Skip to main content
Oriant is a Shadow AI inventory and control plane for managed macOS devices. The Oriant Agent is a tunnel-only HTTPS system proxy. It identifies traffic to catalogued AI providers, attributes it to the machine’s stamped identity, and sends aggregated metadata to Oriant. You can then review your company’s AI surface and set each provider to Unsanctioned, Sanctioned, or Blocked.

Connect a machine

Install the Agent on one macOS machine with a single-use enrollment command.

Deploy your fleet

Generate the Intune deployment artifacts for managed macOS machines.

What Oriant records

Oriant stores the matched provider, stamped identity, originating app when macOS can resolve it, time bucket, request count, byte totals, and whether the connection was allowed or blocked. It never stores prompts, responses, request bodies, URL paths, query strings, or headers. The Agent does not decrypt TLS. It sees the destination from the HTTPS CONNECT request and relays the encrypted connection when it is allowed.

What happens next

  1. Connect a machine to confirm the Agent is reporting.
  2. Review detected providers in AI Tools.
  3. Set their sanction state to match your policy.
Last modified on July 18, 2026