SASE Integration

Discover the AI apps and data sources in use across your network from SASE traffic.

If your company routes internet traffic through a SASE or secure web gateway, Airia can use that traffic to discover which AI apps and AI data sources people are using across the network, continuously, as it happens. This is Shadow AI discovery: finding AI tools in use without anyone having to report them.

SASE is a cloud security service your company's internet traffic flows through. You may also hear it called a secure web gateway or secure service edge. Because everything passes through it, it's a good place to spot AI usage.

This page covers the Discover → Connect side: creating the Shadow AI configuration and pointing your gateway at it. For the full integration build — credential passing, validated platforms, closing the direct path, and token rotation — see SASE Integration.

At a glance

SurfaceEndpoint (network-level)
What it doesDiscovers which AI apps and AI data sources people use, from your network traffic
How Airia connectsYour SASE or gateway forwards AI traffic or logs to Airia, or routes AI calls through Airia
Who sets it upYour network or security team, working with the Airia support team
TimeVaries by vendor

Two common patterns

There are two ways to wire this up. Your Airia contact will tell you which one fits your setup.

PatternWhat happens
Forward logsYour SASE or gateway sends its AI-related traffic logs to Airia's Shadow AI ingestion. Airia reads them to discover AI usage.
Route through AiriaAI API calls are routed through the Airia Gateway's Shadow address. Calls that didn't originate from Airia are still recorded, then passed through to the AI provider unchanged.

Both patterns are about visibility. Neither changes the AI responses your users get.

Before you start

  • A SASE or secure web gateway that your internet traffic already flows through.
  • The ability to forward logs or route AI traffic from that gateway. This usually needs your network or security team.
  • The specific fields, log format, or Shadow address Airia expects — get these from the Airia support team.

Because SASE vendors differ, this guide stays generic on purpose. The exact menu names and field labels live in your vendor's console and your Airia build. Confirm the specific fields and addresses with the Airia support team before you start.

Setup

Part A — Create the Shadow AI configuration in Airia

Open Shadow AI configurations

  1. In Airia, go to Discover → Connect and click the SASE Integration tile. It opens the Shadow AI configurations page, also reachable under Security → Shadow AI configurations.
  2. Each configuration provides a unique URL for redirecting AI API traffic through an Airia Gateway for governance and monitoring.
  3. Click Create Configuration.

Fill in the configuration

FieldValue
Name (required)A descriptive name, for example Corp SASE — Prod
Description (optional)What this configuration covers
Gateway Configuration (required)The Airia AI Gateway to route intercepted traffic through — this is where guardrails, DLP, and monitoring apply
Enable ConfigurationOn. When disabled, the configuration doesn't accept traffic

Click Create, then copy the configuration's unique URL.

Treat the configuration URL like a secret. Anyone with it can send traffic through your gateway.

Create one configuration per traffic segment you want to distinguish — Dev, Prod, one per SASE vendor. Each gets its own URL, so usage stays attributable.

Part B — Redirect traffic in your SASE gateway

This step usually needs your network or security team, since it changes how traffic is routed.

Redirect AI API traffic to the unique URL

  1. In your SASE or gateway product, create a rule that redirects AI API traffic — calls to AI provider endpoints — to the configuration's unique URL.
  2. Traffic hitting that URL is recorded and passed through the selected Airia Gateway, with its guardrails and monitoring applied.

The exact rule mechanics — URL rewrite, proxy chain, PAC file — vary by vendor. Use whichever redirect mechanism your SASE product supports.

Verify it worked

The connection shows Connected. As AI traffic flows through your gateway, discovered AI apps and data sources appear under Discover → Inventory, in the Apps, Data Sources, and Shadow AI views.

Troubleshooting

SymptomFix
Nothing appears in AiriaConfirm AI traffic is actually flowing through your SASE gateway, and that log forwarding or routing points at the correct Airia endpoint.
Connection test failsRe-check the values from your SASE config. Confirm the exact fields and address with the Airia support team.
Unsure which pattern to useAsk the Airia support team whether to forward logs or route AI calls through the Shadow address — it depends on your vendor.
Only some AI usage shows upMake sure all the relevant traffic locations and users route through the gateway that's forwarding to Airia.

What you get

What Airia discovers

ObjectDiscovered?Source
AI apps in useYesAI traffic across your network, via your SASE gateway
AI data sources in useYesAI traffic across your network, via your SASE gateway
Agents / models / MCP & toolsNot produced by this connector

Where it shows up

In the productWhat you see
Discover → Inventory → AppsAI apps seen in your network traffic
Discover → Inventory → Data SourcesAI data sources seen in your network traffic
Shadow AI viewsAI usage discovered across the network, for review and governance

How often it syncs

Continuous, event and log driven. There's no fixed schedule — usage shows up as traffic flows and logs arrive.

What you can do

Govern — everything discovered is inventoried, so you can review AI usage across the network, classify it, and track it.

Secure — apply policy at the network layer through your SASE gateway and the Airia Gateway, giving you visibility plus control over AI traffic. Exact enforcement options depend on your SASE vendor and your Airia build.

CapabilitySupported
DiscoverYes
GovernYes
SecureYes — policy at the network layer
  • SASE Integration — the full integration build.
  • Cloudflare — network-level discovery and blocking through Cloudflare Gateway.
Was this page helpful?

On this page