Forge Agent is the built-in security assistant in the Forge console. Ask about
inventory, activity, sessions, findings, policies, fleet posture, or LLM
Gateway usage using plain language.
Forge Agent is the Console assistant. Forge for devices is the managed
endpoint product, Agent identities represent autonomous workloads, and
Forge MCP is the management interface for MCP-capable assistants. These
products can work together but have separate identities and permissions.
Forge Agent uses the signed-in user’s permissions and organization data. It can
only analyze information Forge collected and retained.
Ask a question
Try questions such as:
- Which AI products were active this week?
- Which people use unapproved MCP servers?
- What happened before this session was blocked?
- Show critical open investigations involving customer data.
- Which devices still need the latest Forge deployment?
- Which models cost the most through LLM Gateway?
- Draft a policy that blocks this tool for contractors.
Forge resolves names to canonical records. If a name is ambiguous, it asks you
to choose rather than combining records silently.
Review changes
Policy changes are proposals. Forge Agent shows the proposed change, and the
live policy remains unchanged until an authorized user selects Apply. If the
policy changed while the proposal was open, Forge asks you to create a fresh
proposal. Applied changes appear in the Audit Log with the
actor and result.
Forge Agent cannot bypass the signed-in user’s permissions. It can prepare a
change only when that user can perform the underlying operation, and sensitive
evidence remains protected by the same approval requirements as the rest of
Forge.
Use JIT Viewing when temporary approval is required for
sensitive session evidence.
Coverage
Forge Agent distinguishes exact totals from searches that return a focused set
of matching records. Exact totals are used for questions such as activity,
usage, and cost summaries. Record searches are suited to reviewing individual
sessions, investigations, devices, and inventory items; Forge identifies when
more matching results are available. It also calls out partial, masked, or
unavailable evidence.
LLM Gateway usage and cost answers cover traffic observed by Forge LLM Gateway;
they do not include unmanaged traffic that bypassed it.
Continue with Inventory, Sessions, or
Investigations.