Skip to main content
AgentGuard ships in phases rather than as a single release. This page tracks which capabilities are available in the current phase.
AgentGuard is an Early Access capability.

Current Phase: Phase 1

Phase 1 focuses on read-only discovery and analytics: finding AI workloads, showing what they talk to, and scoring risk, so you have the information you need before you write enforcement policy.
  • Cloud support: AWS only. Support for additional clouds is planned for a future phase.

Available in Phase 1

  • AI workload discovery — AgentGuard reads existing gateway logs, VPC flow logs, and cloud resource inventory to find AI workloads across managed platforms, Kubernetes, serverless, and virtual machines, without installing software on the workloads. See AI Workload Discovery.
  • Stable, identity-based workload identity — Each workload is keyed to a identity of stable details rather than its IP address, so AgentGuard keeps tracking the same workload after it restarts, scales, or gets a new IP address.
  • Risk scoring — Every discovered workload gets a risk level (Low, Medium, High, or Critical) so you know which ones to review first.
    Risk scoring weighs Topology and Traffic. Traffic scoring is not yet active in Phase 1, so the risk score currently reflects Topology only.
  • AI Traffic Flow Analytics — A Sankey traffic map and source-to-destination flow view built from DCF logs and VPC flow logs, with DCF, VPC, and Merged source modes. See AI Traffic Flow Analytics.
  • AI protocol classification — When a gateway is in path and Distributed Cloud Firewall inspects the traffic, AgentGuard classifies traffic by the LLM, MCP, and Agent protocol families. Without a gateway, destinations are attributed to AI vendors by FQDN instead.
  • Two levels of visibility — Basic visibility (no network changes) or deep visibility and enforcement with a gateway. See Get Basic Visibility Without a Gateway and Get Deep Visibility and Enforcement With a Gateway.
  • Hand-off to enforcement — Every discovered workload is addressable by SmartGroups, so you can build a Distributed Cloud Firewall policy — using the built-in avx-ai-* WebGroups or your own — to allow, block, and inspect AI traffic. See Get Deep Visibility and Enforcement With a Gateway.
  • AgentGuard console — AgentGuard is accessible directly from the Cloud Console.

Not Yet Available

The following capabilities are planned for later phases and are not part of Phase 1. Do not write processes or integrations that depend on them yet.
  • Discovering AWS Bedrock or Azure AI Foundry directly as cloud assets, and showing whether access is by private endpoint or public path
  • Guided SmartGroup and WebGroup creation from discovery findings, and sanctioned / unsanctioned / monitor classification of AI destinations
  • Inline guardrail enforcement — for example, prompt-injection, PII, or content-policy checks from providers such as AWS Bedrock Guardrails or HiddenLayer
  • Screening of MCP tool arguments and agent-to-agent (A2A) tasks
  • A verdict-logging dashboard, fail-open / fail-closed controls, and SIEM integration for enforcement actions
  • Executive-level audit and compliance reporting
  • Support for clouds other than AWS