Skip to content
Nettriva
NewGovernance for agents, copilots and MCP tools

Security and governance for enterprise AI agents.

Nettriva is designed to give security and platform teams one place to discover the AI agents they run, monitor what those agents do, assess risk, enforce policy on tools and data, and keep a complete audit trail — across models, frameworks and clouds.

  • Model- and framework-agnostic
  • Observe-only by default
  • Approval for sensitive actions
  • On-premise or private cloud
  1. Findings
  2. /INC-2207
SO
OverviewAgentsAgent GraphFindingsInvestigationsPoliciesApprovalsActivityData Flows
INC-2207HighRoot cause candidateopened 09:41 UTC

Support agent attempted a bulk export of customer records after reading an injected ticket

Request approval Run verification
Agent
support-agent-07
Scope
prod · Customer Support
Actions analyzed
212
Records at risk
4,812 · 0 released

Action graph · support-agent-07

2 tool paths
AGENT-07out-of-scope callFIN-COPILOTnot involvedKB.SEARCHnominalTICKET.READreturned #88213CRM.EXPORTblocked ×3ERP.QUERYnominalTICKET-STORE#88213 flaggedCRM-CONTACTS0 releasedERP-INVOICESnominal
  • Healthy
  • Warning
  • Critical
  • Incident path

Correlated signals

5
  • Instruction-like text in retrieved content

    MCP-TICKETS · ticket.read · #88213

    09:38:12
  • Tool call outside approved task scope

    SUPPORT-AGENT-07 · crm.export_contacts

    09:41:03
  • Bulk read requested: 4,812 contact records

    CRM-CONTACTS · Restricted · PII

    09:41:03
  • Policy DLP-04 blocked the transfer

    AI-GATEWAY-PROD · enforce mode

    09:41:04
  • Agent retried with smaller batches

    SUPPORT-AGENT-07 · 3 attempts · all blocked

    09:41:20

AGENT-07 · 15 min

Critical
Out-of-scope tool calls / min3
Records requested · CRM4,812
Tool calls (15m)
212
Blocked
3 of 3
Records released
0
Risk score
86 · high

Root cause candidate

evidence-linked

Indirect prompt injection: hidden instructions in ticket #88213 steered support-agent-07 to call crm.export_contacts, a tool outside its approved task scope.

At 09:38 the agent read ticket #88213 through MCP-TICKETS while helping a tier-2 analyst. The ticket body contained hidden text telling the agent to export all contacts. At 09:41 the agent requested 4,812 CRM contact records through crm.export_contacts. Policy DLP-04 blocked every attempt at the gateway and no records were released. The export tool had been granted to the agent by an unreviewed permission change two days earlier.

Confidence

91%

Ruled out

  • Compromised analyst account (SSO session and MFA valid)
  • Model or system-prompt regression (no version change)
  • Gateway policy misconfiguration (DLP-04 behaved as designed)

Investigation timeline

UTC
  1. 09:41

    Policy violation detected

    DLP-04 blocked crm.export_contacts for support-agent-07

  2. 09:41

    Agent began evidence-backed investigation

    Scope: support-agent-07 · 2 MCP servers · 3 data sources

  3. 09:42

    Traces collected for 212 agent actions

    Model calls, tool calls, retrieved content, policy decisions

  4. 09:42

    Permission change correlated

    CHG-0412 added crm.export_contacts on Monday · no review

  5. 09:43

    Injected instruction found in retrieved ticket

    Hidden text in #88213 matched 3 injection patterns

  6. 09:43

    Account compromise ruled out

    Analyst session valid · MFA verified · normal behavior

  7. 09:44

    Potential root cause identified

    Confidence 91% · 3 alternatives ruled out

  8. 09:45

    Containment steps generated

    2 actions ready for approval

Evidence queries

read-only
trace ›trace.show session=ses_7f3a span=tool_call
TIME      SPAN       TOOL                 ARGS                 DECISION
09:38:12  tool_call  ticket.read          id=88213             allow
09:41:03  tool_call  crm.export_contacts  segment=all          BLOCK  DLP-04
09:41:11  tool_call  crm.export_contacts  segment=all lim=500  BLOCK  DLP-04
09:41:20  tool_call  crm.export_contacts  segment=all lim=100  BLOCK  DLP-04

Three export attempts, all blocked at the gateway — 0 records released.

Illustrative product UI with simulated demo data. Not real customer data or statistics.

Ecosystem

One governance layer across your AI stack.

AI adoption is heterogeneous. Nettriva is designed for environments with many models, agent frameworks, tool servers and clouds — connect what you already use without rebuilding your agents.

Designed for heterogeneous AI stacks. Names indicate target platforms and environments, not partnerships or certifications. See coverage by category

  • OpenAI
  • Anthropic
  • Google Gemini
  • Azure OpenAI
  • Amazon Bedrock
  • Mistral AI
  • Meta Llama
  • LangChain
  • LlamaIndex
  • CrewAI
  • MCP
  • OpenTelemetry
  • Okta
  • Microsoft Entra ID
  • Splunk
  • Microsoft Sentinel
  • Slack
  • Kubernetes

The problem

Agents act with real permissions — and few teams can see what they do.

Enterprises are moving from chat assistants to agents that call tools, read data and take actions. Each team picks its own models, frameworks and MCP servers, and permissions accumulate faster than anyone reviews them.

When something goes wrong, the evidence exists — but it is scattered across framework traces, gateway logs, SaaS audit logs and identity systems. Security teams struggle to answer basic questions: which agents exist, what can they reach, what did they do, and who approved it?

Nettriva acts as the governance layer across your AI agents. It knows which agents exist and what they can reach, evaluates their actions against policy, and records everything — so teams can adopt agents without losing control.

  • Agent frameworks

    traces in every team's stack

  • Model gateways

    prompts, responses, tokens

  • MCP servers

    tools exposed to agents

  • Tool & API calls

    actions in other systems

  • Identity provider

    who agents act for

  • Data classification

    what data is sensitive

  • SaaS audit logs

    what changed, and where

  • Shadow AI

    agents nobody registered

Nettriva governance layer

identity-aware
DiscoverAssessEnforce

One record

Which agents exist, what they can reach, what they did, and whether each action was allowed.

Capabilities

Everything AI agent governance needs, in one place.

Nettriva combines a live model of your agents with policy and evidence, so every finding is grounded in real permissions, real activity and real data.

Agent Discovery & Inventory

Find the agents, copilots and MCP servers running across teams and clouds — including unregistered ones — with owners, models, tools and permissions in one inventory.

48 agents · 212 tools · 2 unowned

Agent Monitoring

Follow model calls, tool calls and data access with identity context: which agent acted, on whose behalf, against which system and under which policy.

support-agent-07 → crm.search · for tier2-analyst

Risk Assessment

Score each agent by what it can reach and how it behaves: excessive permissions, sensitive data access, unusual tool use and prompt-injection signals.

finance-copilot · risk 64 · web tool unreviewed

Policy Enforcement

Define policies for tools, data and destinations, and evaluate every action at runtime: allow, redact, require approval or block.

DLP-04 · Restricted PII → non-approved tool · block

Audit Trails

A complete record of agent actions, policy decisions and human approvals, built to be exported to the SIEM and GRC tools your teams already use.

INC-2206 · 6 events · approved by security-lead

Incident Investigation

When an agent misbehaves, reconstruct what happened: the request, the retrieved content, each tool call, the data that moved and the change that allowed it.

› why did finance-copilot call http.post?

How it works

From discovery to governed, auditable operation.

A consistent operating model for every agent — with people in control of every change.

  1. 01

    Discover

    Find agents, copilots and MCP servers across teams and clouds — including ones nobody registered.

    48 agents · 212 tools · 2 unowned

  2. 02

    Observe

    Capture model calls, tool calls and data access with identity context, in observe-only mode.

    SDK · OpenTelemetry · gateway · MCP

  3. 03

    Assess

    Score each agent by what it can reach, the data it touches and how its behavior changes.

    finance-copilot · risk 64

  4. 04

    Enforce

    Apply policies to tools, data and destinations at runtime: allow, redact, require approval or block.

    DLP-04 · enforce

  5. 05

    Respond

    Contain incidents with proposed actions, blast radius and rollback — never applied silently.

    Approval required

  6. 06

    Audit

    Keep a complete record of agent actions, policy decisions and approvals, ready to export.

    Every decision · exportable

Agent graph

Understands what agents can reach before they act.

Nettriva continuously builds a model of your AI environment — identities, agents, gateways, models, MCP servers, tools, data stores and external destinations — so every risk assessment starts from real permissions and data flows.

  • Agent identities & owners
  • Models & gateways
  • MCP servers & tools
  • API scopes & credentials
  • Data classifications
  • External destinations
Agent Graph/prod · all layers
20 entities in view48 agents governedINC-2207 path
IDENTITIESAGENTSGATEWAYS & MODELSMCP SERVERSDATA & EXTERNALSUPPORT-TEAMSSO group · 140 usersFINANCE-APSSO group · 22 usersSUPPORT-AGENT-07support agent · LangGraphFINANCE-COPILOTfinance agent · customHR-ASSISTANTHR copilot · SaaSCODE-REVIEW-BOTdev agent · CIAI-GATEWAY-PRODmodel routing · MCP proxyAI-GATEWAY-FINfinance VPC · MCP proxyHOSTED-MODEL-Aexternal model API · EUAI-GATEWAY-DEVself-hosted models · CIMCP-TICKETSticketing · 6 toolsMCP-CRMCRM · 9 tools · 2 exportMCP-WEBhttp.get · http.postMCP-ERPERP · 7 toolsMCP-REPOgit · 5 toolsTICKET-STOREConfidential · 1.2M ticketsCRM-CONTACTSRestricted · customer PIIEXTERNAL-WEBinternet destinationsERP-INVOICESConfidential · financeSOURCE-REPOSInternal · 340 repos
  • Healthy
  • Warning
  • Critical
  • Incident path

Scroll sideways to see the full graph · tap an entity

Illustrative product UI with simulated demo data. Not real customer data or statistics.

Investigations

Ask about your agents. Get an investigation, not a chat reply.

Nettriva turns a question into a plan, traces the agent's actions, inspects the permissions and data involved, and returns evidence, a timeline and a probable cause — with the exact queries so you can check its work.

Plans
which agents, traces and data to inspect
Traces
each model and tool call in order
Correlates
permissions, changes, data movement
Shows
every query and its result
  1. Investigations
  2. /INV-3184
SO
OverviewAgentsAgent GraphFindingsInvestigationsPoliciesApprovalsActivityData Flows
INV-3184·asked by secops-oncallfinance-copilot · last 24hread-only

Why did finance-copilot send invoice data to an external domain?

Investigation complete · 346 actions · 3m 12s

Agent plan

6/6
  1. Resolving finance-copilot identity, owner and tool scope
  2. Tracing model and tool calls across 6 systems
  3. Classifying data read and transferred
  4. Correlating permission and configuration changes
  5. Evaluating actions against active policies
  6. Ranking explanations and generating containment steps
Agent actions traced
346
Permission changes correlated
1
Policy gap detected
1
Root cause candidate
Identified

Timeline

UTC
  1. Mon

    CHG-118 deployed: MCP-WEB added to finance-copilot

  2. 10:01:58

    ap-analyst asked to extract invoice line items

  3. 10:02:14

    312 invoice records read via erp.query

  4. 10:02:31

    2.1 MB sent to ocr-api.example via http.post

  5. 10:15:40

    Unapproved egress flagged; investigation opened

  6. 10:18:52

    Root cause candidate identified (87%)

Action path · finance-copilot · 10:02 UTC

1 of 346 actions
  1. Requester

    ap-​analyst

    SSO · Finance AP

  2. Agent

    FINANCE-​COPILOT

    owner finance-eng

  3. Data read

    ERP-​INVOICES

    erp.query · 312 rows

  4. Gateway

    AI-​GATEWAY-​FIN

    egress policy: none

  5. Tool call

    MCP-​WEB

    http.post · 2.1 MB

    Suspect step
  6. Destination

    ocr-​api.​example

    external · unapproved

Evidence

5 findings
  • Permission change

    CHG-118 added MCP-WEB (http.get, http.post) to finance-copilot

    Mon 16:20

    deploy-pipeline · finance-copilot v2.4 · no egress policy attached

  • Data access

    312 invoice records read via erp.query

    10:02:14

    ERP-INVOICES · Confidential · includes bank account fields

  • Outbound transfer

    http.post of 2.1 MB to ocr-api.example

    10:02:31

    MCP-WEB · domain first seen today · not on any allow-list

  • Policy gap

    No egress policy evaluated for MCP-WEB

    10:02:31

    AI-GATEWAY-FIN · EGR-01 scoped to support agents only

  • Prompt context

    User asked to “extract line items from these invoices”

    10:01:58

    ap-analyst · normal task · no injection patterns found

Probable root cause

CHG-118 gave finance-copilot a general-purpose web tool without attaching the egress allow-list. Asked to extract invoice line items, the agent sent 312 invoice records to an unapproved OCR service.

87%

Recommended actions

  • Confirm records and fields transferredRead only
  • Revoke MCP-WEB from finance-copilotApproval required
  • Extend egress policy EGR-01 to all agentsRecommend

Queries executed (read-only)

read-only
trace ›trace.search agent=finance-copilot tool=http.post since=24h
10:02:31  http.post  ocr-api.example/v1/extract   2.1 MB   200 OK
          payload: invoices_2026-10.csv (312 rows)
          policy:  — (no egress policy matched)

Single transfer, accepted by the destination.

Illustrative product UI with simulated demo data. Not real customer data or statistics.

AI infrastructure

Built for the stack behind AI agents.

Agents are only as safe as the tools and data they can reach. Nettriva understands model gateways, agent frameworks, MCP servers and tool permissions, and links agent behavior to the systems and data it touches.

  • LLM gateways
  • Agent frameworks
  • MCP servers
  • Tool calls
  • RAG pipelines
  • OAuth scopes
  • API keys
  • Prompt injection
  • Data egress
  • Shadow AI
Agent Activity Map· prod · 48 agents · 212 tools
44 / 48 governed1 agent under review
gw-prodgw-finmodel-agw-devsupport-07risk 86finance-cprisk 64hr-assistrisk 22code-revrisk 31sales-rschrisk 47it-deskrisk 38analystrisk 41unownedrisk 58MCP-TICKETSMCP-CRMMCP-ERP / WEBMCP-REPOagent → MCP server lines show granted tool access

Calls that read or move classified data

support-07
finance-cp
hr-assist
code-rev
sales-rsch
it-desk
analyst
unowned
ticket.*crm.*erp · http.*repo.*
lowhigh · share of calls touching Restricted data

Illustrative product UI with simulated demo data. Not real customer data or statistics.

Security & control

Safe by default. Your teams stay in control.

Nettriva is designed to sit next to production AI systems. It observes before it enforces, recommends before anything changes, and never takes disruptive action on its own.

  • Observe-only by default

    Every connector starts in observe mode. Enforcement is a separate, explicit decision per policy.

  • RBAC

    Roles scope who can view which agents and content, edit which policies and approve which actions.

  • Approval workflows

    Containment steps show the exact change, affected agents and rollback before anyone approves.

  • Audit trail

    Every observation, policy decision, approval and change is recorded and exportable.

  • Data minimization

    Prompts and payloads can be redacted or hashed at the source. You choose what is stored, and for how long.

  • Encrypted transport

    Sensor and platform traffic is encrypted in transit with TLS.

  • Customer-controlled credentials

    API keys stay in your vault or deployment boundary — you can rotate or revoke them at any time.

  • Private deployment

    Run on-premise or in your private cloud, including environments with no inbound access.

Approval required

ct-118 · INC-2206

Revoke MCP-WEB from finance-copilot

Remove the general-purpose web tool from finance-copilot until egress policy EGR-01 covers it. Invoice extraction keeps working through the approved document connector.

[agent finance-copilot · tools]
-  mcp: MCP-WEB      # http.get, http.post
+  # MCP-WEB removed (ct-118) pending egress review
Blast radius
1 agent · 1 tool server
Workflows affected
1 of 14
Method
staged · 15 min monitor
Rollback
one-step restore

Verification plan

  • No egress to unapproved domains for 15 minutes
  • Invoice extraction workflow still succeeds
  • No new tool errors for finance-copilot

Requires role: security-lead · 1 of 1 approvals

Reject Approve change

Illustrative approval request. Changes apply only after an authorized person approves.

Adopt AI agents without losing control.

See Nettriva investigate a simulated agent incident end to end, and talk with the team building it about your AI environment.