RayShield

Pillar 1

Discovery

Find every human and agent using AI in your engineering org — from your first log ingest. No agent on endpoints, no certificate, no proxy, no network change required.

Two collectors, one inventory

The discovery sensor runs in two modes and they can operate simultaneously.

Network tap. The pcap collector reads a SPAN or mirror port and parses TLS ClientHello SNI and JA3 TLS fingerprints from raw frames — no decryption. JA3 fingerprints identify the SDK runtime (Python, Node, Go, Rust) even when SNI is hidden by Encrypted Client Hello.

Log ingest. The ingest collector stands up an HTTPS listener that accepts forwarded logs from your existing SASE, NGFW, DNS and MDM pipelines. Because these logs are user-attributed above the crypto layer, they are immune to ECH, DoH and QUIC opacity that defeats packet inspection. Fourteen formats are supported: Zscaler, Cloudflare, ProxySG, Forcepoint, Prisma, Umbrella, Netskope, Route 53, Azure DNS, GCP DNS, Okta, Entra, Jamf and Intune.

What the inventory shows

Records are deduplicated per source and service within five-minute windows, matched against a 215-service catalog across 18 categories, and flushed to the fleet dashboard. Results are live at first ingest — no waiting period.

  • Per-user and per-device attribution — who is using what, from which device
  • Every autonomous agent running in your org: custom scripts, workflow bots, IDE agents, agentic SaaS
  • Risk scores 0–100 per service
  • Change detection: new services, risk increases, and first personal-account sightings since the prior window
  • OAuth scope extraction from Okta and Entra events — what the service was granted, not just that it was used
  • Which agents can write to external destinations — Notion, Slack, GitHub — with no DLP in the path
  • Coverage sparkline showing signal quality over time

Output is exportable as CSV or JSON.

Service catalog

215 services across 18 categories: coding assistants, model APIs, agentic SaaS, AI-native browsers, image generation, meeting AI, voice AI, productivity copilots, vector databases and others. Risk scores combine data-residency posture, egress scope (what the service can write to), and whether personal accounts are detectable alongside corporate ones.

Separability matters: for tools where AI is a non-separable capability rather than an identifiable service call (a coding IDE with built-in suggestions, for instance), that distinction is recorded in the catalog. You see what is actually controllable versus what requires endpoint-layer enforcement.

Agentic burst detection

More than five API calls in ten seconds from the same source flags agentic behaviour — the cadence of an autonomous agent, not a human typing. Flagged sources surface in the inventory with a confidence marker so your team can distinguish human-tool usage from running agents.

This is the signal that surfaces Claude Code sessions running autonomously, workflow bots looping on a schedule, and IDE agents operating in the background — without any per-endpoint agent required.

What you get from a pilot

  • Per-user attribution of every human using AI tools — approved or shadow — matched against the 215-service catalog
  • Every autonomous agent running in your org identified by agentic burst pattern
  • Which humans and agents hold credentials, and what those credentials can reach
  • Which agents can write to external destinations with no DLP in the path
  • A risk-ranked findings report, mapped to OWASP agentic risk categories
  • Change detection since the prior observation window
  • A readout session with your security and engineering leads

Discovery findings feed directly into policy: you approve the observed allowlist and it deploys to your endpoint protection layer without a reinstall.

An inventory of every human and agent — from your first log ingest

No agent on endpoints. No production workflow touched. Results within hours.

Deployed via Jamf, Kandji or Intune. No engineer action needed.