Start free trial
Company News & Events

One control plane for every AI your people use

One control plane for every AI your people use

Most enterprises did not choose one AI assistant. They chose one, then inherited three more. Governance has to catch up with that, and the place to start is the data every assistant reads. That was the argument behind the announcement we made on Thursday 1 October, in front of an audience from Belgium to Budapest to the US.

What we announced

  • Claude Enterprise governance is in preview, inside the AI & Agents module you already have.
  • ChatGPT Enterprise is next, with its preview opening on 15 October 2026.
  • Microsoft Entra ID joins the estate, so seats, spend and access read by person and department rather than by tool.
  • Existing policies, automations and reviews extend to the new services, with nothing new for end users to learn.

Matt Einig, CEO, opened on why AI has outgrown the silo. Tiina Rytkönen, VP of Product, set out what is shipping and in what order. The rest of the hour was the product itself. The sections below follow the same running order. Watch the full session on demand.

The sprawl pattern is not new

Every collaboration wave arrives the same way. SharePoint sites multiplied from 2004 onward, then sat abandoned with no owner. Teams rolled out in weeks during the pandemic, with the architecture decided afterward. Power Platform handed app building to people who had never shipped an app.

Each wave created value and then created cleanup. AI is the fourth wave, and it is arriving faster than the three before it. In 2023, Gartner forecast that more than 80 percent of enterprises would have used generative AI APIs or deployed generative AI applications by 2026, up from under 5 percent that year (source 1).

Copilot was the plan. Multi-AI is the reality.

Microsoft 365 Copilot sits in the productivity suite. Claude Enterprise shows up in research, analysis and engineering work. ChatGPT Enterprise arrived early in many organizations and stayed. Gemini comes with the Google subscription.

One person often holds two or three of them and uses each for different work. Govern Microsoft 365 Copilot alone and you govern part of the estate. The rest keeps running with no inventory, no named owner and no policy behind it.

The data never left Microsoft 365

This is what makes multi-AI a governance problem rather than a procurement one. Claude Enterprise and ChatGPT Enterprise both connect to Microsoft 365. They read and write SharePoint, OneDrive and Outlook through connectors a user approves in a few clicks.

The data still lives where it always lived. What changed is the number of assistants reading it. Every assistant inherits the oversharing already in your tenant. A SharePoint site connected to a Claude Enterprise project reaches everyone that project is shared with.

Native activity logs are short. Claude Enterprise retains activity for 30 days. When an auditor asks what happened in March, the log has already been purged.

Operational governance, not runtime governance

A crowded field of products now calls itself AI governance, and they do two different jobs. Runtime governance inspects prompts and responses as they happen, through a network proxy, a browser extension or an endpoint agent. It controls what an AI says.

Rencore does operational governance. We inventory the estate, show what each user and each assistant can reach, apply policy and automate the cleanup. We read configuration and metadata. We never read conversation content, in any assistant.

Both have a place. One governs the conversation. Rencore governs the environment the conversation draws from.

Entra ID is the join

Take Barbara. She has a Microsoft 365 Copilot license on her work address, a Claude Enterprise seat on a slightly different address, a ChatGPT Enterprise seat, and Gemini with no single sign-on. Four admin consoles, four partial pictures, one person.

Rencore anchors on Microsoft Entra ID. Where an assistant is connected by single sign-on, the identity join is direct. Where it is not, we match on email address and other attributes. Seats, spend, access and activity then read by person and by department rather than by tool.

What is in the Claude Enterprise preview

Claude Enterprise is live in preview inside the AI & Agents module, next to Microsoft 365 Copilot, Copilot Studio and SharePoint agents. It is a new inventory in the product you already use, not a second product to learn. The preview covers:

  • Users, groups and role-based access control roles, joined to the Microsoft 365 user
  • Projects with owner, visibility and collaborators, plus project attachments
  • Chats as metadata, including the model used and the cost incurred
  • Claude Code and Cowork sessions, local and remote
  • Artifacts, and whether each one has been shared
  • Skills, connectors and plugins in use, by user
  • Seats, token spend by user and department, and spend limits
  • 46 organization settings, tracked for change

The preview reads metadata only and never conversation content. It covers the Claude Enterprise plan only, and it does no runtime inspection.

Policies work the same way they do everywhere else in Rencore. The preview ships with a set already written: artifacts shared publicly, external users in the organization, Claude accounts still active after the Entra ID account is disabled, projects visible to the whole organization, remote sessions left unfinished.

A finding on its own changes nothing, so policies carry automations. A project that should not be open to the organization can trigger a deletion with an approval attached, routed to the project owner in the Rencore Teams app. The owner answers the request in Teams and never opens a governance console.

Reports and dashboards run on the same inventory. Plugin usage by user, Cowork sessions in the last 30 days, spend by department or cost center, seats in use against seats paid for. The licenses nobody opened are usually the fastest money in the room.

What comes next

ChatGPT Enterprise is coming soon, with its preview opening on 15 October 2026. The OpenAI APIs expose more than Anthropic’s do today, so the coverage goes wider: custom GPTs, projects and their connectors to SharePoint, Slack and Google Drive, agents, service accounts, library files, usage limits, cost lines by model and token type, and 12 months of activity. Actions go wider too, including unpublishing an agent rather than deleting it.

The Microsoft side keeps moving in parallel. Agent 365 support, Agent Builder and Copilot Cowork cost analysis are in development. Further assistants follow the demand our customers show us.

Governance is what lets AI ship

Governance has a reputation problem. Nobody starts the day planning to do some governance. But the teams who can see what an assistant reaches are the teams who say yes to the next rollout, because the risk is known rather than assumed.

The same inventory answers the auditor. The EU AI Act, GDPR, NIS2 and DORA all depend on current records: which agents exist, which apps are connected, who owns them, what their purpose is, and when they get reviewed. Rencore does not make anyone compliant with any of them. Rencore supplies the evidence those audits run on, and keeps it current through reviews the owners answer themselves.

Try it on your own estate

If you are a Rencore customer with the AI & Agents module, your customer success manager can switch the Claude Enterprise preview on in your production or staging environment. Connection is always opt in, service by service.

If you are not a customer yet, request preview access and tell us the governance use cases you need covered. Those conversations decide what we build next. Or talk to an expert about your AI estate.

Sources

  1. Gartner, “Gartner Says More Than 80% of Enterprises Will Have Used Generative AI APIs or Deployed Generative AI-Enabled Applications by 2026”, press release, 11 October 2023.
  2. Rencore multi-AI webinar and live product walkthrough, 1 October 2026. Used here for: product scope, policy examples and retention periods.

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organisation and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

Rencore does not claim that its software makes any organisation compliant with any regulation.

Common questions on this

Does Rencore read the prompts and responses in Claude Enterprise or ChatGPT Enterprise?
No. Rencore reads configuration and metadata only: users and groups, projects and who they are shared with, which model a chat used and what it cost, which connectors and plugins are in use, seats, spend and organization settings. It never reads conversation content in any assistant. That is the line between operational governance, which looks after the environment an assistant draws from, and runtime governance, which inspects prompts and responses as they happen through a proxy, a browser extension or an endpoint agent.
Is Claude Enterprise governance generally available?
Not yet. Claude Enterprise is in preview inside the AI & Agents module, and ChatGPT Enterprise is coming soon, with its preview opening on 15 October 2026. Both cover the Enterprise plans only, not Claude Team or ChatGPT Business. Existing customers with the AI & Agents module can ask their customer success manager to switch the preview on in a production or staging environment. Connection is opt in, one service at a time, so nothing is read from an assistant until you connect it.
Why does connecting Claude or ChatGPT to SharePoint make oversharing worse?
Because the assistant inherits whatever access already exists. Claude Enterprise and ChatGPT Enterprise both connect to SharePoint, OneDrive and Outlook through connectors a user can approve in a few clicks. A SharePoint site that was already shared too widely is now also reachable through every project or workspace it is connected to, and through everyone that project is shared with. The data never left Microsoft 365. What changed is the number of assistants reading it, and the number of people who can reach it through them.
Do Microsoft Purview or Entra ID already cover Claude Enterprise and ChatGPT Enterprise?
Partly. Entra ID records sign-ins for any assistant connected to it by single sign-on, and Purview protects and classifies the Microsoft 365 data those assistants read. Neither builds an inventory of what happens inside the assistant: the projects a person owns, who those projects are shared with, which artifacts are public, the connectors in use or the spend by department. Rencore adds that inventory and joins it to the Entra ID user, so the same person reads as one record across every assistant. It extends the Microsoft controls rather than replacing them.
How long do AI assistants keep their activity logs?
It varies by provider and by plan, and it is shorter than most audits need. Claude Enterprise retains activity for 30 days, so a question about what happened three months ago cannot be answered from the native log, because that history has already been purged. Collecting the activity into a store you control is the only way to answer an auditor about last quarter, and the history only starts on the day you begin collecting it.

Last updated 2 October 2026

Related articles

Rencore newsletter

Subscribe to our newsletter

Get the latest insights on governing Microsoft 365, Copilot and AI agents, delivered to your inbox.

Loading form