How AgentGuard Works
AgentGuard correlates that telemetry into a stable workload identity and a view of AI traffic, then feeds both into SmartGroups so Distributed Cloud Firewall can enforce policy. For the underlying mechanism, see Architecture. AgentGuard produces two views:- AI Workload Discovery — a list of every AI workload AgentGuard finds, ranked by how much risk each one could create, so you know which ones to look at first.
- AI Traffic Flow Analytics — a view of what each AI workload is actually talking to on the network, including which company or AI service it is reaching.
AgentGuard rolls out in phases, so not every capability described here may be
available yet. Check the release notes or product notifications from Aviatrix
for the current status of each capability.
Use Cases
Situations where AgentGuard helps:- Finding AI tools you did not know about. Teams across your company may try out new AI tools faster than security can track them. AgentGuard finds these tools automatically, without waiting for anyone to ask permission or install software.
- Checking where your AI traffic goes before writing rules. Before you decide which destinations to allow or block, AgentGuard shows you what your AI workloads are already doing, so your rules match real behavior instead of guesswork.
- Getting ready to enforce policy. Discovered workloads carry the attributes you need to build a SmartGroup, so you can create a Distributed Cloud Firewall policy around real AI workloads instead of guessing identities.
- Tracking workloads that change often. Because AgentGuard identifies each workload from logs instead of by IP address, it keeps following the same workload even after it restarts, scales, or gets a new IP address, so you do not end up with duplicate or missing entries in your workload list.