AI Command Center (AICC) is a Netskope capability that provides comprehensive visibility, governance, and risk management for AI usage across your organization.
As enterprises rapidly adopt AI services, risks such as shadow AI, data leakage, and unmanaged AI assets increase. AI Command Center addresses these challenges by enabling security teams to:
-
Discover AI applications and services in use.
-
Discover MCP Servers in use.
-
Monitor user interactions with AI systems.
Supported Entities
AICC discovers the following asset types, each surfaced through a specific Netskope product as a source.
| Entity | Definition | Source |
|---|---|---|
| AI Applications | AI Applications Applications that provide AI-driven functionality, such as chatbots, coding assistants, and image and video generation tools. | Next-Gen Secure Web Gateway (NG-SWG) |
| MCP Servers | Integration and execution layers for AI systems. They enable communication between models and external tools, retrieval of contextual data, and execution of actions. | – Agentic Broker – Netskope Client (Endpoint AI Discovery) |
| Agents | AI-enabled extensions that run inside a browser, code editor, or desktop, such as browser extensions, editor extensions, and desktop extensions. | Netskope Client (Endpoint AI Discovery) |
| Models | Models running locally on managed endpoints, such as open-source LLMs running in frameworks like Ollama or vLLM. | Netskope Client (Endpoint AI Discovery) |
| Identities | Users and unknown entities that interact with AI applications and MCP servers. Known identities are users authenticated through your Identity Provider (IdP). Unknown identities represent unauthenticated or unrecognized traffic sources, identified by source IP address. | Next-Gen Secure Web Gateway (NG-SWG) |
The Overview page gives you a high level of insights on AI usage, while the Inventory page enables detailed analysis and response.
AICC Dependencies
AICC builds its visibility on several Netskope products. Turn on the ones that match what you want to monitor.
| Use Case | Required Netskope Product |
|---|---|
| Discover AI Application usage across traffic steered via Netskope | Next-Gen Secure Web Gateway (NG-SWG) must be enabled and fully operational |
| Visibility into MCP server access across traffic steered via Netskope.Discover MCP Servers across traffic steered via Netskope | Agentic Broker must be available and operationalized |
| Visibility to MCP servers installed on managed endpoints | Endpoint AI discovery must be enabled. Requires Netskope Client version 138 or later. See Configuring Discovery of AI Assets on Managed Endpoints to enable Netskope Client in your tenant. |
| Visibility to Models installed on managed endpoints | |
| Visibility to Agents installed on managed endpoints | |
| Visibility into Alerts | Data Loss Prevention or Threat Protection must be configured |
| Visibility to Guardrail Alerts | AI Guardrails must be available and functional |
| Visibility to Risk for AI Applications | AI Sec Ops must be available and enabled |
Enableing required Netskope products lets AICC discover AI assets accurately and surface insights you can act on.
Configure Role for AICC
To open the AICC dashboard, your role also needs the Security Posture > AI Visibility permission. See Getting Started with AI Command Center to set this up.

