Network Sources
Network Sources (Admin → Agent Registry → Network) surfaces the shadow AI found in your CASB/SWG logs: which corporate source IPs and users are calling LLM APIs, even where no SDK or endpoint agent is deployed. It’s fed by the CASB & Network connectors — Cisco Umbrella, Zscaler, and others.The discovery window
Activity is reported over a rolling window — 30 days by default (configurable viaNETWORK_DISCOVERY_WINDOW_DAYS). A few sub-views (top domains, top users, unknown domains) use a fixed 7-day window. On first connect, a connector runs a background backfill so history is available immediately.
What each source shows
Drilling into a source shows a per-observation table (domain, provider, connector, calls, user, last-seen).
Triage workflow
- Register a source you recognize (it becomes part of your known inventory), or elevate it for follow-up.
- Ignore / unignore sources that are expected/noise.
- Review the unknown-domains queue to classify AI destinations the catalog didn’t recognize.
- Explore analytics and the topology view for org-wide patterns.
- Export to CSV.
Syncing
Run Sync per connector or Sync All; connectors also sync on a schedule (default every 30 minutes). Backfill progress and connector staleness are shown inline. Connector setup lives in Admin → Integrations → Network.Related
- CASB & Network (SWG) integrations — connect the log sources.
- Endpoint Agent — for endpoints you can manage directly.
- AI Discovery & Inventory Overview

