Skip to main content

Get Started with AIDR

AIDR (AI detection and response) helps you monitor AI usage, detect threats, and enforce policies in enterprise environments. The AI traffic is sent for processing to AIDR APIs, and a report with policy decisions is included in the response according to the configuration defined in the AIDR console. All events are logged, can be visualized and inspected in AIDR console, and analyzed in CrowdStrike Next-Gen SIEM.

In this guide, you will open the AIDR console and explore sample data on the Visibility page.

Requirements

  • Requires one or more of these subscriptions:

    • AIDR for Workforce
    • AIDR for Agents

    note:

    AIDR subscriptions integrate with

    Next-Gen SIEM .

  • Default roles:

    • AIDR Metadata Viewer

      View findings and AI usage metadata. Prompt content and sensitive values are excluded. No access to collectors, policies, or settings.

    • AIDR Data Viewer

      All Metadata Viewer access, plus full event data including prompt content and entity values.

    • AIDR Viewer

      All Data Viewer access, plus read access to collectors, policies, and settings.

    • AIDR Admin

      All Viewer access, plus write access to collectors, policies, and settings.

    The Falcon Administrator role grants full access to AIDR collectors, policies, and settings, plus metadata-only event access.

    For more information, see User management .

  • Permissions required for custom roles:

    • Manage AIDR agent collectors
    • Manage AIDR findings and agent collectors
    • Manage AIDR findings and workforce collectors
    • Manage AIDR policy settings of agent collectors
    • Manage AIDR policy settings of workforce collectors
    • Manage AIDR workforce collectors
    • Read AIDR agent collectors
    • Read AIDR agent events
    • Read AIDR data from LogScale
    • Read AIDR data from LogScale via AIDR
    • Read AIDR findings and agent collectors
    • Read AIDR findings and workforce collectors
    • Read AIDR metadata from LogScale
    • Read AIDR metadata from LogScale via AIDR
    • Read AIDR policy settings of agent collectors
    • Read AIDR policy settings of workforce collectors
    • Read AIDR workforce collectors
  • AIDR permission assignments:

    NameDescriptionAIDR Metadata ViewerAIDR Data ViewerAIDR ViewerAIDR Admin
    Manage AIDR agent collectorsManage AI Detection and Response agent collectors
    Manage AIDR findings and agent collectorsManage AI Detection and Response findings and agent collectors
    Manage AIDR findings and workforce collectorsManage AI Detection and Response findings and workforce collectors
    Manage AIDR policy settings of agent collectorsManage AI Detection and Response agent collector policy settings
    Manage AIDR policy settings of workforce collectorsManage AI Detection and Response workforce collector policy settings
    Manage AIDR workforce collectorsManage AI Detection and Response workforce collectors
    Read AIDR agent collectorsRead AI Detection and Response agent collectors
    Read AIDR agent eventsRead AI Detection and Response agent events
    Read AIDR data from LogScaleRead AI Detection and Response data from LogScale directly
    Read AIDR data from LogScale via AIDRRead AI Detection and Response data from LogScale via AIDR
    Read AIDR findings and agent collectorsRead AI Detection and Response findings and agent collectors
    Read AIDR findings and workforce collectorsRead AI Detection and Response findings and workforce collectors
    Read AIDR metadata from LogScaleRead AI Detection and Response metadata from LogScale directly
    Read AIDR metadata from LogScale via AIDRRead AI Detection and Response metadata from LogScale via AIDR
    Read AIDR policy settings of agent collectorsRead AI Detection and Response agent collector policy settings
    Read AIDR policy settings of workforce collectorsRead AI Detection and Response workforce collector policy settings
    Read AIDR workforce collectorsRead AI Detection and Response workforce collectors
  • CrowdStrike clouds: Available in US-1, US-2, and EU-1

Open AIDR console

In the Falcon console, click the menu icon and go to AI detection and response > Visibility .

Visualize sample data

Before you ingest your own data, you can explore a sample dataset on the Visibility page to see how AIDR visualizes relationships between applications, actors, collectors, and other entities found in AI-related events.

AIDR presents event data on the Visibility page through interactive diagrams, charts, and dashboards.

These visualizations help you see how AI is used across your organization, surface risky usage patterns, and monitor the effectiveness of AI policies and controls.

Once you begin ingesting your own data, it will appear on the Visibility page instead of the sample dataset. You can use the Visualize Sample Data option in the filters dropdown to switch back to the sample data view while you build up real-world coverage.

Data flows

The interactive Sankey diagram on the Visibility page helps you visualize event data by connecting different attributes. This view helps you explore relationships and patterns across your AI activity.

This view supports pattern recognition, anomaly detection, and risk exposure mapping. It helps answer questions such as:

  • Which providers or models dominate usage patterns?
  • Are unapproved providers or models being used, and through which applications?
  • Which users are accessing which applications and models, and at what volume?
  • How do different collector types contribute to observed traffic?
  • Are there unexpected or unusually high-volume flows from unapproved applications or users?

Below are example use cases and corresponding three-node Sankey configurations for common AI activity patterns:

Use CaseAttributesDescription
  • Employee AI usage
  • Use of unapproved providers
  • Potential data exposure
  • Shadow AI discovery
User - Application - Provider

Shows employees' AI provider usage through different applications. Helps uncover unsanctioned tools or traffic observed by browser collectors.

  • Active AIDR coverage
  • Potential gaps in visibility
Application - Collector Type - Model

Identifies which applications are monitored, by which collector types, and which models they access.

  • Collector deployments
Application - Collector Type - Collector

Verifies that collector instances are deployed correctly and cover intended applications.

tip:
  • Hover over elements in the diagram to view metrics and see the breakdown by detection type.
  • Use the View next 10 + and View previous - buttons to scroll through nodes when more data is available than can fit on the screen.

Dashboards

The dashboards on the Visibility page provide additional insight into AI traffic patterns and potential risk exposure.

Quick filters

You can apply filters by clicking the following elements on the Visibility page:

  • DETECTIONS button - Limit the data to events that triggered a detection defined in your policies. Click ACTIVITY to remove this filter and return to the full event view.
  • Date range dropdown - Select a predefined time range from the dropdown next to the search bar. You can also define a custom range and apply your own interval.
  • Attribute nodes - Click any node in the Sankey diagram or the Visibility dashboard to filter by that specific attribute value. For example, clicking an user node filters the data to only show events involving that user.
  • Policy Detections - Click a detection type in the Policy Detections dashboard to show only events that triggered that detection.
  • Active Collectors - Click a collector type in the Active Collectors dashboard to show only events collected by that type.

Choose your path

Select the guide that matches your AIDR subscription and use case:

Monitor Employee AI Usage (AIDR for Workforce)

  • Use case - Monitor and control employee use of web-based AI tools like ChatGPT, Claude, Gemini, and others in managed enterprise environments.
  • Target audience - Security teams, CISOs, compliance officers managing employee endpoints
  • What you'll deploy - Browser collector via managed browser extensions

Get started with AIDR for Workforce

Build AI Applications (AIDR for Agents)

  • Use case - Integrate security controls into AI-powered applications, autonomous agents, and internal AI systems.
  • Target audience - AI application developers and architects
  • What you'll deploy - Application, Agentic, Gateway, Cloud, or OpenTelemetry collectors.

Get started with AIDR for Agents

©2026 CrowdStrike. All rights reserved.

PrivacyTerms of UseLegal Notices