> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Investigations

> Review and remediate security risks identified across your AI estate.

Investigations surface security risks that require attention across your AI
estate. Forge opens them automatically when its analysis identifies a
meaningful issue in the data collected from your agents, endpoints,
applications, cloud environments, networks, and code repositories.

You do not need to create or assemble investigations yourself. Forge connects
the relevant activity, identities, AI assets, and configurations so your team
can understand what happened and decide how to respond.

<Frame caption="Investigations">
  <img src="https://mintcdn.com/forge-93b579e9/qWsC-LZodDrBBlxW/images/screenshots/investigations.png?fit=max&auto=format&n=qWsC-LZodDrBBlxW&q=85&s=c544d83cfc9d447f751f54e84bf2117e" alt="Forge investigations showing finding status, new findings, risk breakdown, and top concerns" width="3432" height="1924" data-path="images/screenshots/investigations.png" />
</Frame>

## What gets investigated

Forge evaluates individual signals in the context of the wider AI estate and
opens an investigation when a risk warrants human review. Examples include:

* Sensitive data or credentials exposed to an unintended destination.
* Agent tools with excessive, destructive, or unexpected capabilities.
* Prompt injection, tool poisoning, or unsafe handling of untrusted content.
* Risky MCP servers, skills, plugins, or dependencies.
* Unexpected privilege expansion or attempts to bypass established controls.
* Multiple otherwise ordinary capabilities that combine into a high-risk path.

An investigation represents a security concern, not every policy event or
unusual action. Forge prioritizes risks with enough evidence and impact to
require a decision. For risks that span multiple tools or MCP servers, Forge
also verifies that an affected identity can reach the complete combination
before presenting it as an actionable path.

## Find what matters

Filter investigations by status, severity, affected identity, asset, or time
period, then search within the results. Forge paginates large result sets so you
can work through the complete matching set without losing your filters.

Policy violations record individual enforcement events. Investigations connect
related findings, affected assets, identities, and evidence into the security
issue your team reviews and resolves.

## Investigation details

Open an investigation to review:

* The risk level, summary, and why the issue matters.
* The identities, agents, sessions, tools, and AI assets involved.
* Supporting evidence and related activity.
* The affected inventory and its detected configuration.
* Recommended actions available for the specific risk.
* The investigation's status and decision history.

This context helps you determine the scope and likely impact without manually
correlating records across the product.

## Respond

Available actions depend on the affected asset and the controls connected to
Forge. From an investigation, you may be able to:

* Stop affected sessions.
* Restrict access to a risky MCP server, skill, or tool.
* Block, disable, or remove an affected asset.
* Review a prefilled policy or access control before applying it.
* Open the affected asset in Inventory for its complete context.

Forge shows the impact before a containment action is applied. Changes that can
interrupt an agent or workflow require review and confirmation.

## Close the loop

After reviewing the evidence and taking any necessary action:

* Mark the investigation as **Resolved** when the risk has been addressed.
* Mark it as **Dismissed** when it is a false positive, accepted risk, out of
  scope, or duplicate. The reason is retained in the investigation history.
* Reopen a resolved investigation if new evidence changes the assessment.

Resolved and dismissed investigations retain their evidence, rationale, and
history so your team can revisit the decision later.
