For IT & Procurement
AI vendor sprawl and shadow AI, audited for IT and procurement
Spendassay is an independent audit of your AI spend. It detects shadow AI from SSO and OAuth grants plus corporate-card charges, maps every AI vendor and seat you pay for, and prices the waste. It surfaces 10 to 15% of seat and subscription spend as recoverable within 30 days, then hands your admins step-by-step instructions.
How do I find the shadow AI employees are already using?
Spendassay detects shadow AI without agents or endpoint scanning. It reads SSO and OAuth grants from Okta and Google Workspace, then matches AI charges on Ramp corporate cards against your sanctioned vendor list. Anything unmanaged surfaces as a dollar-priced finding with a proof level, so IT sees the tool and which team is paying for it.
Shadow AI rarely shows up in a procurement system. It shows up as an OAuth grant an engineer approved, or a card charge under a team budget. Spendassay reads those two signals and flags AI vendors that are not on your managed list.
The detection is metadata-only. Spendassay never reads prompts, message content, or source code. It sees that a grant or charge exists and which team it belongs to, not what anyone typed.
Each finding carries a proof level: counted, compared, or estimated. Shadow AI detected from a live grant or a real card charge is measured, so you can act on it without second-guessing the source.
How many AI vendors are we actually paying for?
Most mid-market companies pay for overlapping AI tools bought by different teams. Spendassay connects GitHub, Cursor, OpenAI, Anthropic, Okta, Google Workspace, Ramp, or a CSV export, then consolidates every seat subscription and API line into one inventory. Tool-overlap findings show where two vendors do the same job.
Vendor sprawl happens when Copilot, Cursor, ChatGPT, and Claude all enter through different budgets. No single owner sees the whole picture, and renewals stack up on different dates.
Spendassay builds one inventory of seat subscriptions, API token spend, and infra, priced per vendor and per team. Tool-overlap findings name the pairs where you pay twice for the same capability.
You do not need every connector live to start. CSV import works with zero integrations, so procurement can load a card export or invoice and get a first inventory before IT wires up any read-only connection.
How do we stop overpaying at AI license renewals?
Spendassay flags unused and underused seats before each renewal and builds a negotiation package. The findings show how many licenses to drop, priced against public list prices with a last-verified date. You right-size the contract count with your vendor, and the audit tracks the banked savings on a Recovered statement.
Unused-seat findings cover licenses with no activity. Underused-seat findings cover seats that are active but far below the cohort. Each dollar is counted once, so the same seat is never claimed twice.
The negotiation package pairs the seat count you can drop with a benchmark against published list prices, each row citing its source and retrieval date. When a vendor is contact-sales only, the benchmark is honestly marked absent rather than guessed.
After your admins execute the change, Spendassay verifies the finding closed on a later sync and banks the dollars on a Recovered statement. That gives procurement a defensible number for the savings, not an estimate.
Is Spendassay safe for IT to approve?
Yes. Spendassay's audit is read-only and metadata-only. It never reads source code, prompts, or message content, and the audit never writes to, routes, or throttles any vendor system. Routing and throttling are Control, a separate opt-in plan (private beta) that runs on your own provider keys. Reporting is team-level, never individual league tables. Recoveries run as step-by-step instructions your own admins execute, approval-tracked and audited in-product.
Every connector uses read-only scopes. Spendassay pulls seat rosters, usage metadata, grants, and spend. The audit cannot change a setting, revoke a seat, or throttle a token on your behalf; only Control can act, and only on rules you configure.
The database itself keeps each customer's data apart, so one customer's query cannot reach another's rows, and the audit log can be added to but never changed or deleted. Recovery actions require an explicit approval click before any set of step-by-step instructions is marked done.
The output is built for two readers: IT sees the vendor and seat inventory with its provenance, and the CFO sees an AI cost report where every number exposes its formula and proof level.
Common questions
Does Spendassay install anything on employee devices?
No. There are no agents and no endpoint scanning. Shadow AI is detected from SSO and OAuth grants in Okta and Google Workspace plus corporate-card spend in Ramp, all through read-only connectors or a CSV import.
Can it see what employees type into ChatGPT or Copilot?
No. Spendassay is metadata-only. It never reads prompts, message content, or source code. It sees seat counts, usage metadata, grants, and spend, reported at the team level, never as individual league tables.
What if we have no live integrations yet?
CSV import works with zero live integrations. Procurement can upload a corporate-card export or vendor invoice and get a priced inventory of AI vendors and seats before IT connects Okta, GitHub, Ramp, or any other source.
Does Spendassay cancel licenses or block tools for us?
No. The audit finds and prices the waste and sets the recoverable target. Your own admins execute the change through step-by-step instructions, which are approval-tracked and audited in-product. The audit never writes to or throttles a vendor system. Routing and throttling are Control, a separate opt-in plan (private beta) that runs on your own provider keys.
See your own AI spend, audited
Connect read-only sources and get a CFO-credible AI cost report. Free to start, about 10 minutes to connect.