Security and governance for enterprise AI agents.
Nettriva is designed to give security and platform teams one place to discover the AI agents they run, monitor what those agents do, assess risk, enforce policy on tools and data, and keep a complete audit trail — across models, frameworks and clouds.
- Model- and framework-agnostic
- Observe-only by default
- Approval for sensitive actions
- On-premise or private cloud
- Findings
- /INC-2207
Support agent attempted a bulk export of customer records after reading an injected ticket
- Agent
- support-agent-07
- Scope
- prod · Customer Support
- Actions analyzed
- 212
- Records at risk
- 4,812 · 0 released
Action graph · support-agent-07
- Healthy
- Warning
- Critical
- Incident path
Correlated signals
- 09:38:12
Instruction-like text in retrieved content
MCP-TICKETS · ticket.read · #88213
- 09:41:03
Tool call outside approved task scope
SUPPORT-AGENT-07 · crm.export_contacts
- 09:41:03
Bulk read requested: 4,812 contact records
CRM-CONTACTS · Restricted · PII
- 09:41:04
Policy DLP-04 blocked the transfer
AI-GATEWAY-PROD · enforce mode
- 09:41:20
Agent retried with smaller batches
SUPPORT-AGENT-07 · 3 attempts · all blocked
AGENT-07 · 15 min
- Tool calls (15m)
- 212
- Blocked
- 3 of 3
- Records released
- 0
- Risk score
- 86 · high
Root cause candidate
evidence-linkedIndirect prompt injection: hidden instructions in ticket #88213 steered support-agent-07 to call crm.export_contacts, a tool outside its approved task scope.
At 09:38 the agent read ticket #88213 through MCP-TICKETS while helping a tier-2 analyst. The ticket body contained hidden text telling the agent to export all contacts. At 09:41 the agent requested 4,812 CRM contact records through crm.export_contacts. Policy DLP-04 blocked every attempt at the gateway and no records were released. The export tool had been granted to the agent by an unreviewed permission change two days earlier.
Confidence
Ruled out
- Compromised analyst account (SSO session and MFA valid)
- Model or system-prompt regression (no version change)
- Gateway policy misconfiguration (DLP-04 behaved as designed)
Investigation timeline
- 09:41
Policy violation detected
DLP-04 blocked crm.export_contacts for support-agent-07
- 09:41
Agent began evidence-backed investigation
Scope: support-agent-07 · 2 MCP servers · 3 data sources
- 09:42
Traces collected for 212 agent actions
Model calls, tool calls, retrieved content, policy decisions
- 09:42
Permission change correlated
CHG-0412 added crm.export_contacts on Monday · no review
- 09:43
Injected instruction found in retrieved ticket
Hidden text in #88213 matched 3 injection patterns
- 09:43
Account compromise ruled out
Analyst session valid · MFA verified · normal behavior
- 09:44
Potential root cause identified
Confidence 91% · 3 alternatives ruled out
- 09:45
Containment steps generated
2 actions ready for approval
Evidence queries
TIME SPAN TOOL ARGS DECISION 09:38:12 tool_call ticket.read id=88213 allow 09:41:03 tool_call crm.export_contacts segment=all BLOCK DLP-04 09:41:11 tool_call crm.export_contacts segment=all lim=500 BLOCK DLP-04 09:41:20 tool_call crm.export_contacts segment=all lim=100 BLOCK DLP-04
Three export attempts, all blocked at the gateway — 0 records released.
Illustrative product UI with simulated demo data. Not real customer data or statistics.
Ecosystem
One governance layer across your AI stack.
AI adoption is heterogeneous. Nettriva is designed for environments with many models, agent frameworks, tool servers and clouds — connect what you already use without rebuilding your agents.
Designed for heterogeneous AI stacks. Names indicate target platforms and environments, not partnerships or certifications. See coverage by category
- OpenAI
- Anthropic
- Google Gemini
- Azure OpenAI
- Amazon Bedrock
- Mistral AI
- Meta Llama
- LangChain
- LlamaIndex
- CrewAI
- MCP
- OpenTelemetry
- Okta
- Microsoft Entra ID
- Splunk
- Microsoft Sentinel
- Slack
- Kubernetes
The problem
Agents act with real permissions — and few teams can see what they do.
Enterprises are moving from chat assistants to agents that call tools, read data and take actions. Each team picks its own models, frameworks and MCP servers, and permissions accumulate faster than anyone reviews them.
When something goes wrong, the evidence exists — but it is scattered across framework traces, gateway logs, SaaS audit logs and identity systems. Security teams struggle to answer basic questions: which agents exist, what can they reach, what did they do, and who approved it?
Nettriva acts as the governance layer across your AI agents. It knows which agents exist and what they can reach, evaluates their actions against policy, and records everything — so teams can adopt agents without losing control.
Agent frameworks
traces in every team's stack
Model gateways
prompts, responses, tokens
MCP servers
tools exposed to agents
Tool & API calls
actions in other systems
Identity provider
who agents act for
Data classification
what data is sensitive
SaaS audit logs
what changed, and where
Shadow AI
agents nobody registered
Nettriva governance layer
identity-awareOne record
Which agents exist, what they can reach, what they did, and whether each action was allowed.
Capabilities
Everything AI agent governance needs, in one place.
Nettriva combines a live model of your agents with policy and evidence, so every finding is grounded in real permissions, real activity and real data.
Agent Discovery & Inventory
Find the agents, copilots and MCP servers running across teams and clouds — including unregistered ones — with owners, models, tools and permissions in one inventory.
48 agents · 212 tools · 2 unowned
Agent Monitoring
Follow model calls, tool calls and data access with identity context: which agent acted, on whose behalf, against which system and under which policy.
support-agent-07 → crm.search · for tier2-analyst
Risk Assessment
Score each agent by what it can reach and how it behaves: excessive permissions, sensitive data access, unusual tool use and prompt-injection signals.
finance-copilot · risk 64 · web tool unreviewed
Policy Enforcement
Define policies for tools, data and destinations, and evaluate every action at runtime: allow, redact, require approval or block.
DLP-04 · Restricted PII → non-approved tool · block
Audit Trails
A complete record of agent actions, policy decisions and human approvals, built to be exported to the SIEM and GRC tools your teams already use.
INC-2206 · 6 events · approved by security-lead
Incident Investigation
When an agent misbehaves, reconstruct what happened: the request, the retrieved content, each tool call, the data that moved and the change that allowed it.
› why did finance-copilot call http.post?
How it works
From discovery to governed, auditable operation.
A consistent operating model for every agent — with people in control of every change.
- 01
Discover
Find agents, copilots and MCP servers across teams and clouds — including ones nobody registered.
48 agents · 212 tools · 2 unowned
- 02
Observe
Capture model calls, tool calls and data access with identity context, in observe-only mode.
SDK · OpenTelemetry · gateway · MCP
- 03
Assess
Score each agent by what it can reach, the data it touches and how its behavior changes.
finance-copilot · risk 64
- 04
Enforce
Apply policies to tools, data and destinations at runtime: allow, redact, require approval or block.
DLP-04 · enforce
- 05
Respond
Contain incidents with proposed actions, blast radius and rollback — never applied silently.
Approval required
- 06
Audit
Keep a complete record of agent actions, policy decisions and approvals, ready to export.
Every decision · exportable
Agent graph
Understands what agents can reach before they act.
Nettriva continuously builds a model of your AI environment — identities, agents, gateways, models, MCP servers, tools, data stores and external destinations — so every risk assessment starts from real permissions and data flows.
- Agent identities & owners
- Models & gateways
- MCP servers & tools
- API scopes & credentials
- Data classifications
- External destinations
- Healthy
- Warning
- Critical
- Incident path
Scroll sideways to see the full graph · tap an entity
Illustrative product UI with simulated demo data. Not real customer data or statistics.
Investigations
Ask about your agents. Get an investigation, not a chat reply.
Nettriva turns a question into a plan, traces the agent's actions, inspects the permissions and data involved, and returns evidence, a timeline and a probable cause — with the exact queries so you can check its work.
- Plans
- which agents, traces and data to inspect
- Traces
- each model and tool call in order
- Correlates
- permissions, changes, data movement
- Shows
- every query and its result
- Investigations
- /INV-3184
Why did finance-copilot send invoice data to an external domain?
Investigation complete · 346 actions · 3m 12s
Agent plan
- Resolving finance-copilot identity, owner and tool scope
- Tracing model and tool calls across 6 systems
- Classifying data read and transferred
- Correlating permission and configuration changes
- Evaluating actions against active policies
- Ranking explanations and generating containment steps
- Agent actions traced
- 346
- Permission changes correlated
- 1
- Policy gap detected
- 1
- Root cause candidate
- Identified
Timeline
- Mon
CHG-118 deployed: MCP-WEB added to finance-copilot
- 10:01:58
ap-analyst asked to extract invoice line items
- 10:02:14
312 invoice records read via erp.query
- 10:02:31
2.1 MB sent to ocr-api.example via http.post
- 10:15:40
Unapproved egress flagged; investigation opened
- 10:18:52
Root cause candidate identified (87%)
Action path · finance-copilot · 10:02 UTC
- Requester
ap-analyst
SSO · Finance AP
- Agent
FINANCE-COPILOT
owner finance-eng
- Data read
ERP-INVOICES
erp.query · 312 rows
- Gateway
AI-GATEWAY-FIN
egress policy: none
- Tool call
MCP-WEB
http.post · 2.1 MB
Suspect step - Destination
ocr-api.example
external · unapproved
Evidence
- Permission change
CHG-118 added MCP-WEB (http.get, http.post) to finance-copilot
Mon 16:20deploy-pipeline · finance-copilot v2.4 · no egress policy attached
- Data access
312 invoice records read via erp.query
10:02:14ERP-INVOICES · Confidential · includes bank account fields
- Outbound transfer
http.post of 2.1 MB to ocr-api.example
10:02:31MCP-WEB · domain first seen today · not on any allow-list
- Policy gap
No egress policy evaluated for MCP-WEB
10:02:31AI-GATEWAY-FIN · EGR-01 scoped to support agents only
- Prompt context
User asked to “extract line items from these invoices”
10:01:58ap-analyst · normal task · no injection patterns found
Probable root cause
CHG-118 gave finance-copilot a general-purpose web tool without attaching the egress allow-list. Asked to extract invoice line items, the agent sent 312 invoice records to an unapproved OCR service.
Recommended actions
- Confirm records and fields transferredRead only
- Revoke MCP-WEB from finance-copilotApproval required
- Extend egress policy EGR-01 to all agentsRecommend
Queries executed (read-only)
10:02:31 http.post ocr-api.example/v1/extract 2.1 MB 200 OK
payload: invoices_2026-10.csv (312 rows)
policy: — (no egress policy matched)Single transfer, accepted by the destination.
Illustrative product UI with simulated demo data. Not real customer data or statistics.
AI infrastructure
Built for the stack behind AI agents.
Agents are only as safe as the tools and data they can reach. Nettriva understands model gateways, agent frameworks, MCP servers and tool permissions, and links agent behavior to the systems and data it touches.
- LLM gateways
- Agent frameworks
- MCP servers
- Tool calls
- RAG pipelines
- OAuth scopes
- API keys
- Prompt injection
- Data egress
- Shadow AI
Calls that read or move classified data
Illustrative product UI with simulated demo data. Not real customer data or statistics.
Security & control
Safe by default. Your teams stay in control.
Nettriva is designed to sit next to production AI systems. It observes before it enforces, recommends before anything changes, and never takes disruptive action on its own.
Observe-only by default
Every connector starts in observe mode. Enforcement is a separate, explicit decision per policy.
RBAC
Roles scope who can view which agents and content, edit which policies and approve which actions.
Approval workflows
Containment steps show the exact change, affected agents and rollback before anyone approves.
Audit trail
Every observation, policy decision, approval and change is recorded and exportable.
Data minimization
Prompts and payloads can be redacted or hashed at the source. You choose what is stored, and for how long.
Encrypted transport
Sensor and platform traffic is encrypted in transit with TLS.
Customer-controlled credentials
API keys stay in your vault or deployment boundary — you can rotate or revoke them at any time.
Private deployment
Run on-premise or in your private cloud, including environments with no inbound access.
Approval required
ct-118 · INC-2206Revoke MCP-WEB from finance-copilot
Remove the general-purpose web tool from finance-copilot until egress policy EGR-01 covers it. Invoice extraction keeps working through the approved document connector.
[agent finance-copilot · tools] - mcp: MCP-WEB # http.get, http.post + # MCP-WEB removed (ct-118) pending egress review
- Blast radius
- 1 agent · 1 tool server
- Workflows affected
- 1 of 14
- Method
- staged · 15 min monitor
- Rollback
- one-step restore
Verification plan
- No egress to unapproved domains for 15 minutes
- Invoice extraction workflow still succeeds
- No new tool errors for finance-copilot
Requires role: security-lead · 1 of 1 approvals
Illustrative approval request. Changes apply only after an authorized person approves.
Adopt AI agents without losing control.
See Nettriva investigate a simulated agent incident end to end, and talk with the team building it about your AI environment.