Skip to main content
No single channel sees everything. A browser extension cannot see a backend service calling GPT-4o; an SDK cannot see someone pasting into ChatGPT. Prompt Shields runs several independent channels and merges what they find.

The channels

Coverage matrix

Which channel catches which kind of usage:
The gap this makes obvious: only the SDK and gateway see code-side AI. If you deploy the endpoint clients alone, every AI call your own services make is invisible.

Multi-source corroboration

When several channels detect the same capability, they merge into a single asset carrying multiple evidence trails:
The asset’s discovery_source field is an array — every channel that saw it. That array is what drives confidence scoring.

How assets get merged

The collector does not create a new asset per event. It looks for an existing asset matching a merge key built from vendor, model, use case, business unit, and calling service. Matching events fold into the existing asset and extend its evidence. Two behaviours worth knowing:
  • Environments stay separate. A production asset and a staging asset are distinct, because conflating them would misrepresent your risk surface.
  • The highest data classification wins. If one event reports internal and another reports confidential for the same asset, the asset is confidential. Classification only ever ratchets upward on merge.
This is why the metadata you set when constructing an SDK client matters so much. Business unit and use case are part of the merge key — get them wrong and one real system fragments into several registry entries. See Python SDK.