Event details
What are the rules that define what a "risky" agent is? So if an agent is determined as "risky", then how are those signals captured?
A risky agent is one whose behavior—especially the data it generates or accesses—indicates a higher likelihood of sensitive data exposure or policy violations. IRM determines this by analyzing signals from agent activity (e.g., responses, data access, sharing) against policy-defined indicators and behavioral baselines, then aggregating those signals into a risk score and assigning a risk level to the agent.
- arinkominsMay 12, 2026Iron Contributor
Is there any documentation which details this out now? So you must have IRM configured to have this piece work? What are the policy-defined indicators?
As a follow-on, should risky behavior be detected, do you have plans to notify the AI administrator?