Outcome · Application Control

Know every script and agent on your network.

Crawlers, scripts, CI runners and AI agents reach your systems all day, and most organisations cannot name one of them. Fowlguard gives each one a row and an owner.

Application ControlEXAMPLE
CallerKindOwnerStatus
build-runner-7CI RunnerPriya NairOwned
report-botAI AgentLena ParkOwned
sync-script.pyScript—No Owner
unknown crawlerCrawler—Blocked
Before and after

What changes on day one.

Today

  • A rulebase written for people, with nothing to say about software
  • Agents identified by whatever name they give themselves
  • Nobody knows who is responsible for a script
  • Inbound crawlers and outbound AI traffic lumped together

With Fowlguard

  • One row per agent, script and crawler
  • What a caller claims is checked against evidence it cannot choose
  • An owner for every caller, and the unowned ones stand out
  • Inbound and outbound kept apart, because they are different problems
How it works

Every caller named and owned.

Application Control

One row per caller.

Fowlguard names what is calling, whether it is a CI runner, a script or an AI agent, and lets you give each one an owner. An agent nobody will claim is the finding.

  • Callers, never conversations: no prompt or response content is read, stored or scored
Application ControlEXAMPLE
CallerKindOwnerStatus
build-runner-7CI RunnerPriya NairOwned
report-botAI AgentLena ParkOwned
sync-script.pyScript—No Owner
unknown crawlerCrawler—Blocked
Inbound and outbound

Two directions, two questions.

Somebody else's crawler reading what you publish is a different problem from your own people sending work to a model, so they are never added together.

  • Included with both Private Access and Internet Access
Logs›Access LogsEXAMPLE
TimePersonDeviceHostResult
14:02Maria OkaforHP-FIN-014ledger.internalAllow
13:58Sam ReyesLNX-CON-011db-prodDeny
13:51Lena ParkMBP-ENG-022git.internalDeny
Get it running

From unknown to owned.

Most teams start by simply looking.

  1. Turn on visibility

    Application Control is part of the Small plan and above for both products.

    Small · $5 per user per month
  2. Claim what is yours

    Give each agent, script and runner an owner. What nobody claims goes on the list to investigate.

  3. Decide what may run

    Use Report first, then Block for callers you do not want.

    Off → Report → Block
Questions

Questions people ask.

More in the guides

Do you read prompts or responses?

No. Application Control identifies callers. No prompt or response content is read, stored or scored to do it.

How do you know what a caller is?

What a caller calls itself is a claim it chose, so it is checked against evidence it does not get to choose.

Which plan includes it?

Application Control is included from the Small plan, on both Private Access and Internet Access.