Announcing Citadel Radar for Agents: Cross-Platform Agent Control and Visibility

Filed under:

Extending Citadel Radar from AI chatbots to AI agents, addressing agent-specific risks to support safe enterprise-wide adoption

Citadel AI Inc. (CEO: Hironori Kobayashi) announces Citadel Radar for Agents, a new product that provides visibility into agents across multiple AI platforms and controls risks at runtime. Radar for Agents is available through an Early Access Program (EAP) for leading enterprises.

This product extends Citadel Radar, which evaluates prompts and responses of generative AI applications. It expands coverage beyond conversational applications such as chatbots to agents that use tools and actions to perform business tasks.

Challenges from scaling individual pilots to enterprise-wide AI

Expanding agent use beyond a small group of employees or a limited environment requires organizations to maintain security while allowing access to the data and tools needed for business tasks. Scaling agent adoption across the enterprise presents four key challenges:

  • Visibility into agent use: Since anyone can easily start using agents, organizations need a complete view of who is using which agents and for what tasks. They also need to understand and manage the data those agents can access, the tools they use, and how they behave at runtime.
  • Agent-specific risks: Malicious instructions embedded in external content (indirect prompt injection), or misinterpreted instructions and divergence from human intent (intent drift), can cause agents to act outside its intended business purpose. Static access control and checking agent responses alone cannot capture the risks of data leakage or unintended actions across the agent’s action loop. 
  • Fragmented platforms: Platforms such as Claude, Copilot, ChatGPT, and in-house systems differ in their settings and management approaches. Rapid advances in agents and platforms also make it difficult for security and governance to keep pace with new capabilities. Applying common internal policies requires platform-specific checks and configuration, increasing operational workload and the likelihood of inconsistent controls.
  • Incident response: Without tracing both the human instructions and intent given to an agent and the full sequence of its actions, organizations cannot identify the cause or scope of an incident. Uncertainty about what to stop and which settings to change delays recovery and remediation.

Controlling high-risk configurations and actions while preserving autonomy

Blanket restrictions on agents’ decisions and actions limit the work they can perform. Organizations need a way to correct unnecessarily risky configurations and intervene during actions that could lead to incidents, while preserving the autonomy and access required for the task.

Citadel Radar for Agents provides posture management to understand what agents are configured and permitted to do, and session management to monitor and control the actions they take at runtime. In addition to static configuration checks, Radar monitors agent activity at runtime, taking into account the user, their intent, and prior actions. It detects deviations from the intended business purpose and policy violations that may not be visible when actions are assessed in isolation, then uses root-cause analysis to guide improvements to configurations and tool connections.

Key features of Citadel Radar for Agents

1. Visibility into models, agents, tools, and other assets

Radar inventories assets, including tools such as MCP servers, and automatically creates an agent registry. It identifies both active agents and those that have been created but left unused.

2. Posture management of agent and platform configuration

Radar checks for excessive permissions and overly broad connections, reviews access to sensitive data, and continuously assesses compliance with common policies. Risk scores are provided alongside specific areas requiring correction.

Posture Management: a list of agent configuration issues and recommended actions
3. Real-time controls informed by session context

Actions are evaluated based on the intent of the prompt, who is running the agent, and what the agent has done so far. In addition to blocking risky tool calls, Radar allows users to define task-specific guardrails in natural language.

Session Management: a detailed timeline for reviewing agent actions and guardrails
4. Incident analysis to investigate causes and scope

An intuitive interface lets users review a timeline from the initial prompt through each tool call. The dashboard clearly visualizes blocked actions and the reasons for blocking them, supporting investigation and remediation.

5. Multi-platform support that keeps pace with platform changes

The product enables centralized agent security management across AI platforms, including Copilot, Claude, and Dify. Ongoing support for new platform features and changes reduces the burden on administrators.

6. Start governing agents by connecting existing platforms

Connecting an existing AI platform enables organizations to begin discovering agents and checking their configurations and permissions. This reduces deployment effort and allows governance to begin within the environments already in use.

  

  

For more information, please visit the Citadel Radar for Agents product page:
https://citadel-ai.com/ja/products/radar-agent/

Early Access Program

The Early Access Program (EAP) for Citadel Radar for Agents is now starting. Participating organizations will help shape product improvements, and the EAP will help participants develop risk management and operational practices to accelerate agent deployment. Companies interested in the EAP can contact info@citadel-ai.com.

Related Articles

Please let us know the demo you’d like to see or the features you wish to check so we can assist you smoothly.