Training Presentation
Monitor, Govern & Protect Generative AI Usage
Check Point Security • Training Edition
A platform that helps administrators monitor, govern, and protect generative AI usage across the organization.
Bottom Line: Balance innovation with security — safely enable AI while protecting sensitive data.
Complete view of all generative AI platforms, their purposes, and associated risks.
Understand top AI use cases to make better policy and investment decisions.
AI-driven data classification reduces risk of sensitive information exposure.
Audit trail of user activities ensures compliance with industry regulations.
Plus: Continuous monitoring, advanced risk assessment, governance & reporting tools.
Two deployment options tailored to organizational needs:
Coverage: Web, Desktop, MSP, IDEs
Capabilities: Full Discovery, Governance & Protection
Integration: Complete — all environments
Positioning: Full-featured, comprehensive
Coverage: Web applications only
Capabilities: Discovery, Governance, Protection (Web)
Integration: Limited to web apps
Positioning: Lighter, more affordable add-on
Workforce AI Security operates across three primary layers:
Captures AI-related user actions on devices:
Evaluates each AI interaction: Access Policies, Chats/DLP Policies, Agent Policies
Check Point Portal — dashboards, analytics, event logs, policy config, RBAC
The system processes AI activity through this sequence:
Central interface for monitoring AI activity — executive summary at a glance
Highest traffic AI apps with risk color indicators:
Critical High Medium
Shows users, sessions, prompts, file uploads & usage trends
Top 5 sensitive data types & top 5 use cases driving AI adoption across the org
Users with highest risky activity — pinpoints where oversight/training is needed
Distribution of Allow / Ask / Prevent / Block actions across sessions
Total AI Traffic: managed vs unmanaged split
Bubble chart: each app's risk level vs usage volume
Endpoint components monitor AI activity & enforce policies on every device.
Visibility into AI agents and AI-enabled applications:
Model Context Protocol servers expose tools & APIs to AI agents:
Active Servers table: Platform, MCP server, Users, Capabilities, Top tools, Operations (CRUD), Invocations
Workforce AI Security enforces security across three policy planes:
Access Policies — Application-Level Control
Decides if a user can access a specific AI app. Actions: Allow / Ask / Block.
Chats / DLP Policies — Content-Level Control
Inspects content sent to AI. Uses Data Types to identify sensitive data. Actions: Allow / Block / Detect / Prevent / Redact.
Agent Policies — Tool-Level Control for MCP
Governs MCP server tools, URL/file reputation, prompt injection protection, content moderation.
Block all by default, allow only approved apps
Maximum control & predictability
Allow all by default, block only known risky apps
Flexible, minimal restrictions
Key Point: Data Types Classification powers DLP — predefined + custom patterns detect sensitive content in prompts, pastes, and uploads.
Design Tip: Be conservative with agent policies. Refine based on discovery data. Agent policies control actions (invoking tools, CRUD ops), not just access.
| Action | Behavior | Data Flow | Data Control |
|---|---|---|---|
| Allow | Accepts without restrictions | Allowed | Not restricted |
| Ask | User must confirm | Conditional | Conditional |
| Block | Rejects data, stops action | Not allowed | Attempt blocked |
| Detect | Logs only, no interruption | Allowed | Not restricted |
| Prevent | Strictly blocks, disables submission | Not allowed | Action disabled |
| Redact | Removes/masks sensitive data | Sanitized only | Sensitive data removed |
Files: Allow / Ask / Block / Prevent • Pasted text: adds Detect • MCP: Block / Allow
Each event row: Application, Type, Time, User, Risk, Use Case, Action, Policy Name, Reason, Sensitive Data, File Names, Prompt (admin view)
Predefined Data Types
Built-in sensitive data patterns
Custom Data Types
Org-specific content patterns
My Groups
Custom collections of types
Check Point Recommended
Curated sensitive data sets
Note: Max 100 Data Types across all policies. Context Data Types use AI analysis for meaning-based detection (available for AI category, Text Control & Paste events).
Connect SaaS platforms to discover and scan agent-based AI workloads.
Connects your workspace to OpenAI through a compliance-controlled API for visibility into OpenAI usage.
Note: Uses a Compliance API key (not standard OpenAI API key). Discovered agents appear in Inventory for review and management.
Monitors Claude Enterprise usage via Anthropic Compliance API (read-only access to audit and usage data).
Manual scan (Scan Now) or Periodic (Off / Daily / Weekly). Agents appear in Inventory with usage levels (Low to Extreme) and models used.
Goal: Block all by default; allow only approved apps
Maximum control & predictability
Goal: Allow all; block only known high-risk apps
Flexible, minimal restrictions
Goal: Same platform, different trust levels
Allow managed, block/restrict unmanaged
Goal: Observe before restricting
Access=Allow, Chats=Detect, then enforce
Goal: Control automated actions
Conservative by design, refine from data
Four specific service roles (in addition to Global Roles):
| Role | Permissions |
|---|---|
| Read-Only | Read-only to all pages. Cannot create/edit policies. No prompt viewing. |
| Admin | Read & write to all pages. No prompt viewing. |
| Admin — View High-Risk Prompts | All Admin privileges + view high & critical risk prompts |
| Admin — View All Sensitive Prompts | Full Admin + visibility into all sensitive prompts (low-risk and above) |
Note: Prompts not classified as sensitive are not stored (privacy control). Assign prompt-viewing roles via Account Settings > Users > Specific Service Roles > AI Security.
Define organization-approved app instances:
Integrate with MDM for user/device synchronization.
Complete visibility into all AI usage across your organization
Layered policies: Access → DLP (Chats) → Agents
Flexible control: Allow, Block, Ask, Prevent, Detect, Redact
Integrate with OpenAI, Claude, M365 Copilot & more
Balance innovation with security — safely enable AI
Workforce AI Security • Training Edition