AI Security Operation Guide
Overview
Cato AI Security logs user activity with GenAI applications and the invocations your Homegrown Agents send to the models they call. Events are visible in the Cato Management Application (CMA) on the Home > Events page, and can be forwarded to a SIEM, data lake, or other external platform for retention, correlation, and alerting.
Events carry metadata only. The prompts and responses exchanged with the model are not stored in the event. That content is retrieved separately, on demand, from Cato's GraphQL API by a caller whose API key holds the required permission.
Investigating an AI Security finding is therefore a two-step workflow:
- Forward events to your SIEM. Configure an Event Integration, filtered to the AI Security event type, so that AI Security events arrive alongside the rest of your Cato telemetry.
- Use the API to pull the sensitive content for the events that warrant it. When an event requires investigation, query the API with the identifiers carried on that event to retrieve the prompt and the model response.
Note: AI Security interactions, including sensitive prompts and responses, can be reviewed directly in CMA without using the API. AI Security for Apps > Interaction Explorer lists the invocations for your Homegrown Agents, and AI Security for Users > Session Explorer lists user sessions with GenAI applications. Both allow you to drill into an individual record. The API is intended for investigations that begin in your SIEM, and for programmatic retrieval.
Cato Events
All AI Security events carry the Event Type AI Security. The event sub-type identifies which part of AI Security generated the event, and determines which fields the event carries and which API query returns its content. An interactive event schema exporer is available at Cato Event Schema.
CMA module | Event sub-type | Description |
|---|---|---|
AI Security for Users | AI User Interaction | Generated by user activity with GenAI applications. |
AI Security for Applications | Application Runtime Protection | Generated when a Guard policy protecting one of your Homegrown Agents takes action on an interaction. |
AI User Interaction Fields
Field | Type | Description |
|---|---|---|
account_id / account_name | long / keyword | Cato account identifier and display name. |
ad_name / user_id / user_name | keyword / long / keyword | The Cato user, and their Active Directory display name. |
vpn_user_email | keyword | The user’s email address. This is the field to filter on when an investigation begins from an email address. |
application_id / application_name | keyword | The GenAI application, for example microsoft_copilot / Microsoft Copilot. |
application_type / categories | keyword | Application classification, for example type System and category Generative AI Tools. |
ai_app_risk_level / application_risk | keyword / integer | Cato’s risk rating for the application, as a label and as a numeric score. |
is_cloud_app / is_sanctioned_app | boolean | Whether the application is cloud-hosted, and whether it is sanctioned for the account. |
app_activity_type | keyword | The activity the event represents. Possible values: Web Request, Prompt, Detection, LLM Response, File Transaction, Engagement Response. |
rule_id / rule_name | keyword | The policy rule that matched, where one fired. Independent of app_activity_type and not exclusive to any one value. |
event_id | keyword | Unique event identifier. |
time / time_str | date (epoch ms) / date (ISO-8601) | When the interaction occurred, in both forms. |
session_id / message_id | keyword | Passed, with application_id, to the sessionConversation query. message_id pairs a Prompt event with its corresponding Detection and LLM Response events. |
invocation_id | keyword | Pairs the same set of events as message_id in a separate identifier namespace, and is not used by either content query. |
interaction_intent | keyword | The classified intent behind a Prompt, for example, getting information. |
interaction_topic / interaction_sub_topic | keyword | The classified subject, for example legal / data privacy. |
url / referer_url | keyword | Page URL and referring page URL, where applicable |
file_name | keyword | The name of the file transferred. Present only when app_activity_type is File Transaction. |
engagement_outcome_action | keyword | The action taken after the user responds to an engagement policy prompt. |
user_justification | keyword | The user’s response to the engagement policy prompt, |
event_count | integer | The number of occurrences the record represents. |
cato_app | keyword | The Cato application identifier for the GenAI application, for example chatgpt. |
Note: Not every event has retrievable content. session_id and message_id appear only in events where the app_activity_type is Prompt, Detection, or LLM Response. Web Request and File Transaction events do not carry them.
Application Runtime Protection Fields
Field | Description |
|---|---|
event_type / event_sub_type | Always AI Security / Application Runtime Protection for these events. Use these values to filter in your integration or on the Events page. |
event_id / event_count | Unique event identifier, and the number of occurrences the record represents. |
time / time_str | When the interaction was intercepted, as an epoch timestamp in milliseconds and an ISO-8601 UTC string. |
account_id / account_name | Cato account identifier and display name. account_id is the value passed as accountId to the API queries. |
guard_id / guard_name | The Guard that protected the application and produced the decision. |
rule_id / rule_name | The specific Guard policy rule that matched. |
action | The enforcement outcome, such as Anonymize, Block, or Monitor. |
detectors | The detectors that fired for this interaction, as an array — for example, a PII detector. |
application_id | The Homegrown Agent the Guard is protecting. |
invocation_id | The key to investigation. Identifies the specific interaction, and is the value passed to the invocation query to retrieve the prompt and response. |
session_id | Groups invocations that belong to the same conversation session. |
cato_app / is_cloud_app / is_sanctioned_app | Present on the event but not relevant to AI Security for Apps investigations. |
Terminology. What CMA refers to as a Homegrown Agent is referred to as an application in the event. The application_id field identifies the Homegrown Agent the Guard is protecting.
Sending Events to a SIEM
Event Integrations forward Cato event data automatically to external platforms and storage destinations, without manual export or continuous polling. Integrations are configured in Resources > Integrations > Configured Integrations in the CMA. For an overview, see Getting Started with Event Integrations.
If a native integration is not available, the Custom HTTP Push integration can be used to push events in JSON format to your destination of your choice. Custom headers can be configured, making it compatible with a wide variety of vendors. For more information, see Sending Data with the Custom HTTP Push Integration.
Filtering for AI Security events
Whichever integration you select, scope it to AI Security events rather than forwarding the account’s full event volume. This is done in the Events Filter, which is built from one or more filter groups: conditions within a group are combined with AND, and groups are combined with OR, so an event is forwarded if it matches any group. Any event field is available as a condition.
- Add a filter group to the Events Filter. In the integration configuration, open the Events Filter and add a filter group.
- Set the Event Type condition. Field Event Type, value AI Security. This scopes the group to AI Security events of all sub-types.

- (Optional) Set the Sub-Type condition. Field Sub-Type, with the values AI User Interaction and Application Runtime Protection, or only the one required by this integration. Because both conditions are in the same group, they are combined with AND, so only AI Security events of the selected sub-types are forwarded.

Filter applied with both Sub-Type AI User Interaction and Application Runtime Protection
- (Optional) Route the two sub-types separately. A single group carrying both values sends both sub-types to the same destination. To deliver them to different destinations, configure two Event Integrations, each with a group scoped to one sub-type.
- Narrow further, if required. Additional conditions can be added to the same group to reduce volume. For example, a Guard Name filter can be added to only forward Application Runtime Protection events that match a particular Guard.

Pulling Sensitive Content with the API
AI Security events deliberately exclude the content of the interaction: they do not contain the prompts, the model responses, or any of the raw message data exchanged with the model. That content is retrieved from Cato’s GraphQL API, on demand, and only by callers whose API key holds the required permission. Two queries are available, one per event sub-type.
API key and permissions
Queries are authenticated with a Cato API key generated in the CMA. For details on how to create an API key, see Generating API Keys for the Cato API.
Access to interaction content is controlled by RBAC permissions on the key:
Access | Permission |
|---|---|
Sensitive content on AI User Interactions | AI Security > AI Security for Users > Read Sensitive Content |
Sensitive content on Application Runtime Protection | AI Security > AI Security for Apps > Read Sensitive Content |
API endpoint and schema
The URL for the API endpoint and schema is specific to the location where your CMA instance is hosted. A <prefix> value may be appended to the URL for your CMA account, and to the API endpoint and schema.
Resource | URL format |
|---|---|
API endpoint | https://api.<prefix>.catonetworks.com/api/v1/graphql2 |
API schema | https://api.<prefix>.catonetworks.com/api/schema |
Prefixes for the different CMA regions
CMA region | CMA URL | Prefix | API endpoint |
Ireland | cc.catonetworks.com | None | https://api.catonetworks.com/api/v1/graphql2 |
US - Virginia | cc.us1.catonetworks.com | us1 | https://api.us1.catonetworks.com/api/v1/graphql2 |
India | cc.in1.catonetworks.com | in1 | https://api.in1.catonetworks.com/api/v1/graphql2 |
Japan | cc.jp1.catonetworks.com | jp1 | https://api.jp1.catonetworks.com/api/v1/graphql2 |
Identify the prefix from the URL of your CMA account and use the corresponding endpoint in every request. For more information, see What is the Cato API.
Running queries in the GraphQL Playground
The GraphQL Playground runs queries against the Cato API directly from a browser, which is useful for ad-hoc investigation and for confirming connectivity before scripting a query. See Connecting to the Cato API from the GraphQL Playground for instructions.
AI User Interaction
Retrieve the user prompt and the model response behind an AI User Interaction event. The same conversations are available in CMA under AI Security for Users > Session Explorer.
AI User Interactions that match detectors configured in policy contain Detection in the app_activity_type field. These events are most relevant for security investigations.
Request fields
Variable | Type | Source |
|---|---|---|
accountId | ID! | The event’s account_id. |
sessionId | ID! | The event’s session_id. |
messageId | ID! | The event’s message_id. Identifies the individual prompt within the session. |
appId | ID! | The event’s application_id. |
userId | ID | The event’s user_id. Optional. |
GraphQL
query SessionConversation(
$accountId: ID!
$sessionId: ID!
$messageId: ID!
$appId: ID!
) {
aiSecurity(accountId: $accountId) {
endUsers {
sessionConversation(
input: { sessionId: $sessionId, messageId: $messageId, appId: $appId }
) {
userPrompt
llmResponse
}
}
}
}
Variables:
{
"accountId": "<ACCOUNT_ID>",
"sessionId": "<session_id from the event>",
"messageId": "<message_id from the event>",
"appId": "<application_id from the event>"
}
Curl
curl -s -X POST https://api.<prefix>.catonetworks.com/api/v1/graphql2 \
-H "x-api-key: $CATO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"query": "query SessionConversation($accountId: ID!, $sessionId: ID!, $messageId: ID!, $appId: ID!) { aiSecurity(accountId: $accountId) { endUsers { sessionConversation(input: {sessionId: $sessionId, messageId: $messageId, appId: $appId}) { userPrompt llmResponse } } } }",
"variables": {
"accountId": "<ACCOUNT_ID>",
"sessionId": "<session_id from the event>",
"messageId": "<message_id from the event>",
"appId": "<application_id from the event>"
}
}' | jq .
Python
import json, requests
API_KEY = "<API_KEY>"
QUERY = """
query SessionConversation($accountId: ID!, $sessionId: ID!, $messageId: ID!, $appId: ID!) {
aiSecurity(accountId: $accountId) {
endUsers {
sessionConversation(input: {sessionId: $sessionId, messageId: $messageId, appId: $appId}) {
userPrompt
llmResponse
}
}
}
}
"""
resp = requests.post(
"https://api.<prefix>.catonetworks.com/api/v1/graphql2",
headers={"x-api-key": API_KEY},
json={"query": QUERY, "variables": {
"accountId": "<ACCOUNT_ID>",
"sessionId": "<Session ID from event>",
"messageId": "<Message ID from event>",
"appId": "<application_id from event>",
}},
timeout=30,
)
print(json.dumps(resp.json(), indent=2))
Response fields
Path | Type | Description |
|---|---|---|
userPrompt | String | The text the user sent to the GenAI application. |
llmResponse | String | The application’s response text. |
Example Response
{
"data": {
"aiSecurity": {
"endUsers": {
"sessionConversation": {
"userPrompt": "<user prompt>",
"llmResponse": “<llm response or null>”
}
}
}
}
}
Application Runtime Protection
Retrieve the invocation metadata and the raw chat messages behind an Application Runtime Protection event. The same invocations are available in CMA under AI Security for Apps > Interaction Explorer.
Request fields
Variable | Type | Source |
|---|---|---|
accountId | ID! | The event’s account_id. |
id | ID! | The event’s invocation_id. Identifies the specific interaction. |
GraphQL
query GetInvocation($accountId: ID!, $id: ID!) {
aiSecurity(accountId: $accountId) {
apps {
invocation(input: { id: $id }) {
id
sessionId
timestamp
tokenCount
guard {
id
name
}
action
data {
message {
role
content {
text
}
}
}
}
}
}
}
Variables:
{
"accountId": "<ACCOUNT_ID>",
"id": "<invocation_id from the event>"
}
Curl
curl -s -X POST https://api.<prefix>.catonetworks.com/api/v1/graphql2 \
-H "x-api-key: <CATO_API_KEY>” \
-H "Content-Type: application/json" \
-d '{
"query": "query GetInvocation($accountId: ID!, $id: ID!) { aiSecurity(accountId: $accountId) { apps { invocation(input: {id: $id}) { id sessionId timestamp tokenCount guard { id name } action data { message { role content { text } } } } } } }",
"variables": {
"accountId": "<ACCOUNT_ID>",
"id": "<invocation_id from the event>"
}
}' | jq .
Python
import json, requests
API_KEY = "<CATO_API_KEY>"
QUERY = """
query GetInvocation($accountId: ID!, $id: ID!) {
aiSecurity(accountId: $accountId) {
apps {
invocation(input: {id: $id}) {
id
sessionId
timestamp
tokenCount
guard { id name }
action
data { message { role content { text } } }
}
}
}
}
"""
resp = requests.post(
"https://api.<prefix>.catonetworks.com/api/v1/graphql2",
headers={"x-api-key": API_KEY},
json={"query": QUERY, "variables": {
"accountId": "<ACCOUNT_ID>",
"id": "<invocation_id from the event>",
}},
timeout=30,
)
print(json.dumps(resp.json(), indent=2))
Response fields
Path | Type | Description |
|---|---|---|
invocation.id | ID! | Globally unique invocation ID. |
.sessionId | ID | Groups invocations from the same conversation session. null if not tracked. |
.timestamp | DateTime! | UTC time the invocation was intercepted. |
.tokenCount | Int! | Total tokens for the invocation (prompt and completion). |
.guard.id / .guard.name | ID! / String! | The Guard that received the invocation. The guard object may be null if the invocation is not associated with a Guard. |
.action | Enum! | Enforcement outcome as an uppercase API value: BLOCK, ANONYMIZE, MONITOR, or NONE. Events present these values with different capitalization, for example Anonymize. |
.data.message[] | [InvocationMessage!]! | The raw chat messages. Each has a role (USER, ASSISTANT, TOOL_CALL, TOOL_MESSAGE, or a custom role) and content[] (each with a text field). This is the sensitive data gated behind the Read Sensitive Content permission. |
Example Response
{
"data": {
"aiSecurity": {
"apps": {
"invocation": {
"id": "01a00ada-c424-700b-9898-ed1ea05a82fb",
"sessionId": "8cf9384d-9a45-4d01-aeff-c3eb31164599",
"timestamp": "2026-08-16T13:55:04.392Z",
"tokenCount": 30,
"guard": {
"id": "d3918cad-ffab-408d-b079-bfecd4842ed1",
"name": "<guard_name>"
},
"action": "BLOCK",
"data": {
"message": [
{
"role": "user",
"content": [
{
"text": "<user prompt>”
}
]
}
]
}
}
}
}
}
}
Appendix: Sample Events and API Calls
Sample events and the API calls that retrieve their content, for both event sub-types.
AI Security for Users
Sample Events
[
{
"account_id": <account_id>,
"account_name": "<account_name>",
"ad_name": "<ad_name>",
"ai_app_risk_level": "Medium",
"app_activity_type": "Prompt",
"application_id": "microsoft_copilot",
"application_name": "Microsoft Copilot",
"application_risk": 5,
"application_type": "System",
"categories": [
"Generative AI Tools"
],
"cato_app": "microsoft_copilot",
"event_count": 1,
"event_id": "7c41ae90b2d5f318",
"event_sub_type": "AI User Interaction",
"event_type": "AI Security",
"interaction_intent": "getting information",
"interaction_sub_topic": "data privacy",
"interaction_topic": "legal",
"invocation_id": "01a01f70-9b12-74ac-8f31-2b6ce0d41aa7",
"is_cloud_app": true,
"is_sanctioned_app": true,
"message_id": "6f2b1c48-55d7-4a9e-9c10-8ab3f7e2d114",
"session_id": "b71f9c02-3ad4-4e8b-90c6-1f5d8e7a4c33",
"time": 1787233820104,
"time_str": "2026-08-20T13:50:20Z",
"url": "https://copilot.microsoft.com/chats",
"user_id": <user_id>,
"user_name": "<user_name>",
"vpn_user_email": "<user_email>"
},
{
"account_id": <account_id>,
"account_name": "<account_name>",
"app_activity_type": "Detection",
"application_id": "microsoft_copilot",
"application_name": "Microsoft Copilot",
"event_count": 1,
"event_id": "b0d3572ea9146fc7",
"event_sub_type": "AI User Interaction",
"event_type": "AI Security",
"invocation_id": "01a01f70-9b12-74ac-8f31-2b6ce0d41aa7",
"message_id": "6f2b1c48-55d7-4a9e-9c10-8ab3f7e2d114",
"rule_id": "1296751412582697861",
"rule_name": "<rule_name>",
"session_id": "b71f9c02-3ad4-4e8b-90c6-1f5d8e7a4c33",
"time": 1787233820331,
"time_str": "2026-08-20T13:50:20Z",
"user_id": <user_id>,
"user_name": "<user_name>",
"vpn_user_email": "<user_email>"
}
]
API Call
curl -s -X POST https://api.catonetworks.com/api/v1/graphql2 \
-H "x-api-key: <api_key>" \
-H "Content-Type: application/json" \
-d '{
"query": "query SessionConversation($accountId: ID!, $sessionId: ID!, $messageId: ID!, $appId: ID!) { aiSecurity(accountId: $accountId) { endUsers { sessionConversation(input: {sessionId: $sessionId, messageId: $messageId, appId: $appId}) { userPrompt llmResponse } } } }",
"variables": {
"accountId": "<account_id>",
"sessionId": "b71f9c02-3ad4-4e8b-90c6-1f5d8e7a4c33",
"messageId": "6f2b1c48-55d7-4a9e-9c10-8ab3f7e2d114",
"appId": "microsoft_copilot"
}
}' | jq .
API Response
{
"data": {
"aiSecurity": {
"endUsers": {
"sessionConversation": {
"userPrompt": "<user_prompt>",
"llmResponse": "<llm_response>"
}
}
}
}
}
AI Security for Apps
Sample Events
[
{
"account_id": <account_id>,
"account_name": "<account_name>",
"action": "Block",
"detectors": [
"SIMPLE_DETECTOR_TYPE_SAFETY_CONTROLS_SAFETY"
],
"event_count": 1,
"event_id": "f98820262dfb8aa9",
"event_sub_type": "Application Runtime Protection",
"event_type": "AI Security",
"guard_id": "d3918cad-ffab-408d-b079-bfecd4842ed1",
"guard_name": "<guard_name>",
"interaction_id": "01a01f71-c3e5-75be-a3cc-d77ec3b9277f",
"internalId": "f98820262dfb8aa9",
"internal_id": "f98820262dfb8aa9",
"invocation_id": "01a01f71-c3e5-75be-a3cc-d77ec3b9277f",
"is_sanctioned_app": false,
"rule_id": "1296751412582697861",
"rule_name": "<rule_name>",
"session_id": "d500d5a4-82cd-4f48-8d70-0ebfc590d605",
"time": 1787233944579,
"time_str": "2026-08-20T13:52:24Z"
},
{
"account_id": <account_id>,
"account_name": "<account_name>",
"action": "Block",
"detectors": [
"SIMPLE_DETECTOR_TYPE_SECURITY_CONTROLS_JAILBREAK",
"SIMPLE_DETECTOR_TYPE_SAFETY_CONTROLS_SAFETY"
],
"event_count": 1,
"event_id": "31156257bcf2d54c",
"event_sub_type": "Application Runtime Protection",
"event_type": "AI Security",
"guard_id": "d3918cad-ffab-408d-b079-bfecd4842ed1",
"guard_name": "<guard_name>",
"interaction_id": "01a01f72-38ce-782f-96c5-5ca071ac9792",
"internalId": "31156257bcf2d54c",
"internal_id": "31156257bcf2d54c",
"invocation_id": "01a01f72-38ce-782f-96c5-5ca071ac9792",
"is_sanctioned_app": false,
"rule_id": "1296751412582697861",
"rule_name": "<rule_name>",
"session_id": "d500d5a4-82cd-4f48-8d70-0ebfc590d605",
"time": 1787233974486,
"time_str": "2026-08-20T13:52:54Z"
}
]
API Call
curl -s -X POST https://api.catonetworks.com/api/v1/graphql2 \
-H "x-api-key: <api_key>" \
-H "Content-Type: application/json" \
-d '{
"query": "query GetInvocation($accountId: ID!, $id: ID!) { aiSecurity(accountId: $accountId) { apps { invocation(input: {id: $id}) { id sessionId timestamp tokenCount guard { id name } action data { message { role content { text } } } } } } }",
"variables": {
"accountId": "<account_id>",
"id": "01a01f72-38ce-782f-96c5-5ca071ac9792"
}
}' | jq .
API Response
{
"data": {
"aiSecurity": {
"apps": {
"invocation": {
"id": "01a01f72-38ce-782f-96c5-5ca071ac9792",
"sessionId": "d500d5a4-82cd-4f48-8d70-0ebfc590d605",
"timestamp": "2026-08-20T13:52:54.486Z",
"tokenCount": 38,
"guard": {
"id": "d3918cad-ffab-408d-b079-bfecd4842ed1",
"name": "<guard_name>"
},
"action": "BLOCK",
"data": {
"message": [
{
"role": "user",
"content": [
{
"text": "<user_prompt>"
}
]
}
]
}
}
}
}
}
}