Skip to main content
Forge Agent is the built-in security assistant in the Forge console. Ask about inventory, activity, sessions, findings, policies, fleet posture, or LLM Gateway usage using plain language.
Forge Agent is the Console assistant. Forge for devices is the managed endpoint product, Agent identities represent autonomous workloads, and Forge MCP is the management interface for MCP-capable assistants. These products can work together but have separate identities and permissions.
Forge Agent uses the signed-in user’s permissions and organization data. It can only analyze information Forge collected and retained.

Ask a question

Try questions such as:
  • Which AI products were active this week?
  • Which people use unapproved MCP servers?
  • What happened before this session was blocked?
  • Show critical open investigations involving customer data.
  • Which devices still need the latest Forge deployment?
  • Which models cost the most through LLM Gateway?
  • Draft a policy that blocks this tool for contractors.
Forge resolves names to canonical records. If a name is ambiguous, it asks you to choose rather than combining records silently.

Review changes

Policy changes are proposals. Forge Agent shows the proposed change, and the live policy remains unchanged until an authorized user selects Apply. If the policy changed while the proposal was open, Forge asks you to create a fresh proposal. Applied changes appear in the Audit Log with the actor and result. Forge Agent cannot bypass the signed-in user’s permissions. It can prepare a change only when that user can perform the underlying operation, and sensitive evidence remains protected by the same approval requirements as the rest of Forge. Use JIT Viewing when temporary approval is required for sensitive session evidence.

Coverage

Forge Agent distinguishes exact totals from searches that return a focused set of matching records. Exact totals are used for questions such as activity, usage, and cost summaries. Record searches are suited to reviewing individual sessions, investigations, devices, and inventory items; Forge identifies when more matching results are available. It also calls out partial, masked, or unavailable evidence. LLM Gateway usage and cost answers cover traffic observed by Forge LLM Gateway; they do not include unmanaged traffic that bypassed it. Continue with Inventory, Sessions, or Investigations.