Skip to main content
Investigations surface security risks that require attention across your AI estate. Forge opens them automatically when its analysis identifies a meaningful issue in the data collected from your agents, endpoints, applications, cloud environments, networks, and code repositories. You do not need to create or assemble investigations yourself. Forge connects the relevant activity, identities, AI assets, and configurations so your team can understand what happened and decide how to respond.
Forge investigations showing finding status, new findings, risk breakdown, and top concerns

Investigations

What gets investigated

Forge evaluates individual signals in the context of the wider AI estate and opens an investigation when a risk warrants human review. Examples include:
  • Sensitive data or credentials exposed to an unintended destination.
  • Agent tools with excessive, destructive, or unexpected capabilities.
  • Prompt injection, tool poisoning, or unsafe handling of untrusted content.
  • Risky MCP servers, skills, plugins, or dependencies.
  • Unexpected privilege expansion or attempts to bypass established controls.
  • Multiple otherwise ordinary capabilities that combine into a high-risk path.
An investigation represents a security concern, not every policy event or unusual action. Forge prioritizes risks with enough evidence and impact to require a decision. For risks that span multiple tools or MCP servers, Forge also verifies that an affected identity can reach the complete combination before presenting it as an actionable path.

Find what matters

Filter investigations by status, severity, affected identity, asset, or time period, then search within the results. Forge paginates large result sets so you can work through the complete matching set without losing your filters. Policy violations record individual enforcement events. Investigations connect related findings, affected assets, identities, and evidence into the security issue your team reviews and resolves.

Investigation details

Open an investigation to review:
  • The risk level, summary, and why the issue matters.
  • The identities, agents, sessions, tools, and AI assets involved.
  • Supporting evidence and related activity.
  • The affected inventory and its detected configuration.
  • Recommended actions available for the specific risk.
  • The investigation’s status and decision history.
This context helps you determine the scope and likely impact without manually correlating records across the product.

Respond

Available actions depend on the affected asset and the controls connected to Forge. From an investigation, you may be able to:
  • Stop affected sessions.
  • Restrict access to a risky MCP server, skill, or tool.
  • Block, disable, or remove an affected asset.
  • Review a prefilled policy or access control before applying it.
  • Open the affected asset in Inventory for its complete context.
Forge shows the impact before a containment action is applied. Changes that can interrupt an agent or workflow require review and confirmation.

Close the loop

After reviewing the evidence and taking any necessary action:
  • Mark the investigation as Resolved when the risk has been addressed.
  • Mark it as Dismissed when it is a false positive, accepted risk, out of scope, or duplicate. The reason is retained in the investigation history.
  • Reopen a resolved investigation if new evidence changes the assessment.
Resolved and dismissed investigations retain their evidence, rationale, and history so your team can revisit the decision later.