The Netskope DLP AISecOps Agent is built for one purpose: to give data security analysts their time back.
The agent transforms raw data into a streamlined incident-to-resolution pipeline through five key stages:
- Signal Ingestion: Collects millions of DLP signals across cloud, web, email, and endpoints to eliminate blind spots.
- Analysis & Clustering: Filters noise and groups related incidents into a single case centered around specific users, data, applications, or devices.
- Enrichment: Automatically enriches the cases with context around identity, application, device & data.
- Recommendation: Provides a clear verdict and risk score based on business context, suggesting the best next steps.
- Resolution: Analysts can execute actions such as revoking sharing or muting benign activity directly from the Netskope One Orchestrator.
For more details:
Overview
To begin using the Netskop DLP AISecOps Agent, log into the Netskope admin console and click AISecOps.

The UI will give insight into Total New Cases, Critical Risk Cases, Average Case Age, and Total Views. The Overview can be filtered by the timeframe using the drop-down box at the top right.
The Incident-to-Resolution Pipeline provides the complete case lifecycle from detection to close. Your Alerts will flow into Incidents which are then grouped into cases and can be further filtered based on severity.
Cases

Cases are a construct of one or more incidents that have been grouped based on customizable rules.
You can filter these cases along the top bar based on Name, Status, Risk Level, Assigned Analyst, Recency, and Timeframe.

Clicking on a case will take you to the case details where you can view all the incidents which comprise the case. From here, you can:
- Re-investigate – Re-investigate an already investigated case.
- Assign – Assign a case to an analyst
- Download –
- Close case – Close the case out.
- Investigate – Launch an investigation to dig into the incidents. The Agent will gather all the evidence across the Netskope platform and provide a risk assessment and recommendation for remediation.
You can also perform bulk actions like Assign Cases or Close Cases when you select multiple cases.

Along the top, you will see Similar Cases, Analysis, Incidents, and Investigation Trail.
The Incidents tab will let you click on an Incident and get additional details on the Incident. You can also click View in Incident Management to get even more detail.

The Similar Cases tab will list cases which are similar in nature.

The Investigation Trail tab will provide information on the investigation and also rename the case based on the findings.

All this information will be populated on the Overview tab after an investigation has been launched along with an Executive Summary and series of Recommended Actions.
You can also see Suggested Remediations.

For information on creating cases, see Case Creation.
Views

The Views tab contains two sections, Data Loss and Insider Threat.
Data Loss
The Data Loss sub-tab allows you to filter incidents by Sanctioned Instances, Critical Severity, PCI Data, and PII Data. These views provide additional granularity and allow analysts to monitor for any fluctuations in behavior across the organization.

Clicking on an insight will provide the analysts with more detail on any spikes in Incidents generated by specific user actions.

Insider Threat

The Insider Threat page allows you create user watchlists for specific users or groups in order to monitor for malicious activity or active malware infections.
Clicking on a user will allow you to get analytics on their behavior and see cases associated with their activity

For more information, see Views.

