Appearance
Automation Setup Guide
Last updated: August 10, 2026
The Automation setup wizard connects approved organization metadata to Briard-AI. Its purpose is to minimize customer work: Briard performs connection verification, metadata discovery, matching, deduplication, inventory creation, and exception routing automatically. People are asked only for access consent or decisions that the approved metadata cannot prove.
What you need before starting
For Microsoft 365 and Entra discovery, have:
- the organization's Microsoft Directory tenant ID; and
- an authorized Microsoft administrator who can grant application permissions for the organization.
The workspace user configuring the connection must be a Briard-AI Owner or Administrator. Never paste a Microsoft client secret, password, MFA code, recovery code, or access token into Briard-AI.
For Google Workspace discovery, have:
- the organization's Google Workspace customer ID;
- the email address of a Workspace super administrator; and
- that super administrator available to authorize Briard's displayed service-account client ID and two read-only scopes in Security > Access and data control > API controls > Manage Domain Wide Delegation.
Never paste a Google service-account key, OAuth token, password, MFA code, or recovery code into Briard-AI.
Run the wizard
Open Automation setup from the application navigation.
1. Plan
Briard automatically prepares the current discovery plan. The wizard separates four coverage paths:
- Microsoft 365: automatic, scheduled metadata discovery after administrator consent.
- Google Workspace: automatic, scheduled Gemini and OAuth audit-metadata discovery after super-administrator authorization.
- Approved browser/endpoint collectors: automatic aggregate observation when the organization deploys a collector under its own approved policy; guided confirmation covers anything outside that managed footprint.
- Cloud AI platforms: metadata-only GitHub Copilot, Azure AI, and AWS Bedrock observations can be accepted after the organization authorizes the applicable collector; local, embedded, and undisclosed use still requires guided confirmation.
The coverage count reports active paths. It is not a claim that Briard has found every AI use.
2. Connect
Enter the Microsoft Directory tenant ID and select Save tenant and continue.
This is the only organization value Briard asks the workspace user to copy. If the organization does not use Microsoft 365, select We do not use Microsoft 365. Briard will skip that connector and prepare the manual coverage steps.
3. Consent
Review the displayed read-only permissions and their purpose. Select Open Microsoft administrator consent and sign in on Microsoft's page as an authorized administrator.
Microsoft shows the permissions configured for the Briard enterprise application. After the administrator approves them, Microsoft returns the browser to Briard. Briard checks that the returned tenant and setup state match the saved configuration before it proceeds.
If consent was already granted, select Consent already granted - verify now.
4. Discover
No input is required. Briard automatically:
- requests a Microsoft Graph application token on the server;
- verifies organization identity;
- reads a bounded, metadata-only set of enterprise applications, directory user status, directory audit events, and conditional-access policy state;
- follows Microsoft Graph pagination only while the next link remains on the approved
graph.microsoft.com/v1.0host and within fixed page and item limits; - matches likely AI services by product name;
- deduplicates repeat observations with a stable fingerprint;
- creates new records as Discovered - unverified;
- records metadata provenance and a ledger event; and
- refreshes the automation exception queue.
5. Finish
The result shows how many enterprise applications were checked, likely AI services found, new inventory records created, and existing records matched.
Daily discovery continues automatically. Use the Dashboard exception queue for the remaining human decisions.
Connect Google Workspace
In the same wizard, enter the Google Workspace customer ID and delegated super-administrator email, then select Save Google Workspace. Briard displays its public service-account client ID and the exact scopes below.
The Workspace super administrator must open Google's domain-wide delegation page, add the displayed client ID, and authorize exactly the two comma-separated scopes. Return to Briard and select Verify and discover. Briard verifies token authority, scans bounded audit and directory metadata, creates or matches Discovered - unverified inventory records, and schedules daily refreshes automatically.
| Google scope | Why Briard requests it |
|---|---|
https://www.googleapis.com/auth/admin.reports.audit.readonly | Read Gemini-in-Workspace and OAuth application audit-event metadata. |
https://www.googleapis.com/auth/admin.directory.user.readonly | Count active users for access-review signals without storing user records. |
The Google collector stores aggregate counts, detected application names/client IDs, source references, and ledger evidence. It does not store Gmail or Chat content, Drive filenames or file contents, prompts, model outputs, IP addresses, individual actor email addresses, or access tokens.
Microsoft permissions
| Permission | Why Briard requests it |
|---|---|
Application.Read.All | Find enterprise applications and service principals that may represent AI services. |
Directory.Read.All | Confirm organization identity and directory context. |
AuditLog.Read.All | Read bounded directory activity metadata for discovery signals. |
Policy.Read.All | Read conditional-access policy state for governance evidence. |
User.Read.All | Count enabled users for joiner and leaver review signals. |
These are application permissions used by a scheduled background service, so Microsoft administrator consent is required. Briard does not request write permissions.
What Briard collects
Briard stores approved governance metadata and source references. The initial Microsoft discovery records aggregate counts and likely AI enterprise-application matches. It does not store Graph access tokens in the browser.
Briard does not collect:
- email or Teams message content;
- files or file contents;
- prompts or model outputs;
- passwords, MFA codes, recovery codes, or Microsoft client secrets; or
- CUI, PHI, payment-card data, or other regulated payloads.
Approved browser and endpoint collectors may send product name, publisher, aggregate installation counts, and SHA-256 hashes for browser origins or executables. Cloud collectors may send aggregate seat or invocation counts, region, service/model identifiers, and hashed resource references. Briard rejects full URLs, paths, query strings, hostnames, device identifiers, usernames, email addresses, prompts, outputs, message text, secrets, and tokens before queueing an observation.
Decisions Briard cannot safely make
An accountable person must still:
- confirm or reject newly discovered AI services;
- identify the business and technical owner;
- confirm business purpose, data use, deployment status, and boundary;
- report browser-only, personal-account, local, embedded, private, and undisclosed API-key-based AI use; and
- approve governance attestations and legal conclusions.
These items appear as focused exceptions after Briard has completed the deterministic work.
Revoke or restore access
A Microsoft administrator can revoke the Briard enterprise application's access in Microsoft Entra. After revocation, Briard stops receiving new Microsoft metadata and creates a reconnect exception. Previously recorded governance and ledger history remains subject to the workspace's retention controls.
To restore access, reopen Automation setup, review the tenant ID, grant administrator consent again, and run verification.
Troubleshooting
- Platform activation is required: Briard's server-side Microsoft application configuration is incomplete. Contact support with the workspace name and visible message. Do not send credentials.
- Consent returned for a different directory: sign out of the unintended Microsoft administrator account and restart the consent step with the administrator for the saved tenant.
- Permission or token error: verify that all displayed application permissions were granted for the Briard enterprise application.
- Google authorization failed: verify the displayed service-account client ID and both exact scopes in Google Admin domain-wide delegation, and confirm the delegated email belongs to an active super administrator in that Workspace customer.
- No AI services found: the scan completed but no supported application or activity metadata matched the current AI detector. Review unmanaged browser, local/private, embedded, and API-key-based use separately.
