ethira

Resources

Notes on the ICT estate.

How vendors, systems, agents, and data flows actually get governed. Written for security, legal, and GRC: one audience, one picture.

DORAJul 2026

Registers go stale

DORA Registers of Information fail when they are homework. A living graph makes reporting day an export.

Read
TPRMJun 2026

The vendor is the agent

Third parties now act through agents. TPRM that stops at the vendor row misses the new entity.

Read
RegulatoryJun 2026

OWASP's Agentic AI Report Shows Governance Needs Instrumentation

OWASP's State of Agentic AI Security and Governance shows that agent failures are now production incidents, not hypotheticals. The operational answer starts with inventory, observability, unified telemetry, and defensible reporting.

Read
ResearchMay 2026

2nd Party Risk: Same Fundamentals, Shifting Ground

AI-assisted development tools have created a new asset class that sits between first-party and third-party risk. The fundamentals of security still apply — discover, review, monitor, prove — but the surface they must cover has fundamentally changed.

Read
ResearchMay 2026

Governance Isn’t a Dashboard. It’s Instrumentation.

Policy-first AI governance fails because you are asked to govern something you cannot see. The case for building real accountability from discovery, observability, and proof — not frameworks and dashboards.

Read
How-toMay 2026

Govern MCP Tools from Slack: Request, Review, Onboard, and Offboard Without Leaving the Channel

MCP tool sprawl is the fastest-growing source of shadow AI risk in agent-first organisations. Ethira's Slack integration puts the full tool lifecycle — request, review, approve, onboard, and offboard — into the channel your team already works in, with a complete audit trail behind every decision.

Read
RegulatoryMay 2026

Shadow Subcontractors: The Hidden Vendors Inside Your SaaS Tools

Every SaaS tool your employees use talks to dozens of other services you never vetted. This post explains why those hidden fourth-party vendors are a compliance liability under GDPR and DORA, and how the Ethira browser extension surfaces them automatically.

Read
How-toMay 2026

How to Find Shadow AI and Shadow SaaS in Your Organisation

The average enterprise runs 261 unsanctioned applications before it knows they exist. This guide explains how SSO integration and a browser extension surface every AI and SaaS tool your workforce is using — and who owns each one.

Read
TechnicalMay 2026

How to Connect the Ethira MCP to Claude and Manage Your Inventory

A five-minute walkthrough for connecting your Ethira workspace to Claude.ai as a custom connector, then using Claude to keep your systems, products, datasets, and microservices inventory current — without leaving the chat.

Read
TechnicalMay 2026

When a Company MCP Server Meets a Personal ChatGPT Account

MCP lets any employee connect a corporate SaaS — GitHub, Jira, Salesforce — to their personal ChatGPT account in under two minutes. This post explains why traditional security tools miss it entirely, and how the Ethira browser extension detects it through five correlated browser-level signals.

Read

Newsletter

The estate does not wait.

Notes on ICT governance: vendors, systems, agents, and the data that moves between them. For security, legal, and GRC sharing one picture.