We're rolling out enterprise Claude company-wide and want it to be the only tool employees can use on work machines.
I recently found that a salesperson was putting company data into personal ChatGPT, this was client names, their whole worksheets; scary stuff on the data-leak front. So a decision has been made to use Claude. I've been tasked with making sure this sort of thing does not happen again, and to get the groundwork done to stop all "unauthorized AI tools".
Honestly, I'm at a loss here. There is no DLP, at least not right now, and implementing it will be a significant lift both in terms of work and $$$ (which we can't do because of austerity measures). So, I'm stuck with having to look at band-aid solutions via firewall web-filter or DNS filtering – again, I don't have a starting point.
We're a Fortinet shop, no Intune, hybrid AD, Claude SSO through Entra.
Appreciate any real-world war stories.
ETA: I understand that this is more a policy question and I'm working on that in parallel. This is more of a question on technical controls without capital spend *sigh*.
submitted by /u/tdiz009 to r/sysadmin
[link] [comments]
Source: r/sysadmin · by /u/tdiz009