AI agent management best practices

更新时间:
复制 MD 格式

Scan AI assets on endpoints, identify risky endpoints, and enforce security controls through the SASE console to manage AI agent usage compliance.

Use cases

SASE Agent management helps you manage AI agents across your organization. Use it when you need to:

  • Inventory all AI agents and tools installed on endpoints.

  • Isolate high-risk endpoints quickly to speed up incident response.

  • Control which AI agents can run on managed endpoints.

Solution overview

Agent management has three phases: asset scanning, risk identification, and security control enforcement.

Phase

Description

Scan assets

Scan endpoints for installed AI agents, LLMs, tools, and skills to build an asset inventory.

Identify risks

Automatically identify risky assets after the scan completes.

Enforce controls

Analyze identified risks and deploy security control policies based on risk severity.

Prerequisites

Before you begin, ensure that:

  • AI agent clients are installed on the target endpoints, such as Claude Code, OpenClaw, or OpenCode.

  • You have SASE console administrator access.

Step 1: Scan AI assets

Scan endpoints for installed AI agents and related components to build an asset inventory and identify risky AI assets.

Start a scan

  1. Log on to the Secure Access Service Edge console.

  2. In the left-side navigation pane, choose Agent Office Security > AI Asset Management.

  3. On the AI Asset Management page, click Configure in the upper-right corner.

  4. In the Quick Scan Configuration dialog box, configure the following parameters:

    Parameter

    Description

    Enable Scan Task

    Enable the scan task.

    Enable Agent Security Scan

    When enabled, also scans the skills associated with AI agents on endpoints.

    Scan Scope

    The scan scope. Options: All Users or Specific User Group.

  5. Click Start Scan.

View scan results

After the scan completes, click Visual Analytics in the upper-right corner of the AI Asset Management page to view the Top 5 AI Asset Installations and Pending Threats.

Click List in the upper-right corner and use the AI Agents, LLMs, Tools, and Skills tabs to view details of each asset type, including associated employees and endpoints.

Export asset data

To export scan results for offline analysis or compliance auditing, go to the AI Asset Management page:

  1. Click List in the upper-right corner, and select the AI Agents, LLMs, Tools, or Skills tab.

  2. Click Export Threats.

    • Export All: Export all assets under the current tab.

    • Export by Search Conditions: Export only assets that match the current search filters.

  3. Click Export Task to view all tasks, locate the target task, and download the results.

Step 2: Analyze agent risks

Create risk analysis policies to identify security risks from AI agents on your endpoints.

  1. Log on to the Secure Access Service Edge console.

  2. In the left-side navigation pane, choose Security Operations > Risk Analysis.

  3. On the Analysis Policy tab, click Create Policy.

  4. In the Create Policy panel, configure the following parameters:

    Parameter

    Description

    Effective Scope

    The user groups to which this policy applies. Configure user groups on the Identity Authentication tab under Identity Access > User Group Management.

    Risk Scenario

    The risk analysis scenario template. Select an option under Agent Security.

Step 3: Enforce security controls

After identifying risky AI assets, create security control policies to block or monitor specific agent programs based on risk severity.

  1. On the AI Asset Management page, click Control Policies in the upper-right corner.

  2. Click Create Policy.

  3. In the Create Policy panel, configure the following parameters:

    Parameter

    Description

    Action

    The action to take when a managed agent program runs:

    • Block Startup: Blocks the agent program from starting.

    • Prompt Only: Shows a pop-up alert without blocking the launch.

    Scope

    The policy scope:

    • Specific User Group: Apply to specified user groups.

    • Specific Device Tag: Apply to devices with specified tags.

    • Specific Device: Apply to specified devices.

    • All Users: Apply to all users.

    Exception User

    Users excluded from this policy.

    Management Agent

    The agent programs to manage. You can select multiple.

    Priority

    The policy priority. A smaller value indicates a higher priority. When multiple policies apply to the same agent, the highest-priority policy takes effect.

    Prompt Display Configuration

    The alert message shown when a managed agent program runs. The pop-up alert appears regardless of the policy action.