Product
The governance layer for enterprise AI agents.
Nettriva combines a live model of your agents, tools and data with analysis that works like an experienced security engineer: map what each agent can reach, watch what it does, test explanations against evidence and enforce policy — with every step visible and every change approved.
Incident lifecycle
Detect to resolve, with a clear hand-off to people.
Nettriva is designed to handle the repetitive, evidence-gathering stages of an agent incident at machine speed. Decisions that change production stay with your people.
- 1
Detect
A policy violation, an anomaly in agent behavior, or a question from an analyst.
- 2
Collect
Pull traces, prompts, tool calls and data access for the agents involved.
- 3
Correlate
Align agent actions, permission changes and data movement on one timeline.
- 4
Investigate
Test explanations — injection, misconfiguration, misuse — against the evidence.
- 5
Explain
Root cause candidate with confidence, evidence and reasoning.
- 6
Recommend
Containment, blast radius, verification plan and rollback.
- 7
Approve
An authorized person approves — or rejects — the exact change.
- 8
Verify
Re-run the evidence checks and confirm the policy holds.
- 9
Resolve
Close with a complete, auditable record of what happened.
Investigation Engine
Explanations, tested against evidence.
The engine treats every agent incident as a set of competing explanations — prompt injection, a permission change, a compromised account, a model regression. It plans targeted, read-only queries to confirm or reject each one, weighs the evidence and keeps going until a candidate clearly stands out — or tells you that it doesn't.
Results always include the evidence trail, so an analyst can verify the conclusion in minutes.
- Plans what to inspect, and where
- Ranks competing explanations
- Records what was ruled out
- Confidence tied to evidence
Hypotheses · INC-2207
H1Indirect prompt injection via ticket #88213 → out-of-scope export
91%supported · 8 evidenceH2Compromised analyst account driving the agent
4%ruled out · 3 evidenceH3Model or system-prompt regression
3%ruled out · 2 evidenceH4Gateway policy misconfiguration
2%ruled out · 2 evidence
Root cause candidate
evidence-linkedIndirect prompt injection: hidden instructions in ticket #88213 steered support-agent-07 to call crm.export_contacts, a tool outside its approved task scope.
Confidence
Sensors & Connectors
Sensors next to your agents. Analysis in the platform.
Lightweight sensors run alongside your agents and gateways and collect through SDKs, OpenTelemetry, gateway integrations, MCP proxies and audit-log APIs. Specialised services handle discovery, risk analysis, investigation and verification, each with a narrow, auditable set of permissions.
Sensors only collect the fields you allow — prompts and payloads can be redacted or hashed before they leave.
- SDK, gateway and MCP proxy options
- Outbound-only connectivity
- Observe-only by default
- Redaction at the source
Sensors & services
sensor-gw-prod
AI-GATEWAY-PROD · 31 agents
Sensorsensor-gw-fin
AI-GATEWAY-FIN · 3 agents
Sensorotel-ingest
14 services · GenAI spans
Collectoridp-sync
4,200 users · 310 groups
Identitydiscovery
48 agents · 212 tools
Modelinvestigator
2 investigations running
Reasoningverifier
1 check scheduled
Verification
All sensors observe-only by default · outbound connections only
Agent Discovery
Every assessment starts from what an agent can actually reach.
Nettriva continuously builds a graph of your AI environment: which agents exist, who owns them, which identities they act for, which models and gateways they use, which tools and MCP servers they can call, and which data those tools expose — including agents nobody registered.
When something happens, an investigation is scoped automatically to the agents, tools and data that could actually be involved — not every alert that fired.
- Agents, owners and identities
- Models and gateways
- Tools, MCP servers and API scopes
- Data stores and destinations
Incident scope · support-agent-07
- Healthy
- Warning
- Critical
- Incident path
Agent Monitoring
Model calls, tool calls and data access, on one timeline.
Nettriva aligns agent activity from different frameworks, gateways and SaaS systems on a shared timeline, then looks for the causal order: what entered the agent's context first, and what it did next.
That is how a ticket read at 09:38 gets linked to a blocked bulk export at 09:41.
- Model and tool calls with arguments
- Identity and on-behalf-of context
- Retrieved content and its source
- Policy decisions and approvals
Correlated agent activity · 09:25 – 09:55 UTC
Risk Assessment
Know what changed, and whether it increased risk.
Nettriva keeps a history of every agent's tools, scopes, data access and approval requirements, and understands them semantically — which tools can write, which data is restricted, which actions need a human — rather than as plain configuration text.
It scores agents by reach and behavior, detects drift from approved baselines, and connects recent changes to the incidents that follow them.
- Drift from approved permission baselines
- Excessive-privilege detection
- Change-to-incident correlation
- Pre-deployment risk review
Permission drift · support agents
- support-agent-07
- support-agent-09
- support-triage
# approved baseline (support-agents-v12) vs. running tools: ticket.read, ticket.reply, kb.search - data_scope: tickets:own_queue + data_scope: tickets:all + tool: crm.export_contacts - approval_required: [refund.issue] + approval_required: []
Introduced
CHG-0412 · Monday · no review recorded
Risk
Bulk PII export · refunds without approval
Action Tracing
Trace any agent action, step by step, across systems.
Follow a single request from the person who asked, through the agent, the data it read and each tool it called, to wherever the result was sent — then inspect each step for sensitive data and the policy decision that applied.
- From requester to destination
- Every model and tool call in order
- Data classification at each step
- Policy decision at each step
finance-copilot · http.post · 10:02 UTC
- Requester
ap-analyst
SSO · Finance AP
- Agent
FINANCE-COPILOT
owner finance-eng
- Data read
ERP-INVOICES
erp.query · 312 rows
- Gateway
AI-GATEWAY-FIN
egress policy: none
- Tool call
MCP-WEB
http.post · 2.1 MB
Suspect step - Destination
ocr-api.example
external · unapproved
Policy Enforcement
Policies for tools, data and destinations — evaluated per action.
Express what agents may do in terms your security team already uses: which tools an agent may call, which data classifications may leave, which destinations are approved and which actions need a person to confirm them.
New policies start in monitor mode so you can see what they would have done. Enforcement is enabled per policy, with approval, and every decision records the inputs and rule that produced it.
- Allow, redact, require approval or block
- Monitor mode before enforcement
- Scoped to agents, tools and data
- Every decision explained and logged
Policies · production
- DLP-04Enforce
Block restricted PII to non-approved tools
37 blocks · 24h
- APR-02Approval
Payments and refunds require approval
3 pending
- SEC-07Redact
Mask secrets and API keys in prompts
112 masked · 24h
- EGR-01Enforce
Egress allow-list for MCP tools
14 domains
- IDN-03Monitor
Agents act only for entitled users
0 violations
- MDL-01Monitor
Restricted data stays on approved models
2 alerts
New policies start in monitor mode · enforcement is enabled per policy
Incident Correlation
Many alerts. One incident. A clear blast radius.
Signals that share a cause are grouped into a single incident using the agent graph and timing, not just text similarity. Each incident shows which agents, tools, records and users are affected — and which are not.
- Agent-aware de-duplication
- Records, users and systems affected
- Linked to changes and content
- Fewer pages, better context
Merged signals
- 09:38:12
Instruction-like text in retrieved content
MCP-TICKETS · ticket.read · #88213
- 09:41:03
Tool call outside approved task scope
SUPPORT-AGENT-07 · crm.export_contacts
- 09:41:03
Bulk read requested: 4,812 contact records
CRM-CONTACTS · Restricted · PII
- 09:41:04
Policy DLP-04 blocked the transfer
AI-GATEWAY-PROD · enforce mode
- 09:41:20
Agent retried with smaller batches
SUPPORT-AGENT-07 · 3 attempts · all blocked
Incident INC-2207 · blast radius
- Agents
- 1
- Tool calls
- 212
- Records requested
- 4,812
- Records released
- 0
- support-agent-07awaiting containment approval
- Ticket #88213flagged · source of injection
- CRM-CONTACTS · Restricted0 records released
- Other support agentsnot affected
Human-in-the-loop Response
Recommend first. Contain only with approval.
Nettriva does not pause agents, revoke tools or start blocking on its own. Each deployment chooses how far automation may go — and every step is recorded.
01Observe Only
Default for every connectorRecord agent activity and evaluate policies without changing agent behavior.
02Alert & Recommend
Nettriva generatesNotify owners of violations and propose containment with evidence, blast radius and rollback.
03Approval Required
Person decidesSensitive actions and containment steps wait for a named approver with the right role.
04Enforce Approved Policy
Scoped policyoff by defaultBlock or redact actions that violate an approved policy, scoped to the agents and tools it covers.
05Verify Result
Nettriva verifiesRe-run the evidence checks and confirm the policy behaves as intended without breaking legitimate work.
06Rollback Guidance
Person decidesIf verification fails, present the prepared rollback and its expected effect.
Approval required
ct-118 · INC-2206Revoke MCP-WEB from finance-copilot
Remove the general-purpose web tool from finance-copilot until egress policy EGR-01 covers it. Invoice extraction keeps working through the approved document connector.
[agent finance-copilot · tools] - mcp: MCP-WEB # http.get, http.post + # MCP-WEB removed (ct-118) pending egress review
- Blast radius
- 1 agent · 1 tool server
- Workflows affected
- 1 of 14
- Method
- staged · 15 min monitor
- Rollback
- one-step restore
Verification plan
- No egress to unapproved domains for 15 minutes
- Invoice extraction workflow still succeeds
- No new tool errors for finance-copilot
Requires role: security-lead · 1 of 1 approvals
Audit log · INC-2206
- 10:18:52
investigator · Generated recommendation
Revoke MCP-WEB from finance-copilot
- 10:19:30
secops-oncall · Requested approval
Containment candidate ct-118
- 10:21:12
security-lead · Approved change
ct-118 · staged · 15 min monitor
- 10:21:20
policy-engine (scoped) · Applied tool revocation
finance-copilot · 1 MCP server
- 10:36:41
investigator · Verified result
0 egress to unapproved domains · workflow OK
- 10:37:02
secops-oncall · Resolved incident
INC-2206 · root cause linked
Security team view
Every agent at a glance.
Governance coverage, open findings, agent inventory and platform activity — the starting point for every review.
- Overview
- /All agents
Governance overview
Governance Coverage
91.7%
+4.2 pts this week
Agents Discovered
48
+3 this week · 2 unowned
Open Risk Findings
7
2 high · 5 medium
Tool Calls (24h)
182k
across 212 tools
Policy Blocks (24h)
37
0.02% of agent actions
Approvals Pending
3
median 6m to decision
Open findings
- HighRCA ready
Injected ticket → out-of-scope export attempt
INC-2207 · 6m ago
- HighAwaiting approval
finance-copilot sent invoices to unapproved domain
INC-2206 · 38m ago
- MediumInvestigating
Unowned agent calling an external model API
INC-2201 · 2h ago
- MediumRecommend
Permission drift · 3 agents vs. approved baseline
INC-2198 · 5h ago
- MediumMonitoring
Secrets detected in prompts · it-helpdesk
INC-2195 · 9h ago
Governance posture by team
- 471.0%
Customer Support
ticketing · CRM tools
- 376.4%
Finance
ERP · payments · web
- 1493.2%
Engineering
repos · CI · cloud
- 990.1%
Sales & Marketing
CRM read · web search
- 296.8%
People Ops
HRIS · read-only
Agent inventory
Platform activity
Collected 212 traces for support-agent-07
sensor-gw-prod · 09:45:02
Ranked 4 hypotheses for INC-2207 · top 91%
investigator · 09:44:47
DLP-04 blocked crm.export_contacts (3 attempts)
policy-engine · 09:41:04
New agent found: unregistered-a1f · no owner
discovery · 09:30:10
Drift detected on 3 agents vs. approved baseline
permission-watch · 09:12:09
Illustrative product UI with simulated demo data. Not real customer data or statistics.
Adopt AI agents without losing control.
See Nettriva investigate a simulated agent incident end to end, and talk with the team building it about your AI environment.