QuilrAI Platform Overview
QuilrAI helps security, governance, and IT teams discover AI usage, understand risk, and safely roll out controls across users, apps, accounts, endpoints, gateways, and integrations.
Visibility
Track AI adoption, risky behavior, sensitive prompts, top users, top apps, and usage trends from a single insights surface.
Users, Apps, Accounts
Review entity-level risk, usage, interactions, and findings with drilldowns for users, SaaS apps, endpoint apps, and accounts.
Smart Groups
Create and manage smart groups and group membership from one place. Smart groups are used to scope access control and rules in MCP Gateway, LLM Gateway, and other platform areas.
AI Inventory
Maintain a live inventory across Browser Extension, Endpoint Agent, LLM Gateway, MCP Gateway, and compliance API sources.
Findings
Investigate findings across browser extension, endpoint agent, LLM Gateway, MCP Gateway, compliance, identity, and all-source views.
Controls
Create, edit, enable, monitor, or enforce controls by posture, with support for system and custom controls.
Quilly
Review security coaching conversations in Slack and Microsoft Teams — finding-linked outreach, proactive coaching, and user-initiated policy questions.
Gateways
Configure LLM Gateway and MCP Gateway protection, logs, routing, guardrails, tools, access control, red teaming, and agent mappings.
Platform Areas
Insights
Use Insights to understand how AI is being adopted across the organization. The dashboard highlights adoption trends, top AI applications, top categories, top users, sensitive data in prompts, and department-level usage.
Findings
Findings centralizes investigation work across the platform. Teams can move between summary insights, all findings, browser extension findings, endpoint findings, LLM Gateway findings, MCP Gateway findings, Compliance Findings, and identity findings.
Escalations
Escalations lets SOC and governance teams raise a finding into a trackable Case, discuss it internally, and ask the finding's own user for a justification via a secure link, with full conversation history and close-out tracking.
Users, Applications, And Accounts
The Users, Applications, and Accounts pages show entity-level AI activity. These views combine KPI summaries, trending entities, searchable tables, drilldowns, conversations, findings links, and app intelligence so teams can understand who is using AI, where, and with what risk.
Smart Groups
Smart Groups is the dedicated screen for creating and managing user groups across the platform. Admins can create groups with or without initial members, add or remove users, and delete groups. Smart groups defined here are used to scope access control rules in MCP Gateway and LLM Gateway.
AI Inventory
AI Inventory helps teams track AI assets and AI activity sources from one place. Source views include Browser Extension applications, Endpoint Agent applications and coding inventory, LLM Gateway API keys, MCP Gateway servers, and Compliance APIs for supported providers.
Controls
Controls let teams operationalize policy. Customers can browse controls by posture, filter by system or custom controls, add or update controls, duplicate existing controls, toggle status, and choose monitor or action mode.
Quilly
Quilly is Quilr's security coaching bot in Slack and Microsoft Teams. Security teams can review finding-linked coaching, proactive outreach, and user-initiated conversations from the Quilly Conversations drawer, User Lens, and finding cards.
Detection Models
Detection Models define what QuilrAI should detect. The data-risk experience supports out-of-box and custom detections, contextual and non-contextual data risks, and custom techniques such as precision, semantic, and intent-based detection. Additional adversarial and insider-risk tabs may appear when enabled for the tenant.
Policy Engine
The Policy Engine is where admins write the rules that govern AI traffic: when traffic matches a condition, apply an effect such as allow, block, redact, throttle, or route elsewhere. Policies are authored, validated, simulated, and published from Policy Studio, then enforced live by the gateway that handles the traffic.
- LLM Gateway policies cover chat and completions traffic, including sensitive-data handling, gateway access, identity and network trust, tool controls, allowed models, routing, limits, token savings, and prompt store enforcement.
- MCP Gateway policies cover agent-to-MCP-server traffic across the session, discovery, request, and response stages, including server access, capability visibility, human approval for tool calls, usage quotas and concurrency, managed authentication, cache isolation, and web search security.
AI Gateway
AI Gateway includes LLM Gateway and MCP Gateway.
- LLM Gateway centralizes provider configuration, API key management, security guardrails, additional guardrails, routing, rate limits, token saving, identity-aware access, prompt store enforcement, logs, and red team testing.
- MCP Gateway manages MCP servers, OAuth and passthrough connections, tools, access tokens, access control, security guardrails, logs, graph views, library installs, and agent configuration.
Browser Extension And Endpoint Agent
Browser Extension and Endpoint Agent settings cover deployment, deployment management, deployment status, whitelisting, detection configuration, DLP actions, and browser monitoring behavior.
Integrations
Integrations help connect QuilrAI to identity providers, device management systems, SaaS platforms, cloud services, and AI services. The current platform includes connected and available connector views, instance configuration, and integration documentation for Microsoft Entra ID, IDP Group to Platform Roles, Okta, Jamf, ChatGPT, and AWS.
Settings And Administration
Settings provides organizational context, general settings, organizational policies, user management, user-interaction customization, compliance setup, browser extension setup, endpoint setup, and AI Gateway setup. Smart group management is available from the dedicated Smart Groups screen.
Data Retention
Data Retention sets how long each kind of LLM and MCP data stays visible in the console. A tenant-wide policy of ordered rules assigns an independent visibility window to eight data classes, from activity metadata through request and response content to finding evidence. It hides data from the console rather than deleting it, and an impact preview estimates what a draft would hide before you publish.
Audit Log And Exports
Audit Log gives teams searchable, filterable event history with expandable snapshots. Exports provides export history and new CSV or JSON exports for supported platform tables.
Suggested Reading Path
- Start with Insights to understand adoption and risk trends.
- Review Users, Applications, Accounts, and AI Inventory to see what exists.
- Use Findings to investigate high-impact issues.
- Configure Detection Models and Controls to align enforcement with policy.
- Use the Policy Engine to turn that policy into rules the gateway enforces on live traffic.
- Set up Browser Extension, Endpoint Agent, Integrations, and Gateways to expand coverage.
- Set Data Retention to match how long each kind of data should stay visible in the console.
- Use Audit Log and Exports for reporting and operational review.