The Axonius AI Agent --copy
The Axonius AI Agent is a conversational assistant built directly into the platform. You can type questions in plain language — such as "How many devices haven't been seen in 30 days?" or "Show me all high-severity CVEs on internet-exposed devices" — and the agent finds the answer, builds the query, or takes the action on your behalf.
The agent is not a single general-purpose model. It is a multi-agent system: a supervisor receives your message and routes it to the specialist best suited for the task. Each specialist has access to a defined set of tools it can call — such as querying assets, searching globally, reading reports, or triggering enforcements — and a knowledge base of Axonius-specific guidance.
What You Can Do with the AI Agent
Here's a comprehensive overview of what you can do with this AI agent — organized by domain, with concrete examples you can ask right now.
🔍 Query & Asset Discovery
Ask questions in plain language — the agent translates them into queries, runs them on your data, and shows the results. See Queries for more information.
Examples:
- "How many Windows servers are missing CrowdStrike?"
- "Show me devices that haven't been seen in the last 30 days"
- "Find all users with admin rights who haven't logged in for 90 days"
- "Which devices have Log4j installed?"
- "List devices that appeared in my environment this week"
You can also save any query as a reusable saved query for dashboards, enforcements, or reports.
📊 Breakdowns, Charts & Dashboards
Segment and visualize your data — and pin the results to a dashboard.
Examples:
- "Break my devices down by OS type"
- "Show me a pivot of risk level by device class"
- "How many devices does each adapter cover?"
- "Create a Pivot Summary chart of devices missing EDR on my Security dashboard"
- "Build me a SentinelOne agent version drift chart" (based on your saved preference)
🩺 Platform Health Checks (Virtual Employee Runs)
One-turn briefings that sweep an entire domain and surface the worst findings first.
Examples:
- "Run my system health check" → discovery cycle, adapter errors, gateways, stuck runs
- "Run my data hygiene check" → stale, single-source, low-confidence, ownership gaps
- "Run my coverage check" → broken agents, unmanaged devices, category gaps
- "Run my identities check" → MFA gaps, dormant accounts, admin surface
- "Run my AI security check" → shadow GenAI apps, AI software on devices, AI cloud services
- "What are the smartest questions to ask right now?" → ranked by what changed this week
🔧 Adapter & Data Source Management
Understand, troubleshoot, and act on your connected data sources.
Examples:
- "Which adapters are failing and why?"
- "Why does my device count show different numbers in the fetch history vs the devices table?"
- "Analyze my last discovery cycle — what was slow?"
- "What fields does the Qualys adapter populate in my environment?"
- "Help me connect the Okta adapter" → guided setup, opens the form pre-filled
- "Which adapters should I connect next?"
⚙️ Automation & Enforcements
Review, create, and manage automated actions.
Examples:
- "What enforcements ran last night and did they succeed?"
- "Create an enforcement that tags devices missing SentinelOne every cycle"
- "Email me the results of this query every discovery cycle"
- "Show me enforcements that never ran — dead weight cleanup"
- "Diagnose why this enforcement failed"
- "Run this enforcement on these 5 devices"
🔐 Security & Exposure Triage
Prioritize and act on vulnerabilities and security findings.
Examples:
- "Show me critical, exploitable findings on internet-exposed assets"
- "Run my exposures triage — what should we ticket today?"
- "Which recommended actions cut the most risk?"
- "Are we affected by CVE-2024-1234?"
- "Which findings are overdue on SLA by remediation owner?"
- "Which of my findings are waiting for exception approval?"
👤 Identity & Access
Govern user accounts across all connected sources.
Examples:
- "Find disabled accounts still holding SaaS app access"
- "Which admins haven't logged in for 60 days?"
- "Show me users with MFA gaps, admins first"
- "Find every device a specific person uses"
- "Which service accounts have no named owner?"
📦 Software Intelligence
Track, govern, and secure your software estate.
Examples:
- "What are my top installed software products?"
- "Show me devices still running end-of-life software"
- "Which devices are behind on the latest SentinelOne agent version?" (your primary EDR)
- "Find unapproved software against our Software Registry"
- "Is there a version-sprawl problem with any product?"
☁️ SaaS & Cloud
Manage your SaaS landscape and cloud infrastructure.
Examples:
- "Show me shadow AI apps discovered without management evidence"
- "Find paid SaaS seats that nobody is using"
- "Give me a multi-cloud inventory by provider, account, and region"
- "Which SaaS apps have misconfigured security settings?"
- "Show app tenants not behind SSO"
📅 Scheduling & Automation
Turn any question into a recurring check.
Examples:
- "Schedule this query to run every Monday morning"
- "Alert me after every discovery cycle if broken agents exceed 50"
- "Set up a workflow that tags a device when it enters a query"
🎓 Learning
Learn the platform interactively on your own data.
Examples:
- "Teach me the Query Wizard step by step"
- "Walk me through building a dashboard chart"
- "Help me set up my environment — what should I connect first?"
The agent works on your live data — every count, list, and chart is computed against your actual environment. Nothing is saved or changed without your explicit approval.
Required Permissions
The AI Agent can perform the same tasks and access the same data as defined for your role and user account.
Access to the AI Agent requires the AI Agents permission to be enabled for your role. If the AI Agent button is not visible in the navigation bar, contact your Axonius administrator to confirm that your role includes this permission.
Some agent actions — such as creating tickets, running enforcements, or updating cases — require additional permissions beyond access to the agent itself. The agent will tell you what is missing if you attempt an action your role does not permit.
Your administrator may also set a per-user usage quota for the AI Agent. If you reach your quota, the agent will let you know.
See Managing Roles to learn about roles and permissions in Axonius.
Updated about 2 hours ago
