AI Security Operation Guide

Prev Next

AI Security Operation Guide

Overview

Cato AI Security logs user activity with GenAI applications and the invocations your Homegrown Agents send to the models they call. Events are visible in the Cato Management Application (CMA) on the Home > Events page, and can be forwarded to a SIEM, data lake, or other external platform for retention, correlation, and alerting.

Events carry metadata only. The prompts and responses exchanged with the model are not stored in the event. That content is retrieved separately, on demand, from Cato's GraphQL API by a caller whose API key holds the required permission.

Investigating an AI Security finding is therefore a two-step workflow:

  1. Forward events to your SIEM. Configure an Event Integration, filtered to the AI Security event type, so that AI Security events arrive alongside the rest of your Cato telemetry.
  2. Use the API to pull the sensitive content for the events that warrant it. When an event requires investigation, query the API with the identifiers carried on that event to retrieve the prompt and the model response.

Note: AI Security interactions, including sensitive prompts and responses, can be reviewed directly in CMA without using the API. AI Security for Apps > Interaction Explorer lists the invocations for your Homegrown Agents, and AI Security for Users > Session Explorer lists user sessions with GenAI applications. Both allow you to drill into an individual record. The API is intended for investigations that begin in your SIEM, and for programmatic retrieval.

Cato Events

All AI Security events carry the Event Type AI Security. The event sub-type identifies which part of AI Security generated the event, and determines which fields the event carries and which API query returns its content. An interactive event schema exporer is available at Cato Event Schema.

CMA module

Event sub-type

Description

AI Security for Users

AI User Interaction

Generated by user activity with GenAI applications.

AI Security for Applications

Application Runtime Protection

Generated when a Guard policy protecting one of your Homegrown Agents takes action on an interaction.

AI User Interaction Fields

Field

Type

Description

account_id / account_name

long / keyword

Cato account identifier and display name.

ad_name / user_id / user_name

keyword / long / keyword

The Cato user, and their Active Directory display name.

vpn_user_email

keyword

The user’s email address. This is the field to filter on when an investigation begins from an email address.

application_id / application_name

keyword

The GenAI application, for example microsoft_copilot / Microsoft Copilot.

application_type / categories

keyword

Application classification, for example type System and category Generative AI Tools.

ai_app_risk_level / application_risk

keyword / integer

Cato’s risk rating for the application, as a label and as a numeric score.

is_cloud_app / is_sanctioned_app

boolean

Whether the application is cloud-hosted, and whether it is sanctioned for the account.

app_activity_type

keyword

The activity the event represents. Possible values: Web Request, Prompt, Detection, LLM Response, File Transaction, Engagement Response.

rule_id / rule_name

keyword

The policy rule that matched, where one fired. Independent of app_activity_type and not exclusive to any one value.

event_id

keyword

Unique event identifier.

time / time_str

date (epoch ms) / date (ISO-8601)

When the interaction occurred, in both forms.

session_id / message_id

keyword

Passed, with application_id, to the sessionConversation query. message_id pairs a Prompt event with its corresponding Detection and LLM Response events.

invocation_id

keyword

Pairs the same set of events as message_id in a separate identifier namespace, and is not used by either content query.

interaction_intent

keyword

The classified intent behind a Prompt, for example, getting information.

interaction_topic / interaction_sub_topic

keyword

The classified subject, for example legal / data privacy.

url / referer_url

keyword

Page URL and referring page URL, where applicable

file_name

keyword

The name of the file transferred. Present only when app_activity_type is File Transaction.

engagement_outcome_action

keyword

The action taken after the user responds to an engagement policy prompt.

user_justification

keyword

The user’s response to the engagement policy prompt,

event_count

integer

The number of occurrences the record represents.

cato_app

keyword

The Cato application identifier for the GenAI application, for example chatgpt.

Note: Not every event has retrievable content. session_id and message_id appear only in events where the app_activity_type is Prompt, Detection, or LLM Response. Web Request and File Transaction events do not carry them.

Application Runtime Protection Fields

Field

Description

event_type / event_sub_type

Always AI Security / Application Runtime Protection for these events. Use these values to filter in your integration or on the Events page.

event_id / event_count

Unique event identifier, and the number of occurrences the record represents.

time / time_str

When the interaction was intercepted, as an epoch timestamp in milliseconds and an ISO-8601 UTC string.

account_id / account_name

Cato account identifier and display name. account_id is the value passed as accountId to the API queries.

guard_id / guard_name

The Guard that protected the application and produced the decision.

rule_id / rule_name

The specific Guard policy rule that matched.

action

The enforcement outcome, such as Anonymize, Block, or Monitor.

detectors

The detectors that fired for this interaction, as an array — for example, a PII detector.

application_id

The Homegrown Agent the Guard is protecting.

invocation_id

The key to investigation. Identifies the specific interaction, and is the value passed to the invocation query to retrieve the prompt and response.

session_id

Groups invocations that belong to the same conversation session.

cato_app / is_cloud_app / is_sanctioned_app

Present on the event but not relevant to AI Security for Apps investigations.

Terminology. What CMA refers to as a Homegrown Agent is referred to as an application in the event. The application_id field identifies the Homegrown Agent the Guard is protecting.

Sending Events to a SIEM

Event Integrations forward Cato event data automatically to external platforms and storage destinations, without manual export or continuous polling. Integrations are configured in Resources > Integrations > Configured Integrations in the CMA. For an overview, see Getting Started with Event Integrations.

If a native integration is not available, the Custom HTTP Push integration can be used to push events in JSON format to your destination of your choice. Custom headers can be configured, making it compatible with a wide variety of vendors. For more information, see Sending Data with the Custom HTTP Push Integration.

Filtering for AI Security events

Whichever integration you select, scope it to AI Security events rather than forwarding the account’s full event volume. This is done in the Events Filter, which is built from one or more filter groups: conditions within a group are combined with AND, and groups are combined with OR, so an event is forwarded if it matches any group. Any event field is available as a condition.

  1. Add a filter group to the Events Filter. In the integration configuration, open the Events Filter and add a filter group.
  2. Set the Event Type condition. Field Event Type, value AI Security. This scopes the group to AI Security events of all sub-types.

  3. (Optional) Set the Sub-Type condition. Field Sub-Type, with the values AI User Interaction and Application Runtime Protection, or only the one required by this integration. Because both conditions are in the same group, they are combined with AND, so only AI Security events of the selected sub-types are forwarded.

Filter applied with both Sub-Type AI User Interaction and Application Runtime Protection

  1. (Optional) Route the two sub-types separately. A single group carrying both values sends both sub-types to the same destination. To deliver them to different destinations, configure two Event Integrations, each with a group scoped to one sub-type.
  2. Narrow further, if required. Additional conditions can be added to the same group to reduce volume. For example, a Guard Name filter can be added to only forward Application Runtime Protection events that match a particular Guard.

Pulling Sensitive Content with the API

AI Security events deliberately exclude the content of the interaction: they do not contain the prompts, the model responses, or any of the raw message data exchanged with the model. That content is retrieved from Cato’s GraphQL API, on demand, and only by callers whose API key holds the required permission. Two queries are available, one per event sub-type.

API key and permissions

Queries are authenticated with a Cato API key generated in the CMA. For details on how to create an API key, see Generating API Keys for the Cato API.

Access to interaction content is controlled by RBAC permissions on the key:

Access

Permission

Sensitive content on AI User Interactions

AI Security > AI Security for Users > Read Sensitive Content

Sensitive content on Application Runtime Protection

AI Security > AI Security for Apps > Read Sensitive Content

API endpoint and schema

The URL for the API endpoint and schema is specific to the location where your CMA instance is hosted. A <prefix> value may be appended to the URL for your CMA account, and to the API endpoint and schema.

Resource

URL format

API endpoint

https://api.<prefix>.catonetworks.com/api/v1/graphql2

API schema

https://api.<prefix>.catonetworks.com/api/schema

Prefixes for the different CMA regions

CMA region

CMA URL

Prefix

API endpoint

Ireland

cc.catonetworks.com

None

https://api.catonetworks.com/api/v1/graphql2

US - Virginia

cc.us1.catonetworks.com

us1

https://api.us1.catonetworks.com/api/v1/graphql2

India

cc.in1.catonetworks.com

in1

https://api.in1.catonetworks.com/api/v1/graphql2

Japan

cc.jp1.catonetworks.com

jp1

https://api.jp1.catonetworks.com/api/v1/graphql2

Identify the prefix from the URL of your CMA account and use the corresponding endpoint in every request. For more information, see What is the Cato API.

Running queries in the GraphQL Playground

The GraphQL Playground runs queries against the Cato API directly from a browser, which is useful for ad-hoc investigation and for confirming connectivity before scripting a query. See Connecting to the Cato API from the GraphQL Playground for instructions.

AI User Interaction

Retrieve the user prompt and the model response behind an AI User Interaction event. The same conversations are available in CMA under AI Security for Users > Session Explorer.

AI User Interactions that match detectors configured in policy contain Detection in the app_activity_type field. These events are most relevant for security investigations.

Request fields

Variable

Type

Source

accountId

ID!

The event’s account_id.

sessionId

ID!

The event’s session_id.

messageId

ID!

The event’s message_id. Identifies the individual prompt within the session.

appId

ID!

The event’s application_id.

userId

ID

The event’s user_id. Optional.

GraphQL

query SessionConversation(
 $accountId: ID!
 $sessionId: ID!
 $messageId: ID!
 $appId: ID!
) {
 aiSecurity(accountId: $accountId) {
   endUsers {
     sessionConversation(
       input: { sessionId: $sessionId, messageId: $messageId, appId: $appId }
     ) {
       userPrompt
       llmResponse
     }
   }
 }
}

Variables:

{
 "accountId": "<ACCOUNT_ID>",
 "sessionId": "<session_id from the event>",
 "messageId": "<message_id from the event>",
 "appId": "<application_id from the event>"
}

Curl

curl -s -X POST https://api.<prefix>.catonetworks.com/api/v1/graphql2 \
 -H "x-api-key: $CATO_API_KEY" \
 -H "Content-Type: application/json" \
 -d '{
   "query": "query SessionConversation($accountId: ID!, $sessionId: ID!, $messageId: ID!, $appId: ID!) { aiSecurity(accountId: $accountId) { endUsers { sessionConversation(input: {sessionId: $sessionId, messageId: $messageId, appId: $appId}) { userPrompt llmResponse } } } }",
   "variables": {
     "accountId": "<ACCOUNT_ID>",
     "sessionId": "<session_id from the event>",
     "messageId": "<message_id from the event>",
     "appId": "<application_id from the event>"
   }
 }' | jq .

Python

import json, requests

API_KEY = "<API_KEY>"

QUERY = """
query SessionConversation($accountId: ID!, $sessionId: ID!, $messageId: ID!, $appId: ID!) {
 aiSecurity(accountId: $accountId) {
   endUsers {
     sessionConversation(input: {sessionId: $sessionId, messageId: $messageId, appId: $appId}) {
       userPrompt
       llmResponse
     }
   }
 }
}
"""
resp = requests.post(
   "https://api.<prefix>.catonetworks.com/api/v1/graphql2",
   headers={"x-api-key": API_KEY},
   json={"query": QUERY, "variables": {
       "accountId": "<ACCOUNT_ID>",
       "sessionId": "<Session ID from event>",
       "messageId": "<Message ID from event>",
       "appId": "<application_id from event>",
   }},
   timeout=30,
)
print(json.dumps(resp.json(), indent=2))

Response fields

Path

Type

Description

userPrompt

String

The text the user sent to the GenAI application.

llmResponse

String

The application’s response text.

Example Response

{
 "data": {
   "aiSecurity": {
     "endUsers": {
       "sessionConversation": {
         "userPrompt": "<user prompt>",
         "llmResponse": “<llm response or null>”
       }
     }
   }
 }
}

Application Runtime Protection

Retrieve the invocation metadata and the raw chat messages behind an Application Runtime Protection event. The same invocations are available in CMA under AI Security for Apps > Interaction Explorer.

Request fields

Variable

Type

Source

accountId

ID!

The event’s account_id.

id

ID!

The event’s invocation_id. Identifies the specific interaction.

GraphQL

query GetInvocation($accountId: ID!, $id: ID!) {
 aiSecurity(accountId: $accountId) {
   apps {
     invocation(input: { id: $id }) {
       id
       sessionId
       timestamp
       tokenCount
       guard {
         id
         name
       }
       action
       data {
         message {
           role
           content {
             text
           }
         }
       }
     }
   }
 }
}

Variables:

{
 "accountId": "<ACCOUNT_ID>",
 "id": "<invocation_id from the event>"
}

Curl

curl -s -X POST https://api.<prefix>.catonetworks.com/api/v1/graphql2 \
 -H "x-api-key: <CATO_API_KEY>” \
 -H "Content-Type: application/json" \
 -d '{
   "query": "query GetInvocation($accountId: ID!, $id: ID!) { aiSecurity(accountId: $accountId) { apps { invocation(input: {id: $id}) { id sessionId timestamp tokenCount guard { id name } action data { message { role content { text } } } } } } }",
   "variables": {
     "accountId": "<ACCOUNT_ID>",
     "id": "<invocation_id from the event>"
   }
 }' | jq .

Python

import json, requests

API_KEY = "<CATO_API_KEY>"

QUERY = """
query GetInvocation($accountId: ID!, $id: ID!) {
 aiSecurity(accountId: $accountId) {
   apps {
     invocation(input: {id: $id}) {
       id
       sessionId
       timestamp
       tokenCount
       guard { id name }
       action
       data { message { role content { text } } }
     }
   }
 }
}
"""
resp = requests.post(
   "https://api.<prefix>.catonetworks.com/api/v1/graphql2",
   headers={"x-api-key": API_KEY},
   json={"query": QUERY, "variables": {
       "accountId": "<ACCOUNT_ID>",
       "id": "<invocation_id from the event>",
   }},
   timeout=30,
)
print(json.dumps(resp.json(), indent=2))

Response fields

Path

Type

Description

invocation.id

ID!

Globally unique invocation ID.

.sessionId

ID

Groups invocations from the same conversation session. null if not tracked.

.timestamp

DateTime!

UTC time the invocation was intercepted.

.tokenCount

Int!

Total tokens for the invocation (prompt and completion).

.guard.id / .guard.name

ID! / String!

The Guard that received the invocation. The guard object may be null if the invocation is not associated with a Guard.

.action

Enum!

Enforcement outcome as an uppercase API value: BLOCK, ANONYMIZE, MONITOR, or NONE. Events present these values with different capitalization, for example Anonymize.

.data.message[]

[InvocationMessage!]!

The raw chat messages. Each has a role (USER, ASSISTANT, TOOL_CALL, TOOL_MESSAGE, or a custom role) and content[] (each with a text field). This is the sensitive data gated behind the Read Sensitive Content permission.

Example Response

{
 "data": {
   "aiSecurity": {
     "apps": {
       "invocation": {
         "id": "01a00ada-c424-700b-9898-ed1ea05a82fb",
         "sessionId": "8cf9384d-9a45-4d01-aeff-c3eb31164599",
         "timestamp": "2026-08-16T13:55:04.392Z",
         "tokenCount": 30,
         "guard": {
           "id": "d3918cad-ffab-408d-b079-bfecd4842ed1",
           "name": "<guard_name>"
         },
         "action": "BLOCK",
         "data": {
           "message": [
             {
               "role": "user",
               "content": [
                 {
                   "text": "<user prompt>”
                 }
               ]
             }
           ]
         }
       }
     }
   }
 }
}

Appendix: Sample Events and API Calls

Sample events and the API calls that retrieve their content, for both event sub-types.

AI Security for Users

Sample Events

[
 {
   "account_id": <account_id>,
   "account_name": "<account_name>",
   "ad_name": "<ad_name>",
   "ai_app_risk_level": "Medium",
   "app_activity_type": "Prompt",
   "application_id": "microsoft_copilot",
   "application_name": "Microsoft Copilot",
   "application_risk": 5,
   "application_type": "System",
   "categories": [
     "Generative AI Tools"
   ],
   "cato_app": "microsoft_copilot",
   "event_count": 1,
   "event_id": "7c41ae90b2d5f318",
   "event_sub_type": "AI User Interaction",
   "event_type": "AI Security",
   "interaction_intent": "getting information",
   "interaction_sub_topic": "data privacy",
   "interaction_topic": "legal",
   "invocation_id": "01a01f70-9b12-74ac-8f31-2b6ce0d41aa7",
   "is_cloud_app": true,
   "is_sanctioned_app": true,
   "message_id": "6f2b1c48-55d7-4a9e-9c10-8ab3f7e2d114",
   "session_id": "b71f9c02-3ad4-4e8b-90c6-1f5d8e7a4c33",
   "time": 1787233820104,
   "time_str": "2026-08-20T13:50:20Z",
   "url": "https://copilot.microsoft.com/chats",
   "user_id": <user_id>,
   "user_name": "<user_name>",
   "vpn_user_email": "<user_email>"
 },
 {
   "account_id": <account_id>,
   "account_name": "<account_name>",
   "app_activity_type": "Detection",
   "application_id": "microsoft_copilot",
   "application_name": "Microsoft Copilot",
   "event_count": 1,
   "event_id": "b0d3572ea9146fc7",
   "event_sub_type": "AI User Interaction",
   "event_type": "AI Security",
   "invocation_id": "01a01f70-9b12-74ac-8f31-2b6ce0d41aa7",
   "message_id": "6f2b1c48-55d7-4a9e-9c10-8ab3f7e2d114",
   "rule_id": "1296751412582697861",
   "rule_name": "<rule_name>",
   "session_id": "b71f9c02-3ad4-4e8b-90c6-1f5d8e7a4c33",
   "time": 1787233820331,
   "time_str": "2026-08-20T13:50:20Z",
   "user_id": <user_id>,
   "user_name": "<user_name>",
   "vpn_user_email": "<user_email>"
 }
]

API Call

curl -s -X POST https://api.catonetworks.com/api/v1/graphql2 \
 -H "x-api-key: <api_key>" \
 -H "Content-Type: application/json" \
 -d '{
   "query": "query SessionConversation($accountId: ID!, $sessionId: ID!, $messageId: ID!, $appId: ID!) { aiSecurity(accountId: $accountId) { endUsers { sessionConversation(input: {sessionId: $sessionId, messageId: $messageId, appId: $appId}) { userPrompt llmResponse } } } }",
   "variables": {
     "accountId": "<account_id>",
     "sessionId": "b71f9c02-3ad4-4e8b-90c6-1f5d8e7a4c33",
     "messageId": "6f2b1c48-55d7-4a9e-9c10-8ab3f7e2d114",
     "appId": "microsoft_copilot"
   }
 }' | jq .

API Response

{
 "data": {
   "aiSecurity": {
     "endUsers": {
       "sessionConversation": {
         "userPrompt": "<user_prompt>",
         "llmResponse": "<llm_response>"
       }
     }
   }
 }
}

AI Security for Apps

Sample Events

[
 {
   "account_id": <account_id>,
   "account_name": "<account_name>",
   "action": "Block",
   "detectors": [
     "SIMPLE_DETECTOR_TYPE_SAFETY_CONTROLS_SAFETY"
   ],
   "event_count": 1,
   "event_id": "f98820262dfb8aa9",
   "event_sub_type": "Application Runtime Protection",
   "event_type": "AI Security",
   "guard_id": "d3918cad-ffab-408d-b079-bfecd4842ed1",
   "guard_name": "<guard_name>",
   "interaction_id": "01a01f71-c3e5-75be-a3cc-d77ec3b9277f",
   "internalId": "f98820262dfb8aa9",
   "internal_id": "f98820262dfb8aa9",
   "invocation_id": "01a01f71-c3e5-75be-a3cc-d77ec3b9277f",
   "is_sanctioned_app": false,
   "rule_id": "1296751412582697861",
   "rule_name": "<rule_name>",
   "session_id": "d500d5a4-82cd-4f48-8d70-0ebfc590d605",
   "time": 1787233944579,
   "time_str": "2026-08-20T13:52:24Z"
 },
 {
   "account_id": <account_id>,
   "account_name": "<account_name>",
   "action": "Block",
   "detectors": [
     "SIMPLE_DETECTOR_TYPE_SECURITY_CONTROLS_JAILBREAK",
     "SIMPLE_DETECTOR_TYPE_SAFETY_CONTROLS_SAFETY"
   ],
   "event_count": 1,
   "event_id": "31156257bcf2d54c",
   "event_sub_type": "Application Runtime Protection",
   "event_type": "AI Security",
   "guard_id": "d3918cad-ffab-408d-b079-bfecd4842ed1",
   "guard_name": "<guard_name>",
   "interaction_id": "01a01f72-38ce-782f-96c5-5ca071ac9792",
   "internalId": "31156257bcf2d54c",
   "internal_id": "31156257bcf2d54c",
   "invocation_id": "01a01f72-38ce-782f-96c5-5ca071ac9792",
   "is_sanctioned_app": false,
   "rule_id": "1296751412582697861",
   "rule_name": "<rule_name>",
   "session_id": "d500d5a4-82cd-4f48-8d70-0ebfc590d605",
   "time": 1787233974486,
   "time_str": "2026-08-20T13:52:54Z"
 }
]

API Call

curl -s -X POST https://api.catonetworks.com/api/v1/graphql2 \
 -H "x-api-key: <api_key>" \
 -H "Content-Type: application/json" \
 -d '{
   "query": "query GetInvocation($accountId: ID!, $id: ID!) { aiSecurity(accountId: $accountId) { apps { invocation(input: {id: $id}) { id sessionId timestamp tokenCount guard { id name } action data { message { role content { text } } } } } } }",
   "variables": {
     "accountId": "<account_id>",
     "id": "01a01f72-38ce-782f-96c5-5ca071ac9792"
   }
 }' | jq .

API Response

{
 "data": {
   "aiSecurity": {
     "apps": {
       "invocation": {
         "id": "01a01f72-38ce-782f-96c5-5ca071ac9792",
         "sessionId": "d500d5a4-82cd-4f48-8d70-0ebfc590d605",
         "timestamp": "2026-08-20T13:52:54.486Z",
         "tokenCount": 38,
         "guard": {
           "id": "d3918cad-ffab-408d-b079-bfecd4842ed1",
           "name": "<guard_name>"
         },
         "action": "BLOCK",
         "data": {
           "message": [
             {
               "role": "user",
               "content": [
                 {
                   "text": "<user_prompt>"
                 }
               ]
             }
           ]
         }
       }
     }
   }
 }
}