It flags anything outside your SOPs
You have a governance policy.
AI ignores it.
Keep enforces it.
Bring your SOP.
Keep reads it and enforces it on every AI request.
Keep checks every AI request against those rules. Even when someone technically has access, if what they did doesn't fit how your company operates, Keep flags it. It also watches for the patterns no one thinks to write down: someone reading far outside their role, unusual volumes, odd hours, an AI tool nobody approved, or repeated attempts to reach things they can't see.
One page. Every Monday.
What your AI tools touched, who read sensitive material, and the short list of things that broke the rules or looked off, each with a plain-English reason and a button to mark it fine or look into it. Larger companies route it by department and send the flags straight to their security tools.