Agentless first
Use existing firewalls, SASE platforms, and secure web gateways as the
primary enforcement layer. Forge for devices is available for local or
off-network coverage.
Automatic routing
Redirect supported browser, desktop, API, and MCP traffic to the
appropriate Forge gateway without hooks or per-client gateway
configuration.
Behavioral context
Connect identity, configuration, model activity, tool activity, and
outcomes across complete agent sessions.
AI enablement
Give employees governed access to approved AI while improving adoption,
configuration, usage, and cost.
Comparisons
Endpoint and network security
Endpoint and network security
Endpoint and network security was designed primarily around human-initiated
process and traffic activity. Agent activity may be machine-to-machine, span
multiple systems, or execute outside the observed control point.
Traditional telemetry can show that a process contacted a destination
without explaining the model, tool, identity, intent, or surrounding
sequence.Forge advantageForge adds agent, model, MCP, tool, identity, content, and session context.
It also compiles broad AI access policy into existing network controls and
routes supported traffic for content-aware enforcement.
Sees
Processes, devices, destinations, and traffic.
Misses
AI-native semantics and behavior spanning sessions, systems, and
identities.
Cloud security
Cloud security
Cloud security products govern resources, workloads, permissions, and
posture inside connected cloud environments. Agents also operate across
endpoints, repositories, SaaS applications, external APIs, and third-party
tools. Activity involving those external systems falls outside any single
cloud provider’s visibility boundary.Forge advantageForge connects cloud evidence with endpoint, network, identity, code, SaaS,
and runtime activity in one inventory and behavioral record. It preserves
the relationship between the cloud workload and the actions it takes
elsewhere.
Sees
Workloads and resources inside connected cloud boundaries.
Misses
Behavior spanning endpoints, code, SaaS, tools, and external services.
Identity access management
Identity access management
Identity and access management determines who an identity is and what it
may access. An authentication or entitlement decision does not reconstruct
what an agent subsequently did, the order of its actions, or their
downstream effects. A permission check at the beginning of a session says
little about the decisions that follow.Forge advantageForge uses identity as policy context throughout the session. It attributes
model and tool activity to people and workloads, evaluates supported actions
as they occur, and connects decisions to sessions, violations, and
investigations.
Sees
Identities, groups, authentication, and entitlements.
Misses
Actual agent behavior, successive decisions, and resulting impact.
LLM gateways
LLM gateways
A standalone LLM gateway sees model requests explicitly configured to pass
through it. Browser AI, SaaS AI, desktop agents, direct integrations, and
MCP activity can remain outside that boundary. Manual gateway configuration
must be applied to each client and can be edited or removed by the end user.Forge advantageForge combines its LLM Gateway with enterprise discovery and automatic
routing. Supported traffic reaches the governed path without hooks, SDK
changes, or per-client gateway configuration, while Inventory retains
visibility across the wider AI estate.
Sees
Model requests and responses routed through the gateway.
Misses
Unrouted AI surfaces and context from agents, tools, identities, and
systems.
MCP gateways
MCP gateways
A standalone MCP gateway evaluates MCP discovery and tool calls routed
through it. Risk can emerge from what the agent observed, which model made
the decision, what preceded the call, and how the result was used. Direct
APIs, hard-coded tools, user-created integrations, and shadow MCP usage can
remain outside an explicitly configured gateway.Forge advantageForge combines MCP Gateway enforcement with Registry, discovery, identity,
model activity, and normalized sessions. Supported tool traffic can be
routed automatically, and each decision is evaluated within the broader
agent interaction.
Sees
MCP servers and tool calls routed through the gateway.
Misses
Shadow usage, non-MCP tools, direct integrations, and risk across a
sequence.
Behavior
Identity → Configuration → Model activity → Tool activity → OutcomeAgents create risk through sequences, not only individual calls. Forge
correlates the complete interaction so policy and investigations can evaluate
what the agent is doing over time.
Enablement
The same inventory, identity, routing, and behavioral context provides the infrastructure for expanding AI safely.Governed access
Publish approved MCP servers and skills, then provide identity-aware
self-service access.
Consistent experience
Distribute native configurations and route existing workflows onto governed
services transparently.
Continuous improvement
Improve adoption, subscriptions, cost, policies, models, and tools using
actual behavior.