Worked Example⬇ Download .md

Grace Hill — Assumed Internal Estate

A modeled internal technology estate for a mature mid-market property-management compliance & training SaaS company — every entry ASSUMED, none confirmed.

Confidential · June 2026. This document MODELS a plausible internal estate inferred from Grace Hill's public business profile (property-management compliance & training SaaS that ships "Gracie," a generative-AI assistant; CTO Chris Fontan; AI-forward leadership). It is ASSUMED / illustrative — every technology, vendor, region, and figure below is a reasoned guess about what a company of this shape typically runs, NOT a confirmed fact about Grace Hill's actual environment. The only confirmed inputs are public OSINT. All assumptions are replaced with measured fact the moment Aperture connectors run live; until then this is a discovery hypothesis, not a record.

How to read this

The govrn assessment never starts from a questionnaire. It starts from an estate hypothesis — what a company like this probably runs — which Aperture then confirms or corrects against actual metadata. This document is that hypothesis for Grace Hill, written so the delivery team can pre-stage connectors, anticipate the three lenses (Technology, Security, AI), and predict where shadow AI hides before the first connector authenticates.

Read every "Vendor (ASSUMED)" entry as "we expect to find one of these; we will know which when we measure."

Cloud & infrastructure (ASSUMED)

ComponentAssumed vendor / shapeLensWhy we assume it
Primary cloudAzure or AWS, single primary + DR region (e.g. East US 2 + Central US, or us-east-1 + us-west-2)TechnologyMid-market B2B SaaS norm; Azure tilt if Microsoft-centric (see identity)
Data residencyUS-only; SOC 2 / tenant-data isolation expectedSecurityFair-housing + tenant PII raises residency stakes
IaCTerraform or Bicep/ARM; partial coverage, drift likelyTechnologyMature-but-not-perfect IaC is the mid-market default
Edge / CDNCloudflare or Azure Front DoorTechnologyStandard public-app fronting

Product & development stack (ASSUMED)

ComponentAssumed vendor / shapeLens
Web applicationMulti-tenant SaaS (React/TypeScript front end; .NET or Node services)Technology
Services / APIREST + some async workers; relational core (SQL Server or PostgreSQL)Technology
Source control + CI/CDGitHub or Azure DevOps (Azure tilt likely); pipelines with uneven gatingTechnology + Security
Artifact / packageGitHub Packages / Azure Artifacts; container registrySecurity
ObservabilityDatadog, App Insights, or Grafana stackTechnology
The CI/CD lens question is not "do they deploy?" — it's what gate, if any, sits between a model-prompt change and production. For a company shipping Gracie, that gate is the AI-lens crux.

AI footprint (ASSUMED) — where the engagement earns its fee

ComponentAssumed vendor / shapeLensShadow-AI exposure
Gracie LLM pipelineRetrieval + generation over compliance/training content; prompt-orchestration layerAI (product)The shipped product — primary attestation target
Foundation-model APIsAnthropic, OpenAI, and/or Azure OpenAI; possibly more than one, undocumentedAIMultiple provider keys = multiple egress paths to inventory
AI gateway / proxyPossibly none — direct SDK callsAI + SecurityNo gateway = no central log, no cost attribution
Employee coding AIGitHub Copilot, CursorAICode + snippets to third-party models, often un-reviewed
Employee chat AIChatGPT (personal and Enterprise unclear), Claude, GeminiAIHighest shadow-AI risk — tenant/fair-housing text pasted into consumer tools
Embedded vendor AIAI features inside CRM, support, M365 CopilotAI"Accidental" AI no one inventoried

Where shadow AI hides (our prior): unmanaged personal ChatGPT/Claude logins on corporate identities; a second model provider used by one team and unknown to security; Copilot/Cursor on repos touching tenant data; M365 Copilot quietly enabled; direct provider SDK calls with no gateway, so no one can answer "how much are we spending on inference, and on what." Aperture's job is to surface each with a dollar figure and a control gap.

Business SaaS (ASSUMED)

ComponentAssumed vendor / shapeLens
Productivity / emailMicrosoft 365 (Azure tilt) or Google WorkspaceTechnology + Security
CRMSalesforce or HubSpotTechnology
Support / ticketingZendesk or IntercomTechnology
HR / HRISWorkday, Bambo.HR, or RipplingSecurity
Data warehouseSnowflake (assumed) or Azure SynapseTechnology + AI
BIPower BI or TableauTechnology

Identity (ASSUMED)

ComponentAssumed vendor / shapeLens
IdP / SSOMicrosoft Entra ID (most likely) or OktaSecurity
MFA / conditional accessEnforced for admins; coverage gaps for contractors likelySecurity
ProvisioningSCIM partial; orphaned accounts a standing riskSecurity

Identity is the spine of the AI lens: every shadow-AI tool is reached through some login. If SSO doesn't front the model providers and AI tools, there is no chokepoint — and no record.

Data classes (ASSUMED) — what raises the stakes

ClassExampleSensitivity driver
Employee PIIHRIS, payrollStandard regulatory
Tenant / resident dataScreening inputs, applications, demographicsFair-housing exposure
Fair-housing-sensitiveAnything feeding tenant-screening or housing decisionsDiscrimination & disparate-impact liability — Gracie's core risk
Customer (PM-company) dataMulti-tenant SaaS recordsContractual isolation duties
Source & secretsRepos, keys, model credentialsBreach + model-egress risk

What the team does with this

This estate hypothesis pre-loads the engagement: connectors are staged against the assumed identity, cloud, and AI providers above, then run to measure. The delta between this modeled estate and the measured record is the assessment finding. Until connectors authenticate, every line here stays labeled ASSUMED / illustrative — and the first deliverable to Grace Hill is the corrected, measured version of this exact table.

See also: The Three Lenses · Aperture Engine · Shadow-AI Discovery