AI visibility and control
AI Visibility and Control
GravityZone AI Visibility and Control (AIVC) helps you discover AI technologies used across your organization, assess their associated security risks, and identify the endpoints affected by them.
AIVC provides centralized visibility into:
Online AI applications and services
Developer tools and coding assistants
Local AI models and runtimes
Model Context Protocol (MCP) clients and servers
AI agents, agent frameworks, and skills
Other supported AI-related components
AIVC is available for supported Windows endpoints and requires an eligible license, the Risk Management module, and the corresponding policy settings.
How AIVC works
AIVC scans supported endpoints and organizes the collected information into AI services and AI findings:
An AI service represents a discovered AI technology or component, such as an AI application, coding assistant, AI agent, local runtime, or MCP component.
An AI finding represents a security risk identified in one or more AI services. Examples include network exposure, shadow AI, excessive privileges, untrusted software sources, and insecure configurations.
A finding can affect multiple AI services and resources. Similarly, an AI service can have multiple associated findings and can be present on multiple endpoints.
AIVC calculates risk scores to help you identify and prioritize the services and findings that require attention.
AIVC pages
You can access AIVC from the AI Visibility and Control section in the main GravityZone navigation.
AI services
The AI services page provides an inventory of the AI technologies discovered on the endpoints of the selected company.
Use this page to:
Review discovered AI services and their categories.
Compare their risk scores.
Identify related AI components.
View the affected resources and platforms.
Add services to the watchlist.
Ignore services that do not require further investigation.
For more information, see AI services.
AI findings
The AI findings page displays the security risks associated with discovered AI services.
Use this page to:
Review and prioritize AI-related risks.
Identify the category and risk score of each finding.
View the affected AI services and resources.
Review supporting information and mitigation guidance.
Add findings to the watchlist.
Ignore or restore findings.
For more information, see AI findings.
Smart Views
The AI services and AI findings pages use Smart Views to organize and filter information.
Default views are available for:
All services or findings
Items with a high risk score
Items added to the watchlist
Ignored items
You can customize the available filters and save the resulting configuration as a new Smart View. If you manage multiple companies, select the company whose data you want to investigate. AIVC displays information for one company at a time.
AIVC and PHASR
When AIVC and PHASR are licensed together, GravityZone can extend PHASR behavioral analysis and access control to discovered AI agents.
Administrators can enable PHASR protection for supported AI-agent activities. Security analysts can then review AI-agent behavioral profiles, receive AI-agent-specific recommendations, and manage access through the PHASR Edit access flow.
For more information, see Managing AI agents with PHASR.
Getting started
Before using AIVC:
Make sure that the company has an eligible AIVC license.
Enable Risk Management and AIVC in the applicable policy.
Make sure that the Risk Management module is installed on the supported Windows endpoints.
Go to AI Visibility and Control > AI services or AI Visibility and Control > AI findings.
Select the company you want to investigate.
Click to discover AI services and identify associated risks.
After the scan is complete, use the available Smart Views, filters, risk scores, and relationship information to investigate the discovered services and findings.