Scan AI assets on endpoints, identify risky endpoints, and enforce security controls through the SASE console to manage AI agent usage compliance.
Use cases
SASE Agent management helps you manage AI agents across your organization. Use it when you need to:
-
Inventory all AI agents and tools installed on endpoints.
-
Isolate high-risk endpoints quickly to speed up incident response.
-
Control which AI agents can run on managed endpoints.
Solution overview
Agent management has three phases: asset scanning, risk identification, and security control enforcement.
|
Phase |
Description |
|
Scan assets |
Scan endpoints for installed AI agents, LLMs, tools, and skills to build an asset inventory. |
|
Identify risks |
Automatically identify risky assets after the scan completes. |
|
Enforce controls |
Analyze identified risks and deploy security control policies based on risk severity. |
Prerequisites
Before you begin, ensure that:
-
AI agent clients are installed on the target endpoints, such as Claude Code, OpenClaw, or OpenCode.
-
You have SASE console administrator access.
Step 1: Scan AI assets
Scan endpoints for installed AI agents and related components to build an asset inventory and identify risky AI assets.
Start a scan
-
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, choose Agent Office Security > AI Asset Management.
-
On the AI Asset Management page, click Configure in the upper-right corner.
-
In the Quick Scan Configuration dialog box, configure the following parameters:
Parameter
Description
Enable Scan Task
Enable the scan task.
Enable Agent Security Scan
When enabled, also scans the skills associated with AI agents on endpoints.
Scan Scope
The scan scope. Options: All Users or Specific User Group.
-
Click Start Scan.
View scan results
After the scan completes, click Visual Analytics in the upper-right corner of the AI Asset Management page to view the Top 5 AI Asset Installations and Pending Threats.
Click List in the upper-right corner and use the AI Agents, LLMs, Tools, and Skills tabs to view details of each asset type, including associated employees and endpoints.
Export asset data
To export scan results for offline analysis or compliance auditing, go to the AI Asset Management page:
-
Click List in the upper-right corner, and select the AI Agents, LLMs, Tools, or Skills tab.
-
Click Export Threats.
-
Export All: Export all assets under the current tab.
-
Export by Search Conditions: Export only assets that match the current search filters.
-
-
Click Export Task to view all tasks, locate the target task, and download the results.
Step 2: Analyze agent risks
Create risk analysis policies to identify security risks from AI agents on your endpoints.
-
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, choose Security Operations > Risk Analysis.
-
On the Analysis Policy tab, click Create Policy.
-
In the Create Policy panel, configure the following parameters:
Parameter
Description
Effective Scope
The user groups to which this policy applies. Configure user groups on the Identity Authentication tab under Identity Access > User Group Management.
Risk Scenario
The risk analysis scenario template. Select an option under Agent Security.
Step 3: Enforce security controls
After identifying risky AI assets, create security control policies to block or monitor specific agent programs based on risk severity.
-
On the AI Asset Management page, click Control Policies in the upper-right corner.
-
Click Create Policy.
-
In the Create Policy panel, configure the following parameters:
Parameter
Description
Action
The action to take when a managed agent program runs:
-
Block Startup: Blocks the agent program from starting.
-
Prompt Only: Shows a pop-up alert without blocking the launch.
Scope
The policy scope:
-
Specific User Group: Apply to specified user groups.
-
Specific Device: Apply to specified devices.
-
All Users: Apply to all users.
Exception User
Users excluded from this policy.
Management Agent
The agent programs to manage. You can select multiple.
Priority
The policy priority. A smaller value indicates a higher priority. When multiple policies apply to the same agent, the highest-priority policy takes effect.
Prompt Display Configuration
The alert message shown when a managed agent program runs. The pop-up alert appears regardless of the policy action.
-