Skip to content
Nettriva

Product

The governance layer for enterprise AI agents.

Nettriva combines a live model of your agents, tools and data with analysis that works like an experienced security engineer: map what each agent can reach, watch what it does, test explanations against evidence and enforce policy — with every step visible and every change approved.

Incident lifecycle

Detect to resolve, with a clear hand-off to people.

Nettriva is designed to handle the repetitive, evidence-gathering stages of an agent incident at machine speed. Decisions that change production stay with your people.

  1. 1

    Detect

    A policy violation, an anomaly in agent behavior, or a question from an analyst.

  2. 2

    Collect

    Pull traces, prompts, tool calls and data access for the agents involved.

  3. 3

    Correlate

    Align agent actions, permission changes and data movement on one timeline.

  4. 4

    Investigate

    Test explanations — injection, misconfiguration, misuse — against the evidence.

  5. 5

    Explain

    Root cause candidate with confidence, evidence and reasoning.

  6. 6

    Recommend

    Containment, blast radius, verification plan and rollback.

  7. 7

    Approve

    An authorized person approves — or rejects — the exact change.

  8. 8

    Verify

    Re-run the evidence checks and confirm the policy holds.

  9. 9

    Resolve

    Close with a complete, auditable record of what happened.

Nettriva performs People decide

Investigation Engine

Explanations, tested against evidence.

The engine treats every agent incident as a set of competing explanations — prompt injection, a permission change, a compromised account, a model regression. It plans targeted, read-only queries to confirm or reject each one, weighs the evidence and keeps going until a candidate clearly stands out — or tells you that it doesn't.

Results always include the evidence trail, so an analyst can verify the conclusion in minutes.

  • Plans what to inspect, and where
  • Ranks competing explanations
  • Records what was ruled out
  • Confidence tied to evidence

Hypotheses · INC-2207

4 tested
  1. H1Indirect prompt injection via ticket #88213 → out-of-scope export

    91%
    supported · 8 evidence
  2. H2Compromised analyst account driving the agent

    4%
    ruled out · 3 evidence
  3. H3Model or system-prompt regression

    3%
    ruled out · 2 evidence
  4. H4Gateway policy misconfiguration

    2%
    ruled out · 2 evidence

Root cause candidate

evidence-linked

Indirect prompt injection: hidden instructions in ticket #88213 steered support-agent-07 to call crm.export_contacts, a tool outside its approved task scope.

Confidence

91%

Sensors & Connectors

Sensors next to your agents. Analysis in the platform.

Lightweight sensors run alongside your agents and gateways and collect through SDKs, OpenTelemetry, gateway integrations, MCP proxies and audit-log APIs. Specialised services handle discovery, risk analysis, investigation and verification, each with a narrow, auditable set of permissions.

Sensors only collect the fields you allow — prompts and payloads can be redacted or hashed before they leave.

  • SDK, gateway and MCP proxy options
  • Outbound-only connectivity
  • Observe-only by default
  • Redaction at the source

Sensors & services

12 / 12 online
  • sensor-gw-prod

    AI-GATEWAY-PROD · 31 agents

    Sensor
  • sensor-gw-fin

    AI-GATEWAY-FIN · 3 agents

    Sensor
  • otel-ingest

    14 services · GenAI spans

    Collector
  • idp-sync

    4,200 users · 310 groups

    Identity
  • discovery

    48 agents · 212 tools

    Model
  • investigator

    2 investigations running

    Reasoning
  • verifier

    1 check scheduled

    Verification

All sensors observe-only by default · outbound connections only

Agent Discovery

Every assessment starts from what an agent can actually reach.

Nettriva continuously builds a graph of your AI environment: which agents exist, who owns them, which identities they act for, which models and gateways they use, which tools and MCP servers they can call, and which data those tools expose — including agents nobody registered.

When something happens, an investigation is scoped automatically to the agents, tools and data that could actually be involved — not every alert that fired.

  • Agents, owners and identities
  • Models and gateways
  • Tools, MCP servers and API scopes
  • Data stores and destinations

Incident scope · support-agent-07

auto-scoped
AGENT-07out-of-scope callFIN-COPILOTnot involvedKB.SEARCHnominalTICKET.READreturned #88213CRM.EXPORTblocked ×3ERP.QUERYnominalTICKET-STORE#88213 flaggedCRM-CONTACTS0 releasedERP-INVOICESnominal
  • Healthy
  • Warning
  • Critical
  • Incident path

Agent Monitoring

Model calls, tool calls and data access, on one timeline.

Nettriva aligns agent activity from different frameworks, gateways and SaaS systems on a shared timeline, then looks for the causal order: what entered the agent's context first, and what it did next.

That is how a ticket read at 09:38 gets linked to a blocked bulk export at 09:41.

  • Model and tool calls with arguments
  • Identity and on-behalf-of context
  • Retrieved content and its source
  • Policy decisions and approvals

Correlated agent activity · 09:25 – 09:55 UTC

4 sources
Flagged content in context · support-agent-07Out-of-scope tool calls / minRecords requested / min · CRM-CONTACTSPolicy blocks / min · DLP-0409:38 injected ticket read09:41 export blocked

Risk Assessment

Know what changed, and whether it increased risk.

Nettriva keeps a history of every agent's tools, scopes, data access and approval requirements, and understands them semantically — which tools can write, which data is restricted, which actions need a human — rather than as plain configuration text.

It scores agents by reach and behavior, detects drift from approved baselines, and connects recent changes to the incidents that follow them.

  • Drift from approved permission baselines
  • Excessive-privilege detection
  • Change-to-incident correlation
  • Pre-deployment risk review

Permission drift · support agents

3 agents drifted
  • support-agent-07
  • support-agent-09
  • support-triage
# approved baseline (support-agents-v12) vs. running
  tools: ticket.read, ticket.reply, kb.search
- data_scope: tickets:own_queue
+ data_scope: tickets:all
+ tool: crm.export_contacts
- approval_required: [refund.issue]
+ approval_required: []

Introduced

CHG-0412 · Monday · no review recorded

Risk

Bulk PII export · refunds without approval

Action Tracing

Trace any agent action, step by step, across systems.

Follow a single request from the person who asked, through the agent, the data it read and each tool it called, to wherever the result was sent — then inspect each step for sensitive data and the policy decision that applied.

  • From requester to destination
  • Every model and tool call in order
  • Data classification at each step
  • Policy decision at each step

finance-copilot · http.post · 10:02 UTC

6 steps
  1. Requester

    ap-​analyst

    SSO · Finance AP

  2. Agent

    FINANCE-​COPILOT

    owner finance-eng

  3. Data read

    ERP-​INVOICES

    erp.query · 312 rows

  4. Gateway

    AI-​GATEWAY-​FIN

    egress policy: none

  5. Tool call

    MCP-​WEB

    http.post · 2.1 MB

    Suspect step
  6. Destination

    ocr-​api.​example

    external · unapproved

Policy Enforcement

Policies for tools, data and destinations — evaluated per action.

Express what agents may do in terms your security team already uses: which tools an agent may call, which data classifications may leave, which destinations are approved and which actions need a person to confirm them.

New policies start in monitor mode so you can see what they would have done. Enforcement is enabled per policy, with approval, and every decision records the inputs and rule that produced it.

  • Allow, redact, require approval or block
  • Monitor mode before enforcement
  • Scoped to agents, tools and data
  • Every decision explained and logged

Policies · production

18 active
  • DLP-04

    Block restricted PII to non-approved tools

    37 blocks · 24h

    Enforce
  • APR-02

    Payments and refunds require approval

    3 pending

    Approval
  • SEC-07

    Mask secrets and API keys in prompts

    112 masked · 24h

    Redact
  • EGR-01

    Egress allow-list for MCP tools

    14 domains

    Enforce
  • IDN-03

    Agents act only for entitled users

    0 violations

    Monitor
  • MDL-01

    Restricted data stays on approved models

    2 alerts

    Monitor

New policies start in monitor mode · enforcement is enabled per policy

Incident Correlation

Many alerts. One incident. A clear blast radius.

Signals that share a cause are grouped into a single incident using the agent graph and timing, not just text similarity. Each incident shows which agents, tools, records and users are affected — and which are not.

  • Agent-aware de-duplication
  • Records, users and systems affected
  • Linked to changes and content
  • Fewer pages, better context

Merged signals

  • Instruction-like text in retrieved content

    MCP-TICKETS · ticket.read · #88213

    09:38:12
  • Tool call outside approved task scope

    SUPPORT-AGENT-07 · crm.export_contacts

    09:41:03
  • Bulk read requested: 4,812 contact records

    CRM-CONTACTS · Restricted · PII

    09:41:03
  • Policy DLP-04 blocked the transfer

    AI-GATEWAY-PROD · enforce mode

    09:41:04
  • Agent retried with smaller batches

    SUPPORT-AGENT-07 · 3 attempts · all blocked

    09:41:20

Incident INC-2207 · blast radius

5 signals merged
Agents
1
Tool calls
212
Records requested
4,812
Records released
0
  • support-agent-07awaiting containment approval
  • Ticket #88213flagged · source of injection
  • CRM-CONTACTS · Restricted0 records released
  • Other support agentsnot affected

Human-in-the-loop Response

Recommend first. Contain only with approval.

Nettriva does not pause agents, revoke tools or start blocking on its own. Each deployment chooses how far automation may go — and every step is recorded.

  1. 01Observe Only

    Default for every connector

    Record agent activity and evaluate policies without changing agent behavior.

  2. 02Alert & Recommend

    Nettriva generates

    Notify owners of violations and propose containment with evidence, blast radius and rollback.

  3. 03Approval Required

    Person decides

    Sensitive actions and containment steps wait for a named approver with the right role.

  4. 04Enforce Approved Policy

    Scoped policyoff by default

    Block or redact actions that violate an approved policy, scoped to the agents and tools it covers.

  5. 05Verify Result

    Nettriva verifies

    Re-run the evidence checks and confirm the policy behaves as intended without breaking legitimate work.

  6. 06Rollback Guidance

    Person decides

    If verification fails, present the prepared rollback and its expected effect.

Approval required

ct-118 · INC-2206

Revoke MCP-WEB from finance-copilot

Remove the general-purpose web tool from finance-copilot until egress policy EGR-01 covers it. Invoice extraction keeps working through the approved document connector.

[agent finance-copilot · tools]
-  mcp: MCP-WEB      # http.get, http.post
+  # MCP-WEB removed (ct-118) pending egress review
Blast radius
1 agent · 1 tool server
Workflows affected
1 of 14
Method
staged · 15 min monitor
Rollback
one-step restore

Verification plan

  • No egress to unapproved domains for 15 minutes
  • Invoice extraction workflow still succeeds
  • No new tool errors for finance-copilot

Requires role: security-lead · 1 of 1 approvals

Reject Approve change

Audit log · INC-2206

exportable
  1. 10:18:52

    investigator · Generated recommendation

    Revoke MCP-WEB from finance-copilot

  2. 10:19:30

    secops-oncall · Requested approval

    Containment candidate ct-118

  3. 10:21:12

    security-lead · Approved change

    ct-118 · staged · 15 min monitor

  4. 10:21:20

    policy-engine (scoped) · Applied tool revocation

    finance-copilot · 1 MCP server

  5. 10:36:41

    investigator · Verified result

    0 egress to unapproved domains · workflow OK

  6. 10:37:02

    secops-oncall · Resolved incident

    INC-2206 · root cause linked

Security team view

Every agent at a glance.

Governance coverage, open findings, agent inventory and platform activity — the starting point for every review.

  1. Overview
  2. /All agents
SO
OverviewAgentsAgent GraphFindingsInvestigationsPoliciesApprovalsActivityData Flows

Governance overview

Last 24h48 agents

Governance Coverage

91.7%

+4.2 pts this week

Agents Discovered

48

+3 this week · 2 unowned

Open Risk Findings

7

2 high · 5 medium

Tool Calls (24h)

182k

across 212 tools

Policy Blocks (24h)

37

0.02% of agent actions

Approvals Pending

3

median 6m to decision

Open findings

7 open
  • High

    Injected ticket → out-of-scope export attempt

    INC-2207 · 6m ago

  • High

    finance-copilot sent invoices to unapproved domain

    INC-2206 · 38m ago

  • Medium

    Unowned agent calling an external model API

    INC-2201 · 2h ago

  • Medium

    Permission drift · 3 agents vs. approved baseline

    INC-2198 · 5h ago

  • Medium

    Secrets detected in prompts · it-helpdesk

    INC-2195 · 9h ago

Governance posture by team

agents · score
  • Customer Support

    ticketing · CRM tools

    471.0%
  • Finance

    ERP · payments · web

    376.4%
  • Engineering

    repos · CI · cloud

    1493.2%
  • Sales & Marketing

    CRM read · web search

    990.1%
  • People Ops

    HRIS · read-only

    296.8%

Agent inventory

48
Agent inventory (demo data)
AgentFrameworkOwnerEnvToolsRiskStatus
support-agent-07LangGraph · AI-GATEWAY-PRODcx-platformprod9
86
Critical
finance-copilotCustom · Python · AI-GATEWAY-FINfinance-engprod12
64
Warning
unregistered-a1fUnknown · external API— unownedunknown2
58
Warning
sales-researchLlamaIndex · HOSTED-MODEL-Arevopsprod6
47
Healthy
data-analystLangChain · AI-GATEWAY-DEVdata-platformstaging4
41
Healthy
it-helpdeskSemantic Kernel · AI-GATEWAY-PRODit-opsprod8
38
Healthy
code-review-botCrewAI · AI-GATEWAY-DEVplatform-engci5
31
Healthy

Platform activity

  • Collected 212 traces for support-agent-07

    sensor-gw-prod · 09:45:02

  • Ranked 4 hypotheses for INC-2207 · top 91%

    investigator · 09:44:47

  • DLP-04 blocked crm.export_contacts (3 attempts)

    policy-engine · 09:41:04

  • New agent found: unregistered-a1f · no owner

    discovery · 09:30:10

  • Drift detected on 3 agents vs. approved baseline

    permission-watch · 09:12:09

Illustrative product UI with simulated demo data. Not real customer data or statistics.

Adopt AI agents without losing control.

See Nettriva investigate a simulated agent incident end to end, and talk with the team building it about your AI environment.