Catalog: browse tools, review risk, set policy
Hundreds of known AI tools, each with a risk assessment. Filter, open any tool, and set policy in bulk.
The catalog holds every known AI tool: more than 700 of them, each with a risk assessment already done. It is where you decide what your organisation allows, and where you steer people towards safer options. Policy is default-deny: every tool starts at No decision yet until your organisation says otherwise, and a risk band is advice, never a decision BeeSensible makes for you.
Catalog in the dashboardUnder AI Governance in the menu; also where you add your own tools.Browsing and filtering
Each row shows the tool with its vendor, its sector, the vendor's country, its visits in your organisation (last 30 days), its risk band with score, and its current policy. You can:
- use the quick filters: All, Shadow AI (self-serve tools without a yes from the organisation that are being used anyway), With activity, and New; within With activity you can slice further by status
- filter via the Filters button on risk level, sector, category, vendor country, access, tag, and certification, and search by tool, vendor, or category
- sort on any column by clicking its header, for example by risk or by visits
- add an internally sanctioned tool with Add your own tool; it appears with the Own badge alongside the global catalog and can be picked as an allowed alternative
The catalog is continuously curated: BeeSensible scans the web for new AI tools, assesses them, and adds them with the full fact sheet. Added tools carry a New badge for 30 days and can be found through the New quick filter; a dismissible banner at the top tells you how many arrived since your last visit.
Setting policy
Every tool has one of four statuses: Allowed, Limited use, No decision yet, or Not allowed. You set a status per row through the status control in the Policy column, or in bulk:
Select tools
Tick tools; shift-click selects a range, and the checkbox in the header selects everything your filter shows.
Pick a status in the bar at the bottom
As soon as anything is selected, a bar appears at the bottom with the four statuses. One click applies the status to the whole selection.
For Limited use: write the condition
Choosing Limited use first opens the dialog "What are the limits for this tool?", asking for the condition employees will see. The field comes pre-filled with the common rule and ready-made lines sit below it; short and concrete works best (200 characters at most). Confirm with Allow with limits.
Reviewing a tool
Click a row and you get the full detail view, built to answer one question quickly: is this tool safe enough for our people, and if not, where should they go instead? The policy buttons sit at the bottom of the view, visible on every tab.
Why this assessment
Risk breakdown
Higher = more risk (5 = worst)
EU AI Act
Limited riskTransparency duty (Art. 50): must disclose it's AI, or label generated content.
Not legal advice; based on the vendor's documented intended use.
Incidents
Overview
The Overview tab opens with the tool's use in your own organisation (visits in the last 30 days, with a click-through to the Usage tab) and its Properties: trains on input, data residency, integration, DPA available, underlying model, access, and certifications.
Risk and compliance
The Risk & compliance tab shows the risk band with its score, and under "Why this assessment" the reasons behind it. The Risk breakdown scores the tool on six dimensions, each from 1 to 5: Data governance, Jurisdiction, Compliance, Incidents, Integration scope, and Vendor trust. Next to it sit an EU AI Act card with the tool's classification and the documented incidents, each with a source, so the assessment is not a black box. Bands run from Low to Critical.
Alternatives
The Alternatives tab lists allowed alternatives with the reason for each. Through Add an alternative you pin the one your organisation prefers; it then shows as Pinned at the top, and employees see it first in the note when they open a tool that is not allowed.
Usage
If the tool has activity, the Usage tab shows how often and when it is used and what for, so you can prioritise the tools that carry the most real exposure.
Guiding people, not blocking them
Policy is a note, not a wall; nothing in BeeSensible blocks sending or opening a tool. What employees see in the browser depends on the status:
| Status | What employees see |
|---|---|
| Allowed | Never a note. |
| Limited use | A note with your own condition and the button "Hold to continue anyway". |
| No decision yet | A calm note: only enter public information, with a plain "Continue anyway" button. |
| Not allowed | A note leading with your allowed alternatives and the button "Hold to continue anyway". |
Whether a status actually shows a note is your call, per status, under Organisation, in Organisation settings:
Coaching
| Status | Switch | Default |
|---|---|---|
| Not allowed | Note with "hold to continue anyway" and an allowed alternative | On |
| Limited use | The same note, with the condition you set on the tool | On |
| No decision yet | A calm note; off by default, so new catalog tools never nudge on their own | Off |
| Allowed | Never shows a note | n/a |
The layer for tools without a decision is a deliberate opt-in: switch it on and the calm note applies to everything not yet decided. How often notes are shown and what people do with them appears on Risk, under Warnings about tools.
Tips
- Start with the Shadow AI quick filter: those are the tools in real use without a yes from the organisation. That is where your data is most exposed.
- Leave a tool at No decision yet while you gather information; that is also where every tool starts.
- Revisit Not allowed tools now and then. A tool may come to meet your requirements later, or a better alternative may appear.