. If an administrator specifically wants to use a known Tenant ID, open I already know the Microsoft organization ID. The Tenant ID is also called the Directory ID and is available in Microsoft Entra under Entra ID > Overview > Properties > Tenant ID. If the organization does not use Microsoft 365, select We do not use Microsoft 365.

Review the displayed read-only permissions and their purpose. Select Continue to Microsoft and sign in on Microsoft's page as an authorized administrator.

Microsoft shows the permissions configured for the Briard enterprise application. After approval, Microsoft returns the browser to Briard with the organization's Tenant ID. Briard validates a short-lived, tamper-resistant setup response, binds the value to the signed-in workspace, requests a server-side application token, and confirms the same organization through Microsoft Graph before the connection can become active. The returned browser value alone is never treated as proof.

If consent was already granted, select Consent already granted - verify now.

4. Discover ​

No input is required. Briard automatically:

  • requests a Microsoft Graph application token on the server;
  • verifies organization identity;
  • reads a bounded, metadata-only set of enterprise applications, directory user status, directory audit events, and conditional-access policy state;
  • follows Microsoft Graph pagination only while the next link remains on the approved graph.microsoft.com/v1.0 host and within fixed page and item limits;
  • matches likely AI services by product name;
  • deduplicates repeat observations with a stable fingerprint;
  • creates new records as Discovered - unverified;
  • records metadata provenance and a ledger event; and
  • refreshes the automation exception queue.

5. Finish ​

The result shows how many enterprise applications were checked, likely AI services found, new inventory records created, and existing records matched.

Daily discovery continues automatically. Use the Dashboard exception queue for the remaining human decisions.

Connect Google Workspace ​

In the same wizard, enter the Google super-administrator email and select Continue. No Customer ID is needed. Briard displays its public service-account client ID and the exact scopes below.

The Workspace super administrator opens Google's approval page, selects Add new, adds the displayed client ID, and authorizes exactly the two comma-separated scopes. Return to Briard and select Verify and find AI tools. Briard verifies token authority, resolves Google's current-customer alias to the canonical Customer ID, checks that any manually entered ID matches, scans bounded metadata, creates or matches Discovered - unverified inventory records, and schedules daily refreshes automatically.

Manual fallback: open I already know the Google Customer ID. A Customer ID usually starts with C and is in Google Admin under Account > Account settings > Profile > Customer ID. It is not a Google Cloud organization ID, Google Ads ID, billing ID, or organization-unit ID.

Google scopeWhy Briard requests it
https://www.googleapis.com/auth/admin.reports.audit.readonlyRead Gemini-in-Workspace and OAuth application audit-event metadata.
https://www.googleapis.com/auth/admin.directory.user.readonlyCount active users for access-review signals without storing user records.

The Google collector stores aggregate counts, detected application names/client IDs, source references, and ledger evidence. It does not store Gmail or Chat content, Drive filenames or file contents, prompts, model outputs, IP addresses, individual actor email addresses, or access tokens.

Connect this browser ​

In Automation setup, choose This browser and select Add Browser Check. Briard opens the official Chrome or Edge store page for your browser. Add it, then select Turn on Browser Check once. The browser shows the exact short list of AI websites before access is approved and then brings you back to Briard.

Browser Check stays off until the person using the browser turns it on. It recognizes only supported AI website hostnames and does not read the page, prompts, answers, files, passwords, cookies, names, or device identifiers. It keeps the product name, publisher, one-way SHA-256 website fingerprint, notice times, notice count, and Briard workspace ID in the add-on until Briard saves them. It then keeps only the one-way fingerprint for that workspace so the same tool is not reported on every later visit. It never sends a waiting finding to a different workspace.

Back in Briard, there is no reload or Send step. Briard saves the metadata as Shadow AI findings and opens the review. A person still chooses Yes, No, or I'm not sure. Browser Check never approves a tool or changes a policy.

When Browser Check later notices a new supported site, it opens one quiet Briard tab, saves the finding, and closes that tab after Briard confirms the exact batch. The add-on keeps any new visit that happens during that sync for the next batch.

If the safe one-click store install is not ready, Briard says so and offers another check or an IT handoff. The ZIP is an IT/test package, not a customer installer; do not unzip it or open popup.html yourself.

Microsoft permissions ​

PermissionWhy Briard requests it
Application.Read.AllFind enterprise applications and service principals that may represent AI services.
Directory.Read.AllConfirm organization identity and directory context.
AuditLog.Read.AllRead bounded directory activity metadata for discovery signals.
Policy.Read.AllRead conditional-access policy state for governance evidence.
User.Read.AllCount enabled users for joiner and leaver review signals.

These are application permissions used by a scheduled background service, so Microsoft administrator consent is required. Briard does not request write permissions.

What Briard collects ​

Briard stores approved governance metadata and source references. The initial Microsoft discovery records aggregate counts and likely AI enterprise-application matches. It does not store Graph access tokens in the browser.

Briard does not collect:

  • email or Teams message content;
  • files or file contents;
  • prompts or model outputs;
  • passwords, MFA codes, recovery codes, or Microsoft client secrets; or
  • CUI, PHI, payment-card data, or other regulated payloads.

Approved browser and endpoint collectors may send product name, publisher, aggregate installation counts, and SHA-256 hashes for browser origins or executables. Cloud collectors may send aggregate seat or invocation counts, region, service/model identifiers, and hashed resource references. Briard rejects full URLs, paths, query strings, hostnames, device identifiers, usernames, email addresses, prompts, outputs, message text, secrets, and tokens before queueing an observation.

Decisions Briard cannot safely make ​

An accountable person must still:

  • confirm or reject newly discovered AI services;
  • identify the business and technical owner;
  • confirm business purpose, data use, deployment status, and boundary;
  • report browser-only, personal-account, local, embedded, private, and undisclosed API-key-based AI use; and
  • approve governance attestations and legal conclusions.

These items appear as focused exceptions after Briard has completed the deterministic work.

Revoke or restore access ​

A Microsoft administrator can revoke the Briard enterprise application's access in Microsoft Entra. After revocation, Briard stops receiving new Microsoft metadata and creates a reconnect exception. Previously recorded governance and ledger history remains subject to the workspace's retention controls.

To restore access, reopen Automation setup, select Connect Microsoft 365, grant administrator consent again, and run verification. Briard will identify and verify the organization again.

Troubleshooting ​

  • Platform activation is required: Briard's server-side Microsoft application configuration is incomplete. Contact support with the workspace name and visible message. Do not send credentials.
  • Microsoft approved a different organization: choose automatic setup and sign in with the administrator for the intended organization. If using manual setup, check the Tenant ID.
  • Permission or token error: verify that all displayed application permissions were granted for the Briard enterprise application.
  • Google authorization failed: verify the displayed client ID and both exact scopes in Google Admin, and confirm the delegated email belongs to an active super administrator. Automatic setup should be used unless IT specifically requires a Customer ID.
  • No AI services found: the scan completed but no supported application or activity metadata matched the current AI detector. Review unmanaged browser, local/private, embedded, and API-key-based use separately.
  • Browser Check is not detected: confirm that the official store says Browser Check is installed, then reopen Briard and select Check again. If your organization uses the IT-only package, ask IT to finish the managed installation; do not open files from the ZIP yourself.

Open Briard-AI

Back to Client Documentation

Briard-AI and KAIDAN are products of Unfettered Minds LLC. Governance documentation and review support. Not legal advice or certification.