All Products
Search
Document Center

:AI asset management

Last Updated:Jun 22, 2026

AI Asset Management discovers AI agents and related components across your enterprise endpoints and builds a unified asset inventory. It identifies security risks—such as shadow AI usage, prompt leakage, and unauthorized access—introduced by AI-powered productivity tools like OpenClaw, and enables you to enforce control policies to keep AI applications secure and compliant.

Scan AI assets

Use AI Asset Management to scan endpoints for installed AI agents and related components, build an asset inventory, and discover AI assets that pose security risks.

Start a scan

  1. Log on to the Secure Access Service Edge console.

  2. In the left-side navigation pane, choose Agent Office Security > AI Asset Management.

  3. On the AI Asset Management page, turn on the Asset Scan toggle in the upper-right corner to enable asset scanning.

  4. Click Configure next to the Asset Scan toggle. In the Quick Scan Configuration dialog box, configure the following parameters.

    Parameter

    Description

    Enable Scan Task

    Turn on the toggle to enable the scan task.

    Enable Agent Security Scan

    When enabled, the system also scans skills associated with AI agents on endpoints.

    Enable Session Scan

    When enabled, the system scans agent behavior logs. You can view and download the logs from the log management page.

    Scan Scope

    Select the scan scope. Valid values: All Users and Specific User Group.

  5. Click Start Scan.

View scan results

After the scan is complete, you can view the results in either of the following views:

  • Data visualization: Click Visual Analytics in the upper-right corner of the AI Asset Management page to view the Top 5 AI Asset Installations and Pending Threats charts.

  • Table view: Click Table View in the upper-right corner of the AI Asset Management page. Switch between the AI Agents, LLMs, Tools, and Skills tabs to view details of each asset type, including the number of associated employees and devices. Click the number in the Terminal Count or Employee Count column to view the associated details.

Export asset data

To export scan results for offline analysis or compliance auditing, perform the following steps on the AI Asset Management page:

  1. Click Table View in the upper-right corner. Switch to the AI Agents, LLMs, Tools, or Skills tab.

  2. Click Export Threats and select an export method:

    • Export All: Exports all assets under the current tab.

    • Export by Search Conditions: Exports only the assets that match the current search filters.

  3. Click Export Task to view all export tasks, locate the target task, and download the results.

Configure control policies

After you identify AI assets that pose security risks, you can configure control policies to enforce appropriate measures based on risk severity.

  1. On the AI Asset Management page, click Control Policy in the upper-right corner.

  2. Click Create Policy.

  3. In the Create Policy panel, configure the following parameters:

    Parameter

    Description

    Action

    The action to take when a specified agent program is detected running.

    • Block Startup: Blocks the agent program from starting.

    • Prompt Only: Displays a popup notification without blocking startup.

    Scope

    The scope in which the policy takes effect.

    • Specific User Group: Applies to a specific user group.

    • Specific Device Tag: Applies to devices with a specific tag.

    • Specific Device: Applies to specific devices.

    • All Users: Applies to all users.

    Exception User

    The users to exclude from the policy scope.

    Management Agent

    The agent programs to control. You can select multiple agents.

    Priority

    The priority of the policy. A smaller value indicates a higher priority. Policies are enforced in priority order.

    Prompt Display Configuration

    The notification message displayed when a controlled agent program is detected running. A popup notification is displayed regardless of whether Action is set to Block Startup or Prompt Only.

Free trial

For information about the free trial, see Apply for a free trial.