Mentorloop adopts RexCommand to curb shadow AI use
Sun, 19th Jul 2026 (Yesterday)
Mentorloop has adopted RecordPoint's RexCommand to manage its AI inventory and govern internal AI use, aiming to address shadow AI and support its product plans.
The mentoring software provider turned to the system after finding AI use had spread across its operations, from engineering to its matching tools. An initial attempt to track usage in a spreadsheet was dropped in favour of a centralised platform.
Mentorloop said its 76-person software-as-a-service team created an AI inventory within 30 days and registered 11 AI systems in the first month. It said the approach avoided about USD $150,000 a year in costs, which would typically cover a dedicated AI governance hire working with a governance, risk and compliance consultancy.
Tracy Bongiorno, Chief Technology Officer at Mentorloop, described the point at which the company changed course. "We had got to the point where we were starting to put together a spreadsheet," Bongiorno said. "Then the RecordPoint webinar for RexCommand came up. We liked the idea, and it solved the problem. We abandoned the spreadsheet and set up RexCommand."
Shadow AI
Mentorloop said its main problem was not deliberate policy breaches by staff, but a lack of visibility over which tools were being used. Employees had been experimenting with a range of AI products, including Claude, HubSpot AI, Google AI and other specialist applications.
RexCommand is being used to catalogue approved AI tools, connect them to the datasets they access, assess risk and route requests for new tools through approval workflows. Staff can submit new AI tools through a public internal portal, which guides requests and sends them to the leadership team for review.
The system was introduced through the company's regular security and privacy training. Bongiorno said the organisation's size made it easier to identify where AI was being used and bring it into a managed process.
"As a small team, shadow AI is much more measurable than it would be in a 400, 4,000, or 400,000-person team," Bongiorno said. "It was more about finding out what tools were in active use, then putting that into a system where we could clearly say what's approved, what's not approved, and employees could request new tools if they were interested in trying something out."
She said the result was better visibility across the business. "The team now has a single source of truth where they can see what tools are in use and the business value we get from them," Bongiorno said. "Anyone can explore and better understand our AI tech stack."
Data controls
Mentorloop handles information including professional profiles, career goals, workplace preferences and self-reported development needs. That means its AI governance work sits alongside broader questions about where personal data is sent and how it is used.
By linking AI tools to associated datasets, the company said it can apply a more consistent view of risk across its systems. The process is designed to reduce the chance that sensitive information is routed through unapproved tools and to maintain tighter control over customer data.
Bongiorno said data handling remained central to any decision about AI use. "When data is involved, you always have to think about how you're treating it. What kind of data is it, how sensitive it is, what it's being used for," she said. "We have to have that lens and then make decisions about which data can go where."
Agentic plans
The adoption also comes as Mentorloop moves towards more automated and agentic workflows in its product. The company said it is working on features that suggest actions for participants, programme managers and mentors, while keeping a person responsible for final decisions.
One example is the core mentoring match process, where a human still approves each match before it is enacted. That reflects a broader approach in which automation may propose steps, but staff retain oversight.
"Things are clearly moving more toward agentic," Bongiorno said. "The more we can proactively find actions or suggestions for someone to take, the easier it'll be for them to do their role. But there's always a human in the loop to take that final decision."
Mentorloop said it has also expanded its use of RexCommand into real-time prompt monitoring on Claude. The company is using custom guardrails to flag prompts involving themes such as insider trading and disability-rights language, with an option to log only violations rather than all activity.
RecordPoint said the Mentorloop deployment showed smaller organisations were also formalising AI governance. Anthony Woodward, Chief Executive Officer and Founder at RecordPoint, said: "Organisations like Mentorloop are proof that you don't need to be an enterprise to take AI governance seriously. Tracy and her team have built real rigour into how they manage data and AI, and we're proud to help make that easier."
RecordPoint said it now handles nearly four billion records globally and processes more than 15 million data transactions a day.