SASE Integration
Discover the AI apps and data sources in use across your network from SASE traffic.
If your company routes internet traffic through a SASE or secure web gateway, Airia can use that traffic to discover which AI apps and AI data sources people are using across the network, continuously, as it happens. This is Shadow AI discovery: finding AI tools in use without anyone having to report them.
SASE is a cloud security service your company's internet traffic flows through. You may also hear it called a secure web gateway or secure service edge. Because everything passes through it, it's a good place to spot AI usage.
This page covers the Discover → Connect side: creating the Shadow AI configuration and pointing your gateway at it. For the full integration build — credential passing, validated platforms, closing the direct path, and token rotation — see SASE Integration.
At a glance
| Surface | Endpoint (network-level) |
| What it does | Discovers which AI apps and AI data sources people use, from your network traffic |
| How Airia connects | Your SASE or gateway forwards AI traffic or logs to Airia, or routes AI calls through Airia |
| Who sets it up | Your network or security team, working with the Airia support team |
| Time | Varies by vendor |
Two common patterns
There are two ways to wire this up. Your Airia contact will tell you which one fits your setup.
| Pattern | What happens |
|---|---|
| Forward logs | Your SASE or gateway sends its AI-related traffic logs to Airia's Shadow AI ingestion. Airia reads them to discover AI usage. |
| Route through Airia | AI API calls are routed through the Airia Gateway's Shadow address. Calls that didn't originate from Airia are still recorded, then passed through to the AI provider unchanged. |
Both patterns are about visibility. Neither changes the AI responses your users get.
Before you start
- A SASE or secure web gateway that your internet traffic already flows through.
- The ability to forward logs or route AI traffic from that gateway. This usually needs your network or security team.
- The specific fields, log format, or Shadow address Airia expects — get these from the Airia support team.
Because SASE vendors differ, this guide stays generic on purpose. The exact menu names and field labels live in your vendor's console and your Airia build. Confirm the specific fields and addresses with the Airia support team before you start.
Setup
Part A — Create the Shadow AI configuration in Airia
Open Shadow AI configurations
- In Airia, go to Discover → Connect and click the SASE Integration tile. It opens the Shadow AI configurations page, also reachable under Security → Shadow AI configurations.
- Each configuration provides a unique URL for redirecting AI API traffic through an Airia Gateway for governance and monitoring.
- Click Create Configuration.
Fill in the configuration
| Field | Value |
|---|---|
| Name (required) | A descriptive name, for example Corp SASE — Prod |
| Description (optional) | What this configuration covers |
| Gateway Configuration (required) | The Airia AI Gateway to route intercepted traffic through — this is where guardrails, DLP, and monitoring apply |
| Enable Configuration | On. When disabled, the configuration doesn't accept traffic |
Click Create, then copy the configuration's unique URL.
Treat the configuration URL like a secret. Anyone with it can send traffic through your gateway.
Create one configuration per traffic segment you want to distinguish — Dev, Prod, one per SASE vendor. Each gets its own URL, so usage stays attributable.
Part B — Redirect traffic in your SASE gateway
This step usually needs your network or security team, since it changes how traffic is routed.
Redirect AI API traffic to the unique URL
- In your SASE or gateway product, create a rule that redirects AI API traffic — calls to AI provider endpoints — to the configuration's unique URL.
- Traffic hitting that URL is recorded and passed through the selected Airia Gateway, with its guardrails and monitoring applied.
The exact rule mechanics — URL rewrite, proxy chain, PAC file — vary by vendor. Use whichever redirect mechanism your SASE product supports.
Verify it worked
The connection shows Connected. As AI traffic flows through your gateway, discovered AI apps and data sources appear under Discover → Inventory, in the Apps, Data Sources, and Shadow AI views.
Troubleshooting
| Symptom | Fix |
|---|---|
| Nothing appears in Airia | Confirm AI traffic is actually flowing through your SASE gateway, and that log forwarding or routing points at the correct Airia endpoint. |
| Connection test fails | Re-check the values from your SASE config. Confirm the exact fields and address with the Airia support team. |
| Unsure which pattern to use | Ask the Airia support team whether to forward logs or route AI calls through the Shadow address — it depends on your vendor. |
| Only some AI usage shows up | Make sure all the relevant traffic locations and users route through the gateway that's forwarding to Airia. |
What you get
What Airia discovers
| Object | Discovered? | Source |
|---|---|---|
| AI apps in use | Yes | AI traffic across your network, via your SASE gateway |
| AI data sources in use | Yes | AI traffic across your network, via your SASE gateway |
| Agents / models / MCP & tools | — | Not produced by this connector |
Where it shows up
| In the product | What you see |
|---|---|
| Discover → Inventory → Apps | AI apps seen in your network traffic |
| Discover → Inventory → Data Sources | AI data sources seen in your network traffic |
| Shadow AI views | AI usage discovered across the network, for review and governance |
How often it syncs
Continuous, event and log driven. There's no fixed schedule — usage shows up as traffic flows and logs arrive.
What you can do
Govern — everything discovered is inventoried, so you can review AI usage across the network, classify it, and track it.
Secure — apply policy at the network layer through your SASE gateway and the Airia Gateway, giving you visibility plus control over AI traffic. Exact enforcement options depend on your SASE vendor and your Airia build.
| Capability | Supported |
|---|---|
| Discover | Yes |
| Govern | Yes |
| Secure | Yes — policy at the network layer |
Related
- SASE Integration — the full integration build.
- Cloudflare — network-level discovery and blocking through Cloudflare Gateway.