Skip to content
Nettriva

AI Infrastructure

Built for the stack behind AI agents.

Agents are only as safe as the tools, data and models they can reach. Nettriva is designed to understand the agent stack — model gateways, agent frameworks, MCP servers, tool permissions and retrieval pipelines — and connect agent behavior to the systems and data it affects.

Agent Activity Map· prod · 48 agents · 212 tools
44 / 48 governed1 agent under review
gw-prodgw-finmodel-agw-devsupport-07risk 86finance-cprisk 64hr-assistrisk 22code-revrisk 31sales-rschrisk 47it-deskrisk 38analystrisk 41unownedrisk 58MCP-TICKETSMCP-CRMMCP-ERP / WEBMCP-REPOagent → MCP server lines show granted tool access

Calls that read or move classified data

support-07
finance-cp
hr-assist
code-rev
sales-rsch
it-desk
analyst
unowned
ticket.*crm.*erp · http.*repo.*
lowhigh · share of calls touching Restricted data

Illustrative product UI with simulated demo data. Not real customer data or statistics.

Why it is different

AI agents fail in ways traditional controls miss.

Most security tooling was designed for people and services with predictable behavior. Agents combine delegated permissions, untrusted input and non-deterministic decisions — so they need visibility and control at the level of each action.

Agents act, not just answer

Agents call tools and APIs with real credentials. A wrong answer becomes a wrong action — a refund issued, a record deleted, data sent outside.

Untrusted content steers behavior

Retrieved documents, emails, tickets and web pages can carry instructions. Prompt injection turns content into control.

Permissions accumulate

Each new tool, scope or MCP server widens what an agent can reach. Few teams review the combined effect.

Behavior appears at runtime

The same request can produce different tool sequences. Design reviews miss behavior that only shows up in production.

Policy enforcement

Identity, scope, data and destination — evaluated as one decision.

A safe tool call depends on several checks agreeing. Nettriva is designed to evaluate who the agent is acting for, whether the tool is in scope, what data is involved and where it is going — and to record why each decision was made.

Runtime policy check for an agent tool callAn AI agent requests a tool call. The policy check evaluates identity, task scope, data classification and destination. The tool is outside the agent's approved task and the data is restricted, so the call is blocked and the reason is returned to the agent. High-impact actions can instead be held for a named approver. Every decision is written to the audit trail.AI agentsupport-agent-07policy check · DLP-04evaluated before the tool runsidentityentitled userpassscopenot in taskfaildataRestricted · PIIflagdestinationinternal CRMpassdecisionBLOCKrule 2 · bulk PII export requires approvalMCP-CRMcrm.export_contactsApproversecurity-leadAudit traildecision + inputstool callallowed onlyBLOCK + reason returned to agenthigh-impact → hold for approvalrecorded
Nettriva is designed to evaluate each tool call against identity, task scope, data classification and destination before it runs — and to record every decision with the inputs and the rule that produced it.

Coverage

What Nettriva understands in an AI agent stack.

AI agents

Software that uses a model to plan and take actions through tools, APIs and other agents, often with delegated user or service permissions.

Watches · Owner, purpose, model, tools, permissions and run history.

Copilots & assistants

AI features embedded in SaaS and internal apps that read and write business data on a user's behalf.

Watches · Enabled features, data connectors, sharing settings and usage.

Model gateways

Proxies that route requests to model providers and apply logging, rate limits and guardrails in one place.

Watches · Which agents call which models, from where, with what data.

Agent frameworks

Libraries such as LangGraph, LlamaIndex or CrewAI that orchestrate model calls, memory and tool use.

Watches · Agent definitions, tool bindings, traces and errors.

MCP servers

Model Context Protocol servers expose tools and resources to agents through a standard interface.

Watches · Exposed tools, write capabilities, authentication and callers.

Tool calls

Each action an agent takes in another system: a query, an API request, a file write, a message sent.

Watches · Tool, arguments, result, identity and the policy decision applied.

Prompt injection

Instructions hidden in user input or retrieved content that try to override an agent's intended behavior.

Watches · Instruction-like content in context, followed by unusual actions.

Retrieval (RAG)

Pipelines that pull documents into an agent's context from search indexes and vector stores.

Watches · Sources retrieved, their classification and their influence on actions.

Agent identity

Who an agent is, who owns it and on whose behalf it is acting at any moment.

Watches · Service accounts, delegated tokens, OAuth scopes and user entitlements.

Secrets & API keys

Credentials agents use to reach models and tools — and that sometimes leak into prompts and logs.

Watches · Key usage, scope, rotation and secrets appearing in content.

Data egress

Data leaving your boundary through tool calls, model requests or generated output.

Watches · Destinations, volume, classification and allow-list coverage.

Human approvals

Checkpoints where a person must confirm a high-impact action before an agent proceeds.

Watches · Which actions require approval, who approved them and how long it took.

Investigation

From a suspicious tool call to a specific cause.

When an agent does something unexpected, Nettriva works back from the action to the request, the retrieved content, the permissions and the change that made it possible — and shows which explanations it ruled out along the way.

Correlated agent activity · 09:25 – 09:55 UTC

4 sources
Flagged content in context · support-agent-07Out-of-scope tool calls / minRecords requested / min · CRM-CONTACTSPolicy blocks / min · DLP-0409:38 injected ticket read09:41 export blocked

Hypotheses · INC-2207

4 tested
  1. H1Indirect prompt injection via ticket #88213 → out-of-scope export

    91%
    supported · 8 evidence
  2. H2Compromised analyst account driving the agent

    4%
    ruled out · 3 evidence
  3. H3Model or system-prompt regression

    3%
    ruled out · 2 evidence
  4. H4Gateway policy misconfiguration

    2%
    ruled out · 2 evidence

Root cause candidate

evidence-linked

Indirect prompt injection: hidden instructions in ticket #88213 steered support-agent-07 to call crm.export_contacts, a tool outside its approved task scope.

Confidence

91%

Ruled out

  • Compromised analyst account (SSO session and MFA valid)
  • Model or system-prompt regression (no version change)
  • Gateway policy misconfiguration (DLP-04 behaved as designed)

Illustrative product UI with simulated demo data. Not real customer data or statistics.

For AI platform and security teams

Questions you can ask about your agents.

Nettriva is designed for heterogeneous AI stacks: hosted and self-hosted models, several agent frameworks, internal and third-party MCP servers, and the SaaS systems agents act on.

  • ›Why did support-agent-07 call crm.export_contacts at 09:41?
  • ›Which agents can reach production databases through MCP tools?
  • ›Which tool calls were blocked by policy in the last 24 hours?
  • ›Which agents send data to external model endpoints?
  • ›Did last week's tool release widen any agent's permissions?
  • ›Are system prompts consistent across every deployment of the support agent?

Make your AI agents accountable.

Walk through a simulated agent investigation with our team and discuss how Nettriva would connect to your environment.