Skip to main content
AI Workload Discovery is the inventory capability of AgentGuard. It discovers AI workloads from existing Aviatrix Cloud telemetry and presents a ranked inventory with per-workload attributes and risk scoring.

What It Discovers

AgentGuard discovers workloads that exhibit AI behavior, such as AI agents and the model or LLM endpoints they call, across managed platforms, Kubernetes, serverless, and virtual machines. Discovery reads existing telemetry rather than requiring SDK adoption or an in-guest agent. It surfaces both sanctioned and shadow AI workloads. Each discovered workload is tagged with the AI sub-types it exhibits. A workload may hold several sub-types simultaneously.

Workload Identity

Each workload is keyed to a stable identity derived from details that do not change when the workload restarts or moves, unlike its IP address. For how the identity is built, see Architecture.
Correlate AgentGuard data with other systems on the workload identity, not on IP address. IP addresses change as workloads reschedule; the identity does not.

Workload Attributes

For each discovered workload, AgentGuard records the following attributes:
  • Name, Kubernetes namespace, and workload type
  • AI type and AI vendor
  • Cloud provider, region, and VPC
  • Resource tags
  • Risk level
  • Associated underlying cloud resources: pods, instances, deployments, and container images

Risk Scoring

AgentGuard assigns a risk level to each workload to prioritize which workloads to contain first. Risk scoring weighs two factors: Topology and Traffic.
Traffic scoring is not yet active in this release. Until it ships, the risk score reflects Topology only.
The risk score maps to four risk levels: Use the risk level to guide remediation order rather than treating all discovered workloads equally.

Hand-Off to Enforcement

Every discovered workload is addressable by SmartGroups. The inventory becomes the source set for Distributed Cloud Firewall containment without re-modeling workload identity.