Intent Drift

Detect when agents drift from purpose.

Compare each agent's observed behavior with its established purpose and baseline.

Intent Drift

Runtime evidence chain

The observed path behind this activity

Live

Agent

payments-agent

Known

API

billing.internal

Expected

Model

approved-model

Expected

Database

!

payroll-db

First seen

Egress

!

new-destination

First seen

!

Material intent drift

A new sensitive datasource and a first-seen destination appeared in the same runtime window.

Monitoring liveData refreshed 30s ago

A baseline you can explain

Keep the observations behind every agent baseline.

Establish

Learn the agent's normal destinations, dependencies, data systems, APIs, models, files, commands, identities, and activity shape.

Compare

Evaluate new behavior against the baseline and the agent's recorded purpose without inferring intent from its name.

Explain

Show the changed behavior, affected systems, materiality signals, and supporting records together in the finding.

PURPOSE IN RUNTIME

Authorized does not mean appropriate.

Judge whether access still serves the agent's established purpose.

Runtime context

Observed evidence chain

Live
Actor
Agent
Tool
Data

Agent or service scoped

Provider logs, application telemetry, and runtime signals

Environment-specific behavior kept separate

01 / AGENT BASELINE

Baseline each agent separately

A baseline belongs to a logical agent or service, not an infrastructure primitive. Vertex AI, Bedrock, and Databricks logs can contribute alongside application telemetry and runtime signals.

Runtime comparison

Expected and observed behavior

REVIEW

Expected

New tools, models, endpoints, identities, and data systems

Observed

Changes in frequency, volume, and access shape
Sensitivity, authority, and outcome used to rank risk
Difference retained with the supporting runtime records

02 / MATERIAL CHANGE

Detect shifts, not just new values

Aurva considers both new values and changes in the distribution or volume of known behavior. A familiar API used at an unfamiliar scale can matter as much as a new destination.

Reviewable finding

Runtime evidence · high confidence

HIGH
01

Expected and observed behavior side by side

02

Affected agents, data systems, and destinations

03

Evidence retained for investigation and audit

Review evidenceRecommended action

03 / REVIEWABLE FINDING

Show exactly what changed

Every finding states the expected behavior, the observed change, why it is risky, and the records that support it. Reviewers can distinguish a legitimate product change from an agent acting outside its purpose.

RUNTIME SIGNALS

Nine signals. One agent baseline.

Track coverage across provider logs, application telemetry, and runtime signals.

01

External destinations

Hosts, IP addresses, ports, and first-time egress.

02

Internal dependencies

Services and protocols reached inside the environment.

03

Database access

Database systems, services, connection patterns, and data volume.

04

API behavior

Methods and normalized routes without variable identifiers.

05

AI usage

Providers, models, operations, and agent or tool protocols.

06

File activity

Stable path groups and reads or writes to sensitive locations.

07

Processes and commands

Executables and normalized command actions.

08

Identity and credentials

Actors, delegated users, providers, and credential types.

09

Activity shape

Volume, bytes, destinations, and read-to-write patterns.

Inspect an agent action end to end

See the identity, tools, data, and destination behind it.

Connect inventory to runtime activity.

See what exists, who acted, and what data moved.

Agent runtime chain

Trace every agent action.

See where purpose or authority changed.

Intent DriftAgent Identity
Explore Agentic Security
AI inventory and posture

Inventory the AI estate.

Find models, tools, MCP servers, and vector stores.

AI InventoryAI-SPM
Explore AI-SPM
aicpa-logoiso-logo

© 2025 Aurva. All rights reserved.Terms of ServicePrivacy Policy

twitterlinkeding