> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# AI Workload Discovery

> AgentGuard discovers AI workloads running across your cloud estate from existing telemetry and presents a ranked inventory with risk scoring and per-workload attributes.

AI Workload Discovery is the inventory capability of AgentGuard. It discovers AI
workloads from existing Aviatrix Cloud telemetry and presents a ranked inventory
with per-workload attributes and risk scoring.

## What It Discovers

AgentGuard discovers workloads that exhibit AI behavior, such as AI agents and
the model or LLM endpoints they call, across managed platforms, Kubernetes,
serverless, and virtual machines. Discovery reads existing telemetry rather than
requiring SDK adoption or an in-guest agent. It surfaces both sanctioned and
shadow AI workloads.

Each discovered workload is tagged with the AI sub-types it exhibits. A workload
may hold several sub-types simultaneously.

## Workload Identity

Each workload is keyed to a stable identity derived from details that do not
change when the workload restarts or moves, unlike its IP address. For how the
identity is built, see
[Architecture](/docs/cloud/security/agentguard/agentguard-architecture#workload-identity).

<Note>
  Correlate AgentGuard data with other systems on the workload identity,
  not on IP address. IP addresses change as workloads reschedule; the identity does not.
</Note>

## Workload Attributes

For each discovered workload, AgentGuard records the following attributes:

* Name, Kubernetes namespace, and workload type
* AI type and AI vendor
* Cloud provider, region, and VPC
* Resource tags
* Risk level
* Associated underlying cloud resources: pods, instances, deployments, and
  container images

## Risk Scoring

AgentGuard assigns a risk level to each workload to prioritize
which workloads to contain first. Risk scoring weighs two factors: Topology and
Traffic.

<Note>
  Traffic scoring is not yet active in this release. Until it ships, the risk
  score reflects Topology only.
</Note>

The risk score maps to four risk levels:

| Risk Level | Score Range |
| - | - |
| Low | 0–30 |
| Medium | 31–60 |
| High | 61–80 |
| Critical | 81–100 |

Use the risk level to guide remediation order rather than treating all
discovered workloads equally.

## Hand-Off to Enforcement

Every discovered workload is addressable by
[SmartGroups](/docs/cloud/resource-groups/smartgroup/smartgroups-about). The
inventory becomes the source set for
[Distributed Cloud Firewall](/docs/cloud/security/dcf/about-dcf-security)
containment without re-modeling workload identity.

## Related Topics

* [AgentGuard](/docs/cloud/security/agentguard/agentguard-overview)
* [AI Traffic Flow Analytics](/docs/cloud/security/agentguard/agentguard-traffic-analytics)
* [Manage SmartGroups](/docs/cloud/resource-groups/smartgroup/smartgroups-about)
* [Protect Your Traffic with Distributed Cloud Firewall](/docs/cloud/security/dcf/about-dcf-security)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.