Skip to content
Status

Secure · Secure

Secure

Detect and control risk in agent sessions: risk analytics, policies, findings, shadow MCP inventory, and detection rules.

The Secure section of the dashboard detects and controls risk in agent sessions. Policies scan session interactions for secrets, sensitive data, prompt injection, destructive tool use, and unsanctioned MCP servers — then flag or block what they find. Findings feed risk analytics, per-session review, and an inventory of shadow MCP servers discovered in agent traffic.

Secure pages require the organization admin role.

The risk dashboard: findings clustered into ranked signals, with headline metrics, exposure by data type, and suppression and exclusion actions. Any finding opens the full session transcript for investigation. Watchdog replaces the former Risk Overview page.

The finding-level log: every policy finding across recently analyzed sessions, one row per finding, with redacted matches, filters, and a risk-focused session view for investigating any single finding.

Create and manage the policies that scan agent sessions. A stepped editor configures what to detect, which sessions are in scope, whether to flag or block, severity, sensitivity, and audience — including natural-language guardrail policies. Detection rules and exclusion rules live here as tabs.

An inventory of unsanctioned MCP servers discovered in agent traffic, each with an evidence-backed access review: gathered evidence, member requests, optional cited web research, and approve/deny decisions enforced across blocking policies.

The catalog of built-in detectors behind guardrail policies — secrets, financial data, PII, healthcare, prompt injection, and more — plus custom rule authoring with CEL expressions, live testing, and AI-suggested rules. Lives as a tab on the Guardrails page.

The rules that suppress false-positive findings: expression criteria, global or per-policy scope, a built-in library of known-safe values, and one-click creation from a Watchdog signal or session transcript. Lives as a tab on the Guardrails page.

Additional security controls live in the organization settings rather than the project Secure group: audit logs, roles and permissions (RBAC), SSO and directory sync, remote identity providers for MCP authentication, API keys, and active MCP connection management.