> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Overview

> AgentGuard automatically finds the AI tools running across your cloud accounts and shows what network traffic they generate, without installing any software on those workloads.

AgentGuard is a feature of the Aviatrix [Cloud Native Security Fabric (CNSF)](/docs/enterprise/10.1/concepts-architectures/CNSF/index)
that automatically finds the AI tools and services running across your cloud
accounts and shows you what network traffic they generate. AgentGuard gathers
this information from the telemetry that your cloud provider and your Aviatrix
gateways already collect, so you do not need to install any software on your AI
workloads.

AgentGuard only watches and reports. It does not block or change any traffic
itself. To control what an AI workload can reach, use
[Distributed Cloud Firewall](/docs/cloud/security/dcf/about-dcf-security)
together with the information AgentGuard provides.

## How AgentGuard Works

AgentGuard correlates that telemetry into a stable workload identity and a
view of AI traffic, then feeds both into
[SmartGroups](/docs/cloud/resource-groups/smartgroup/smartgroups-about) so
[Distributed Cloud Firewall](/docs/cloud/security/dcf/about-dcf-security) can
enforce policy. For the underlying mechanism, see
[Architecture](/docs/cloud/security/agentguard/agentguard-architecture).

AgentGuard produces two views:

* **[AI Workload Discovery](/docs/cloud/security/agentguard/agentguard-workload-discovery)**
  — a list of every AI workload AgentGuard finds, ranked by how much risk
  each one could create, so you know which ones to look at first.
* **[AI Traffic Flow Analytics](/docs/cloud/security/agentguard/agentguard-traffic-analytics)**
  — a view of what each AI workload is actually talking to on the network,
  including which company or AI service it is reaching.

<Note>
  AgentGuard rolls out in [phases](/docs/cloud/security/agentguard/agentguard-release-phases), so not every capability described here may be
  available yet. Check the release notes or product notifications from Aviatrix
  for the current status of each capability.
</Note>

## Use Cases

Situations where AgentGuard helps:

* **Finding AI tools you did not know about.** Teams across your company may try
  out new AI tools faster than security can track them. AgentGuard finds these
  tools automatically, without waiting for anyone to ask permission or install
  software.
* **Checking where your AI traffic goes before writing rules.** Before you
  decide which destinations to allow or block, AgentGuard shows you what your AI
  workloads are already doing, so your rules match real behavior instead of
  guesswork.
* **Getting ready to enforce policy.** Discovered workloads carry the attributes
  you need to build a SmartGroup, so you can create a Distributed Cloud Firewall
  policy around real AI workloads instead of guessing identities.
* **Tracking workloads that change often.** Because AgentGuard identifies each
  workload from logs instead of by IP address, it keeps following the
  same workload even after it restarts, scales, or gets a new IP address, so you
  do not end up with duplicate or missing entries in your workload list.

## Related Topics

* [AI Workload Discovery](/docs/cloud/security/agentguard/agentguard-workload-discovery)
* [AI Traffic Flow Analytics](/docs/cloud/security/agentguard/agentguard-traffic-analytics)
* [Protect Your Traffic with Distributed Cloud Firewall](/docs/cloud/security/dcf/about-dcf-security)
* [Manage SmartGroups](/docs/cloud/resource-groups/smartgroup/smartgroups-about)
* [Manage WebGroups](/docs/cloud/resource-groups/webgroups/webgroups-about)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.