What It Discovers
AgentGuard discovers workloads that exhibit AI behavior, such as AI agents and the model or LLM endpoints they call, across managed platforms, Kubernetes, serverless, and virtual machines. Discovery reads existing telemetry rather than requiring SDK adoption or an in-guest agent. It surfaces both sanctioned and shadow AI workloads. Each discovered workload is tagged with the AI sub-types it exhibits. A workload may hold several sub-types simultaneously.Workload Identity
Each workload is keyed to a stable identity derived from details that do not change when the workload restarts or moves, unlike its IP address. For how the identity is built, see Architecture.Correlate AgentGuard data with other systems on the workload identity,
not on IP address. IP addresses change as workloads reschedule; the identity does not.
Workload Attributes
For each discovered workload, AgentGuard records the following attributes:- Name, Kubernetes namespace, and workload type
- AI type and AI vendor
- Cloud provider, region, and VPC
- Resource tags
- Risk level
- Associated underlying cloud resources: pods, instances, deployments, and container images
Risk Scoring
AgentGuard assigns a risk level to each workload to prioritize which workloads to contain first. Risk scoring weighs two factors: Topology and Traffic.Traffic scoring is not yet active in this release. Until it ships, the risk
score reflects Topology only.
Use the risk level to guide remediation order rather than treating all
discovered workloads equally.