See the AI attack surface. Govern the agents behind it.
Connect supported human, agent, model, and MCP activity with accountable ownership, policy state, and the managed path where a control can operate.
MCP Servers
Start with evidence from the AI work you can observe.
Cortex records provider, model, device, user, process, harness, and tool signals on supported capture paths. Security teams can review policy-relevant activity without claiming an inline block.
- Identity, provider, model, and harness context
- Policy-relevant signals with explicit blind spots
- Searchable audit evidence for supported activity





Slack


Put agent identity, ownership, and MCP access in one review.
Cortex already records useful agent and tool signals on supported traffic. The productized inventory shown here is Roadmap and will add coverage confidence, owner, approval state, last seen, and blind spots.
- Human sponsor and non-human identity
- MCP server and tool relationships
- Coverage confidence and explicit blind spots
Enforce only where Cortex owns the decision point.
Inline policy requires the request or execution to traverse a configured Cortex-controlled enforcement point. Current available controls include organization RPM admission and allow or deny policy for supported Cortex-initiated MCP calls.
- Named deployment prerequisite
- Named request or execution path
- Decision evidence attached to the control



NK

HRJLAudit mode before enforce mode.
The Roadmap policy simulation shown here replays a candidate rule against historical activity, exposes affected workflows and exceptions, and reports what Would block in enforce mode before a policy reaches a supported managed path.
- Historical replay and affected workflows
- Exception review before enforcement
- Would block in enforce mode
Govern the managed paths your agents depend on.
Review supported activity, agent and MCP relationships, current enforcement points, and the Roadmap from audit mode to managed enforcement.