Reagent Docs

FAQ

Frequently asked questions about Zaun Reagent.

General

What is Reagent?

Reagent is Zaun's AI Adoption Security product. It gives you one place to govern every AI tool your teams adopt and use, from procurement to production: discover it, assess it, enforce policy on it, watch how it behaves, and see what it costs.

What makes Reagent different?

  • One pane for AI adoption. Discovery, runtime, and spend in a single view.
  • No new sensors. Reagent correlates the identity provider, EDR, gateways, cloud accounts, and AI tools you already own.
  • Contain at machine speed. AI misbehaves in seconds. Reagent's inline gate rejects a request before it leaves, and armed response actions fire without waiting for a human.
  • Private by default. Personal data is masked in findings. A reveal is confirmed and audited.
  • Honest states. Coverage, enforcement, and spend all report what is measured. A gap shows as a gap, never as a clean result.

Does Reagent replace my EDR, identity provider, or web gateway?

No. Reagent reads from them. Every connection on the Connections page is to a tool you already run, and each setup guide lists the read permissions it needs and the optional write permissions that enable response actions.

What is a Forward Deployed Engineer?

A named Zaun engineer who works alongside your team on rollout, policy tuning, and the edge cases that block production. Connection setup does not depend on one; every tile on the Connections page is self-serve.

Coverage

What counts as shadow AI?

AI that is in use but not sanctioned: discovered through telemetry rather than an approved rollout. Each shadow entity can be confirmed or dismissed from the Discover queue.

What are the discovery signals?

Categories of AI usage Reagent can inventory, such as AI app sign-ups and OAuth grants, AI desktop apps, local LLM runtimes, coding agents, MCP servers, and AI features inside sanctioned SaaS. Each connection lights up one or more of them, and each setup guide under Connect Your Stack says which.

Why is Discover empty?

Discover shows only what your connections found. Connect a source, run Automated Discovery, and rows appear as telemetry lands. Template signals wait until you confirm the data source on your environment.

Does Reagent read prompts?

Only where a source carries them. Claude Code and Cowork telemetry include user prompts and tool results. The Zaun Agent Gateway sees routed requests inline. Perplexity's webhook streams literal query and answer text. Endpoint sweeps never read file contents, and identity and SaaS audit connectors carry identity and action, not content. Where content is captured, personal data is masked by default.

What is ABBA?

Agent and Bot Behavioral Analytics: Reagent's behavioral monitoring for AI agents. It learns what normal looks like for every AI identity in your environment, flags what is not, and can respond through the tools you connected. It lives on the Monitor page in Reagent.

What can Reagent contain?

What your connections allow. With write permissions granted: revoke an Okta session or suspend a user, isolate a host in CrowdStrike or SentinelOne, block a tool or an MCP server at the Zaun Agent Gateway, freeze a session, and DM the developer to confirm or coach. Each action has an enabled toggle and an auto-fire toggle that requires engineer sign-off.

Platform

Which tools does Reagent connect to?

Identity providers (Okta, Google Workspace, Microsoft Graph), EDR (CrowdStrike, SentinelOne, Defender for Endpoint), AI tools (Claude, ChatGPT, Copilot, Cursor, Codex, Gemini, Atlassian Rovo, Slack, Snowflake Cortex, ServiceNow, Salesforce Agentforce, Devin, Glean, Perplexity, Replit, Kiro, and more), AI gateways (Zaun, LiteLLM, agentgateway, Kong, AgentCore, Azure AI Foundry, Google), cloud (AWS, Azure, GCP, Wiz, Upwind), networking (Zscaler, Netskope, Cato, Cloudflare, PAN-OS, FortiGate, Cisco, Alkira, LayerX), and GitHub. The full list with setup steps is on Connections.

Where is my data stored?

In your environment's own data lake, either in Zaun's cloud or inside your own boundary. Data is encrypted in transit and at rest, and retention is configurable per environment. See Deployment.

Is Reagent SOC 2 compliant?

Yes. Zaun is SOC 2 Type II. Contact us for the latest report.

Why does Reagent ask for LLM provider credentials?

Reagent's own analysis (investigations, alert triage, reports, the assistant) runs on model tiers you configure under Settings → AI Inference, so you choose the provider and the models. On AWS deployments a platform-default Bedrock model carries chat until you pin explicit tiers.

Getting started

What should I connect first?

Your identity provider and your EDR. Identity resolves who is using AI; the EDR sees agents and MCP servers on hosts and enables response actions. Then add the agentic tools your teams use, or the Zaun Agent Gateway for inline control.

How long does setup take?

Most connections take five to thirty minutes each, depending on the vendor's credential flow. The four setup steps are on Getting Started. Discovery results appear as soon as the first signals run.

How do I contact support?