Intent Drift
Detect when agents drift from purpose.
Compare each agent's observed behavior with its established purpose and baseline.
Intent Drift
Connect purpose, identity, access, and outcome
Runtime evidence chain
The observed path behind this activity
Agent
payments-agent
Known
API
billing.internal
Expected
Model
approved-model
Expected
Database
payroll-db
First seen
Egress
new-destination
First seen
Material intent drift
A new sensitive datasource and a first-seen destination appeared in the same runtime window.
A baseline you can explain
Keep the observations behind every agent baseline.
Establish
Learn the agent's normal destinations, dependencies, data systems, APIs, models, files, commands, identities, and activity shape.
Compare
Evaluate new behavior against the baseline and the agent's recorded purpose without inferring intent from its name.
Explain
Show the changed behavior, affected systems, materiality signals, and supporting records together in the finding.
PURPOSE IN RUNTIME
Authorized does not mean appropriate.
Judge whether access still serves the agent's established purpose.
Runtime context
Observed evidence chain
Agent or service scoped
Provider logs, application telemetry, and runtime signals
Environment-specific behavior kept separate
01 / AGENT BASELINE
Baseline each agent separately
A baseline belongs to a logical agent or service, not an infrastructure primitive. Vertex AI, Bedrock, and Databricks logs can contribute alongside application telemetry and runtime signals.
Runtime comparison
Expected and observed behavior
Expected
Observed
02 / MATERIAL CHANGE
Detect shifts, not just new values
Aurva considers both new values and changes in the distribution or volume of known behavior. A familiar API used at an unfamiliar scale can matter as much as a new destination.
Reviewable finding
Runtime evidence · high confidence
Expected and observed behavior side by side
Affected agents, data systems, and destinations
Evidence retained for investigation and audit
03 / REVIEWABLE FINDING
Show exactly what changed
Every finding states the expected behavior, the observed change, why it is risky, and the records that support it. Reviewers can distinguish a legitimate product change from an agent acting outside its purpose.
RUNTIME SIGNALS
Nine signals. One agent baseline.
Track coverage across provider logs, application telemetry, and runtime signals.
01
External destinations
Hosts, IP addresses, ports, and first-time egress.
02
Internal dependencies
Services and protocols reached inside the environment.
03
Database access
Database systems, services, connection patterns, and data volume.
04
API behavior
Methods and normalized routes without variable identifiers.
05
AI usage
Providers, models, operations, and agent or tool protocols.
06
File activity
Stable path groups and reads or writes to sensitive locations.
07
Processes and commands
Executables and normalized command actions.
08
Identity and credentials
Actors, delegated users, providers, and credential types.
09
Activity shape
Volume, bytes, destinations, and read-to-write patterns.
Connect inventory to runtime activity.
See what exists, who acted, and what data moved.
Trace every agent action.
See where purpose or authority changed.
Inventory the AI estate.
Find models, tools, MCP servers, and vector stores.




