All capabilities
All the capabilities, by workspace.
Each module of the ColossalX console, grouped by the six workspaces it lives in. Filter by what it does, then hover or tap a tile for the detail.
In short
All capabilities is a visual map of the ColossalX console: each module as one tile, grouped by its six workspaces (Command Center, AI Gateway, Agent Security, Risk and Testing, Compliance and GRC, Administration) and by verb. Each tile gives one line on what the module does today, with detail on hover or tap.
A long module list hides which ones answer your question, and which are still partly built.
Each module is described as it works today, grouped by workspace and by verb.
Command Center
Your first screen: posture, open work and the assistant.
- DashboardHow safe and governed your AI is today
See. One screen shows the trust grade, the alerts that matter, the traffic the gateway handled and where compliance stands. A count that cannot be read shows a dash, never a zero.
-
Issues
One queue of owned work, closed on evidence
Govern. Findings from testing, scanning, intelligence, audit and compliance land in one issue with an owner and a due date. A risk acceptance has to expire, so work cannot quietly disappear.
- InsightsWhat needs acting on this week, in order
See. Measured insights such as overdue fixes, untested agents and spend spikes, each with its evidence and the rule that fired. An AI brief ranks them and must cite them.
-
Trust Score
A grade that explains why it moved
Govern. Five pillars, graded A+ to F, with what pulls the score down and which evidence is missing. A grade resting on thin evidence is labelled provisional.
- MonitoringHealth of the platform itself, by component
See. A live health check lists each service of the platform with its current status, so IT can confirm the workspace itself is running.
-
Assets & Topology
Providers, agents and sensitive data, one map
See. An interactive map of the AI supply chain: model providers, agents and the classified data around them, with live status on each node. Where a list cannot be read, it says so.
-
Assistant
Ask your security workspace in plain language
See. Nine lookups and nine confirm-first actions run under your own permissions. When an answer is an action, it arrives as a card you approve, never something the model runs itself.
- My PoliciesPolicies in force, accepted by each person
Govern. Published policies show their version and owner. People accept each one by version, and a new version asks again, leaving the record an auditor will ask for.
AI Gateway
Each model call governed, from keys to consent.
-
Overview
See AI traffic and what was stopped
Control. One screen shows request volume against blocked requests, policy matches, provider health and any active kill switch. A figure that cannot be read shows a dash, never a zero.
-
Providers & Keys
Bring your own keys, hosted or self-hosted
Control. Connect 31 provider families, including self-hosted models. Your keys are sealed at rest and never shown again, and provider health is scored from the traffic that actually passed.
-
Guardrails & Policies
Write a control, see if it runs
Control. Each policy row says whether the control is really in force and why not, if it is not. A count shows requests where a control could not run.
-
Model Access
Decide which models each team may reach
Control. Set which people and contexts may use which models, with per-request and daily allowances. Switch any model off in one place; retired models are never offered.
-
Traffic Logs
A record of who asked, and what happened
See. Each request that reaches the gateway is stored with the person, the model that answered, tokens, cost and whether a control stopped it. Per-request decisions can be read back through the API.
-
Playground
Test a prompt or agent behind real guardrails
Prove. Try a prompt, or build and test a whole agent, through the same controls production traffic meets. Then register it and send it for approval.
-
Kill Switch
One switch halts AI, narrowly or broadly
Control. Halt AI for the whole workspace, one provider, one model or one person, with a written reason on record. Provider and model switches catch requests that name them.
-
Shadow AI
Find the AI nobody approved, decide once
See. Discover AI tools from gateway traffic, 13 collector types and a browser sensor. One decision becomes a standing rule, and the product says where a block really takes effect.
-
Content Scanning
Scan prompts and answers for sensitive identifiers
Control. Add your own identifiers, such as a policy number format, and try them on sample text. Plant canary tripwires in prompts, documents or database rows: a leak opens a critical incident.
- Data GovernanceClassified data assets, retention and consent
Govern. One inventory of data assets with their classification, retention and recent consent. Retention flags, archives or anonymises on schedule and never hard-deletes.
-
Consent
Withdraw consent, and the next request stops
Control. When a person withdraws consent for AI use, the gateway refuses their next request and logs it. It covers the inference-context purpose for signed-in users, and records a gap when the check cannot run.
-
AI Tool Registry
Allow, monitor or block each agent tool
Control. A control view of the MCP Firewall rules: allow, monitor or block each tool an agent can call. It is a rule list, not a discovered inventory of tools.
-
MCP Servers
See each MCP server your agents reach
See. Learned from real requests, nothing added by hand: who reached each server and which tools it offered. Approve or block it with a reason; a blocked server is refused for all agents.
-
AI App Catalog
A starter risk catalogue of GenAI apps
See. Score GenAI apps on data handling, compliance, security and terms, then record your own assessment. The starter scores are editorial judgements to re-assess, not measurements.
-
Telemetry
Requests, blocks, tokens and spend over time
See. Charts of request volume with blocked traffic, top models and provider mix, plus tokens and cost, over a range you choose. Export the hourly series as CSV.
-
Data Lineage
Which agent sent which data to which model
See. Drawn from real traffic: personal-data kinds sent to a model against those found and held back, and kinds returned in answers. Impact analysis shows what a change would touch.
Agent Security
Find, identify, admit, test and contain agents.
-
AI Agent Map
The agents you run, and what they touch
See. A live map of agents, the models they call, the declared tools and data they touch and who they delegate to, with attacker paths to your data lit up.
-
Agent Registry
A governed catalogue: registered is not approved
See. Agents enter four ways: registered by hand, found in code, discovered in traffic or attested from CI or the cloud. Approval needs an owner and a second approver.
-
LLM Inventory
Models and AI libraries your code imports
See. The models your gateway offers, and the AI SDKs, agent frameworks and MCP libraries your code actually imports. The code-discovered list is the strong part today.
-
SBOM & AI-BOM
Software parts listed, AI parts set apart
See. A bill of materials for each repository that separates ordinary libraries from the AI inside it, exportable as CycloneDX or SPDX, with approved baselines and drift alerts.
-
Repo Security
Secrets, dependencies and unsafe code, one scan
Prove. One scan per repository across 8 source-control providers: secrets, vulnerable dependencies, insecure code and personal data. False positives teach the scanner; findings become tickets and build gates.
-
Code Scan
Paste code, get findings and suggested fixes
Prove. Paste code or point at a repository and get findings mapped to OWASP web and LLM categories, each with a suggested fix. A quick check; serious repository work goes to Repo Security.
-
Scan Governance
Approve what code may be fetched for scanning
Govern. Decide which code may be fetched, who approved it, and keep an audit trail of each request. Source is read in memory; findings are kept, not the source.
-
Live App Scan
Test running apps, APIs and AI endpoints
Prove. Safe checks on any public site; deeper active, API and LLM checks only on domains you have proven you own. A build gate blocks only on new problems.
-
AI Red-Team
Attack your own chatbots, APIs and agents
Prove. Paste a chatbot, API or session URL and get the exact attack, the exact reply, the verdict and the framework reference for each break.
-
Supply Chain & Runtime
Stop a poisoned model file before it loads
Control. Model files are inspected, never executed, and a poisoned artifact is stopped at the gate. Containment of machine-speed agents is opt-in, on limits you set.
-
Guardrail Profiles
Write safety rules once, roll out gradually
Control. Reusable profiles follow the agent. Try a change on real traffic without enforcing it, roll it out to a few agents, enforce, and roll it back at any step.
-
Threat Intelligence
Threats matched to the AI you run
Prove. Intelligence is matched to your SBOM, models, agents and vendors and reviewed by a person. Each threat ends in a recorded decision: owned work, a watch, a simulation or a no.
-
MCP Firewall
Default-deny rules in front of agent tools
Control. Per-agent rules, a scanner for poisoned tool descriptions, tool pinning and a tester you can run before anything goes live. Argument checks are built in.
-
OWASP Assessments
Each agent assessed against OWASP Agentic risks
Prove. Each agent's configured controls are assessed against the OWASP Top 10 for Agentic Applications, showing which risks are covered and which are open. It is a configured-controls assessment, not an attack.
-
Trust Zones
Per-agent limits, measured on each request
Control. Give each agent a zone with limits you set: call rate, session length, tokens, tools and model hosts. Each request is measured and each breach recorded; refusal is a rule you switch on.
-
Prompt Injection Lab
See whether a pasted prompt is an attack
Prove. See if a prompt is an injection or a jailbreak, the technique it uses and how it maps to OWASP and MITRE ATLAS, then what your gateway actually stopped in the last day.
-
Agent code inspection
Code a model hands an agent, read first
Control. Code a model hands an agent is read for what it does before the agent gets it. It is read, never run.
-
Control Tower
Fleet posture, spend and the agent behind refusals
Control. A fleet control room: posture, violations, spend, kill-switch state and an agent leaderboard in one view, with the agent named behind each refusal.
-
Orchestrator
Chain agents into workflows a person can join
Control. Design workflows that ask agents, branch on their answers, wait for a human decision and contain or escalate. Each agent step runs through the gateway as that agent.
-
Agent Lifecycle
An append-only history of each agent's state
Govern. Where each agent stands, what changed this month and who changed it, from an append-only history of its lifecycle states.
-
Agent Governance
Controls in force over agents, with a trail
Govern. The controls in force over your agents, how the fleet behaved against them, and a trail of who changed what. Enforced means a rule on the request path reads it.
-
Session Recordings
Replay an agent's session request by request
Control. Record an agent, or your own privileged session, for a set time with full prompts and responses, then replay it with the decision each guardrail made on each request.
-
Agent Identity
Agents prove who they are, cryptographically
Control. Each agent gets a cryptographic identity, post-quantum hybrid on open standards, with signed requests that cannot be replayed, delegation that only narrows and a revocation list anyone can check.
-
Gate Enrolment
Choose which agents may pass your gate
Control. Enrol the agents allowed through the zero-trust gate, with expiry dates and one-click revocation. Roll it out in monitor mode first, then enforce when you are ready.
-
Access Graph
Review each agent's granted access in one place
Control. One place to review the just-in-time access granted to each agent, and catch grants that ran past their approval or still belong to an agent you shut down.
-
Access Requests
Just-in-time access instead of standing privilege
Control. One agent, one tool, until a date, approved by someone else and revocable at any time. Access that expires replaces standing privilege.
-
Fingerprinting
Recognise agents by what they do
See. Recognise each agent by its behaviour, see when that behaviour moves, and find out which known agent an anonymous caller really is. A baseline needs the agent's traffic to pass the gateway.
-
Intent Verification
Check an agent's purpose against its zone
Control. An agent's declared purpose is checked against what its trust zone allows before a sensitive operation, and each live tool call is checked against the same scope.
Risk & Testing
Quantify risk, then attack your own defences.
-
Risk Overview
AI risk posture, heat map and top risks
Govern. A live heat map and your top risks, with a maturity read judged from how your register is actually run rather than from a questionnaire.
-
Risk Register
A register that fills itself from findings
Govern. Entries arrive from compliance gaps, audits, scans, proven attacks and intelligence, de-duplicated and auto-closed. Each risk has an owner and a review date, and is never silently re-scored.
-
FAIR Analysis
Quantify AI risk in money, not colours
Govern. Enter low, likely and high estimates and get an annual loss range with its tail. The numbers come from your estimates, never from the product.
-
Vendor Risk
Which AI vendors nobody has assessed
Govern. An inventory of AI vendors you actually depend on, discovered from your gateway and app catalogue, flagging those in use but not assessed. The register itself is a manual list.
-
Risk Sync
Send the register to tools you already run
Govern. Outbound sync of the risk register to your GRC, ticketing and third-party risk tools, signed and replayable. It sends out only; nothing is written back.
-
AEV Simulations
Attack your agents in-path, through real controls
Prove. Attacks run in-path through your real controls and are judged blocked, detected, missed or refused by the model. See which control was meant to stop each probe and what you can close.
-
Exposure (CTEM)
Fix first what your tests proved reachable
Prove. Exposures ranked by validated reachability and business impact, with drift alerts when a defence regresses. One status reads incomplete when a source could not be read.
-
Playbooks
Incident playbooks, rehearsed before they are needed
Control. Incident playbooks built as real workflows, rehearsed safely before they are needed, with an honest count of which steps can actually run.
-
CyberTwins
Attack a twin of your agents, not production
Prove. A twin of your agents with its campaigns, findings and health on one page. Attacks and guardrail tests run against the twin rather than production.
-
Red Team Campaigns
Campaigns against named agents, with a clear record
Prove. Run a campaign against named agents through your real gateway. The record says what was attempted and what was not, with narratives for the board, CISO, engineers and regulator.
-
Attack Paths
Findings chained into routes an attacker could walk
Prove. Scan findings are chained into the routes an attacker could actually walk, with the evidence behind each step and a fix plan that you decide on.
-
Attack Library
AI attack scenarios, each runnable on your agents
Prove. A library of AI attack scenarios mapped to OWASP and MITRE ATLAS, each runnable against your own agents. A newly published technique can be turned into tests the same day.
-
Twin Environments
Attack a copy, then test the fix
Prove. Attack a copy of your agents, not production, then try the guardrail fix on the copy and promote it only if it holds.
-
Chaos Engineering
Break a provider on purpose, watch failover
Prove. Real faults are injected into AI traffic, with automatic rollback if the experiment hurts more than you planned. A failed experiment opens owned work with a due date.
-
Disaster Recovery
Backups proven to restore, every week
Prove. Each week the newest backup is restored into a scratch database and timed, and the recovery time and data loss are recorded. A restore drill is a test, not a live failover.
-
MITRE ATLAS coverage
Which ATLAS techniques you have actually tested
Prove. Measured from real runs: techniques exercised, exercisable and untestable are kept apart, so an untested technique is never counted as covered.
Compliance & GRC
Frameworks, evidence, audits and policies for the regulator.
-
Frameworks
Switch on the frameworks that apply to you
Govern. Activate the frameworks that apply, such as the EU AI Act, NIST AI RMF and India DPDP, each mapped to or assessed against. Collect fresh evidence on demand.
-
AI Governance
An AI control catalogue, measured from live signals
Govern. Controls mapped to the EU AI Act, NIST AI RMF, ISO/IEC 42001 and NIS2 and assessed from live signals. Controls without a runtime signal are reported not assessable and left out of the score.
-
Controls
Each control: a decided status, and proof
Govern. Each control carries a status someone decided and a health label showing whether anything proves it is working now, with the reasons one click away.
-
Cloud Posture
Posture counted from what discovery finds in AWS
Govern. Counted from the resources discovery finds in your connected AWS account and the configuration audit run against them, with a daily history that starts when recording starts.
-
Evidence
Evidence graded by where it came from
Govern. Graded A to D by how it was obtained, verified by a second person, kept byte-exact, sealed daily with a trusted timestamp, and withdrawn with a reason, never deleted.
- ReportsBranded reports, signed off and scheduled
Govern. Branded PDFs across 11 report types for the board and the auditor, with second-person sign-off, schedules and a flag when a report is out of date.
-
Regulatory Feed
Watch regulator pages, with a person confirming
Govern. Watch the regulator pages that matter to you. New circulars land as candidates for a person to read and confirm, never as unverified compliance content.
-
Jurisdictions
Tell it where you operate; clocks follow
Govern. Choose where you operate and what kind of entity you are, and the applicable regulators' reporting duties load as a rulebook with deadline clocks. It is starting content for your counsel to review.
-
Control Validation
Test frameworks against live state, with reasons
Govern. Each control gets a verdict and a stated reason against live platform state. A control with no runtime signal is shown as not assessable instead of being silently passed.
-
Cross-Mapping
Control-to-control mappings, each with a rationale
Govern. Control-to-control mappings between common frameworks, each with a stated confidence and rationale. A supporting view that shows where one control answers clauses in another framework.
-
Compliance Calendar
Each deadline you carry, on one calendar
Govern. Framework targets, audit plans, evidence expiry, regulatory reporting stages, finding due dates and risk-acceptance expiries, all built from the records you actually hold.
-
Audits
Plan on risk, finish with a sealed archive
Govern. Run each engagement through independence declarations, two-person review and management sign-off, ending in a sealed, timestamped archive anyone can verify. Preparer is never reviewer.
-
Policies
Write once, publish, collect acceptance by version
Govern. Generate an AI policy or upload yours and align it. Policies are versioned with a hash of the text, accepted per version by named people, with an auditor proof pack.
- Policy ExceptionsRisk acceptances that always have an end date
Govern. Each acceptance records who decided, why and until when, lapses back into open work on its end date, and goes to the board when it exceeds appetite.
-
Incidents
Runtime AI incidents, deduplicated and ticketed
Control. Runtime AI security incidents are deduplicated, ticketed and closed with a resolution note, and measured by trend and mean time to resolve. A runtime board, not a full case manager.
Administration
Identity, access, integrations and the product's own AI.
- Security & PrivacySet what employees may upload to the Assistant
Control. Set which files employees may upload to the Assistant, with a size cap and allowed file types, and choose to block sensitive content before it reaches a model.
-
Integrations
Connect your SIEM, ticketing, cloud and identity tools
Govern. For each connection, see what ColossalX reads, does and never does. Test it, rotate or revoke it from the row, and set up signed outbound and verified inbound webhooks.
- MarketplaceA catalogue of 120+ integration templates
Govern. Search templates across SIEM, cloud security, identity, DevOps, ticketing and more, and connect from the card. Depth varies: three SIEMs send natively and the rest receive by signed webhook.
- Identity ProvidersSingle sign-on with the accounts people have
Govern. Connect a SAML provider by pasting its metadata, with just-in-time provisioning and Microsoft Entra directory sync. People sign in with the accounts they already have.
- Access ManagementMap directory groups to access levels once
Govern. Map directory groups to access levels once, with custom roles down to the page, MFA required by role and an allowed email-domain list. Each screen tailors itself to the role.
-
API Keys
Scoped keys that never outlive their maker
Govern. Create a key with a lifetime and only the scopes the API checks. A key can never exceed its maker's permissions, the secret shows once, and a CI preset is ready.
- AI ModelsChoose where ColossalX's own AI runs
Govern. Run ColossalX's own AI features on a managed model, your own model and key, or a self-hosted endpoint, per feature, with a live test. Each internal AI call is recorded.
-
Browser Extension
See AI tools on laptops, local models too
See. A browser sensor, rolled out by browser policy, finds AI tools on laptops including local models that no network log can see. It is tested never to read a prompt.
- Data ProvenanceEach record says where it came from
Govern. Each record is labelled demonstration data or created by your own use, so evaluation numbers can be trusted. Counts are shown per table.
Honest by design
What this page does not claim.
This page · stated, not implied: Scope Console modules, one tile each; Described As they work today; Left out Plumbing and placeholders; Count Taken from the tiles. Stated, not implied.
x, not measured
Tiles describe what a module does today; a partly built module is described by what works.
All 3 limits
- Plumbing such as email delivery and help guides is left out.
- Frameworks are mapped to and assessed against; ColossalX holds no certification.
Questions
Questions buyers ask
What does All capabilities cover?
It lists each module in the ColossalX console, grouped by the six workspaces: Command Center, AI Gateway, Agent Security, Risk and Testing, Compliance and GRC, and Administration. Each tile gives one line and a short detail, written from what the module does today, not from what is planned.
Which modules are left out, and why?
Plumbing such as email delivery and help guides is left out, and so is any page that is a placeholder today. Where a module is only partly built, its tile says what it does now. The count above the tiles is taken from the tiles themselves, so it cannot drift from the page.
How do the verb and workspace filters work?
See, Control, Prove and Govern say what a module does: find AI, stop unsafe behaviour as it happens, show defences hold, or answer to the board and the regulator. Choose a verb, a workspace or both. A choice with no tiles is dimmed, and the count updates as you filter.
Where can I read more about one capability?
A tile with a page of its own links to it. Hover, focus or tap a tile for its detail, which is also written into the page for readers and crawlers, and into the Markdown copy of this page. A walkthrough shows the product itself, with your own questions.
Next step
Know your x.
Pick the workspace you care about and bring your own questions to a walkthrough of those modules.
- 01Pick a workspace
- 02Bring your own questions
- 03Decide where to start