SAGA — Frequently Asked Questions

Need Help?

Have a question not covered here? We’ll tell you upfront if SAGA is the right fit for your situation.

Frequently Asked Question

SAGA — the Spartan AI Governance Audit, is a three-layer methodology built specifically to assess how AI tools are operating in your environment. Layer 1 inventories every AI tool across four asset classes: Sanctioned, Shadow, Embedded, and Agentic. Layer 2 scores each tool's access and authority across five dimensions using a weighted risk model. Layer 3 assesses governance maturity across eight evidence-based dimensions and produces a maturity level from 1 to 4. A standard security audit evaluates your existing controls against a framework. SAGA evaluates something most audits ignore entirely, the AI tools that have been granted access, authority, and autonomy inside your environment without a governance structure to manage them.

Because your existing security program almost certainly wasn't built with AI tools in scope. Most security programs were designed to evaluate networks, endpoints, identity systems, and applications. AI tools, especially Shadow AI adopted by employees and Embedded AI activated by vendors without deliberate organizational decision, fall outside the visibility of traditional controls. A mature security program with no AI governance is like a building with excellent locks on every door and an open window on the third floor. SAGA finds the window.

  1. Shadow AI discovery is built into Layer 1 of SAGA and is one of the most consistently valuable outputs of the engagement. We use a tiered discovery methodology that prioritizes technical evidence over self-reporting. Tier 1 analyzes existing tooling, SIEM logs, EDR telemetry, identity provider OAuth grants, CASB and DLP logs, and browser extension inventories, to identify AI tools operating under corporate credentials without IT knowledge. Tier 2 uses DNS and network traffic analysis when Tier 1 coverage has gaps. The result is an inventory built from evidence, not from asking employees what tools they use. In practice, organizations are consistently surprised by what we find.

The standard SAGA engagement runs three weeks. Week 1 is discovery, Week 2 is assessment, Week 3 is reporting and delivery. Engagements run after hours and on weekends by default to avoid operational disruption. Pricing is scoped per engagement based on your environment size, regulatory obligations, and discovery complexity. We don't publish flat rates for methodology engagements because a 150-person insurance firm and a 1,500-person healthcare organization are fundamentally different scopes. Contact us for a scoping call, there's no obligation and we'll tell you upfront if SAGA is the right fit for your situation.

Every SAGA engagement produces two deliverables. The Executive Scorecard is a one-page board-ready document that communicates your AI maturity level, top risks in plain business language, governance gap summary across all eight dimensions, and priority actions. No jargon. Designed for your CEO, board, or audit committee. The Technical Findings Report is the full evidence-based document for your CISO, IT security team, and compliance function. Every finding includes a unique finding ID, severity rating, observation, risk implication, recommended action, effort level, and supporting evidence. No boilerplate filler. No findings invented to pad the report. Preliminary findings are shared with your technical lead at the end of Week 2 for validation before the final report is produced.

NIST AI RMF and ISO 42001 are prescriptive frameworks, they define what controls should exist and apply uniform requirements regardless of your environment. If a control is absent, the finding is the same whether you have ten compensating controls or none. SAGA takes a fundamentally different approach. Every finding is assessed in full operational context. A missing policy in an environment with no other controls is a Critical finding. The same missing policy in an environment with hardware token authentication and conditional access policies is a Low observation. SAGA accounts for this because mid-market organizations operate under real resource constraints and make real tradeoffs. The methodology doesn't prescribe which risks to accept, it identifies the gaps, quantifies the exposure, and gives your leadership the information to make informed decisions. SAGA is also practitioner-led and evidence-based, findings require documented evidence, not self-reported compliance.

Ready to see what's running in your environment?

Most organizations are surprised by what a SAGA assessment finds. Schedule a scoping call, no obligation, no template proposals. We'll tell you upfront whether SAGA is the right fit.