Unauthorized Application Monitoring Agent
The Unauthorized Application Monitoring agent automatically scans your identity provider (IdP) for applications that have not been formally approved and surfaces them to your team on a recurring schedule. Instead of manually auditing your application catalog, you get a ready-made ticket, a detailed report, and a direct notification every time the agent runs - so unauthorized apps never go unnoticed.
What the Agent Does
Each time the agent runs, it performs the following actions:
Scans your IdP for any application that lacks an approved status in your catalog.
Creates a ticket that lists every unauthorized application found during that scan.
Attaches a CSV report to the ticket containing enriched details for each app, including owner, status, assigned users, first-seen date, last-seen date, and more.
Notifies the IT desk owner or assignee via Slack or Microsoft Teams so the right person can act immediately.
Supported Identity Providers
The agent works with the following IdPs:
Okta
Microsoft Entra
Google Workspace
JumpCloud
Prerequisites
Before activating the agent, make sure you have:
A connected IdP integration (Okta, Entra, Google Workspace, or JumpCloud)
A ticketing integration configured (for ticket creation)
A Slack or Microsoft Teams integration configured (for notifications)
Defined which applications in your IdP catalog are considered approved
Setting Up the Agent
Navigate to AI Agents in the left sidebar and select Unauthorized Application Monitoring.
Choose the IdP you want the agent to scan.
Select your ticketing destination where new tickets should be created.
Choose the IT desk owner or assignee who will receive Slack or Teams notifications when the agent surfaces unauthorized apps.
Set the recurring schedule that controls how often the agent runs (for example, daily or weekly).
Save your configuration and activate the agent.
Once activated, the agent will run automatically on the schedule you defined.
Understanding the CSV Report
Every ticket created by the agent includes an attached CSV report. The report contains one row per unauthorized application and includes the following fields:
Application Name
The display name of the app in your IdP
Owner
The user or team assigned as the app owner
Status
The current approval or provisioning status
Assigned Users
Number of users with access to the app
First Seen
Date the app was first detected in your IdP
Last Seen
Most recent date the app was observed
Use this report to prioritize remediation, track repeat offenders, and maintain an auditable record of your application catalog reviews.
Recurring Schedule
The agent runs on a schedule you configure during setup. On each run:
Only applications that are currently unauthorized at the time of the scan are included.
A new ticket is created for each run so you have a clear, time-stamped history of findings.
The designated owner or assignee receives a fresh notification via Slack or Teams.
Adjust the schedule at any time by returning to the agent's configuration page.
Notifications
When the agent completes a scan and finds unauthorized applications, it sends a notification to the configured IT desk owner or assignee through your connected messaging platform. The notification includes a summary of what was found and a link to the newly created ticket, so the recipient can jump directly into the details without searching for context.
Last updated
Was this helpful?
