Complete AI Training

AI agent for manager of its

Cloud Security Group Review Agent

Cloud network rules limited to what is needed, with each change tested

Cloud Security Group Review Agent: what goes in, what the agent does and what you get

What it does

Cloud rules sometimes open ports to the whole internet and stay that way for years. This agent reads security groups and route tables, then finds public exposure and unused rules. It checks resource tags to find the owner of each exposed item and proposes tightening, such as limiting a source range or closing an old port. After the owner approves a change, it tests connectivity from the allowed sources to make sure the service still works. If the test fails, it rolls back and tries a narrower change. Edge case: a database port is open to the internet, but the tag shows a vendor integration, so the agent asks for the vendor's address range.

How it works

Follow the arrows from top to bottom. The orange dashed arrow is the loop: when a check fails, the agent goes back and tries again.

Start and resultWhat it doesA check on its own workWaits for your OKGoes back and retries
Yes, continueApprovedYes, continueNoNo 1 STARTS WHEN Weekly security group scan 2 USES A TOOL Read security groups, route tables and tags 3 DOES Find rules open to the internet and unused rules 4 DOES Find each owner from the resource tags 5 CHECKS THE RESULT Does each exposed rule have an owner and adocumented reason? If not: ask the owner or escalate to the security team.Back to step 3. 6 DOES Propose a narrower rule for each risky item 7 YOU APPROVE Owner approves each change 8 USES A TOOL Apply the change and test connectivity from theallowed sources 9 CHECKS THE RESULT Does the service still work for the allowed users? If not: roll back and propose a narrower change. Back tostep 6. 10 RESULT Exposure report with changes made
Read the steps as a list
  1. Weekly security group scan
  2. Read security groups, route tables and tags
  3. Find rules open to the internet and unused rules
  4. Find each owner from the resource tags
  5. Does each exposed rule have an owner and a documented reason?If not: ask the owner or escalate to the security team. Back to step 3.
  6. Propose a narrower rule for each risky item
  7. Owner approves each changeThe agent waits here for your OK.
  8. Apply the change and test connectivity from the allowed sources
  9. Does the service still work for the allowed users?If not: roll back and propose a narrower change. Back to step 6.
  10. Exposure report with changes made

How it decides

A rule is risky when it allows a sensitive port from anywhere or has no recent traffic. Tightening must keep the known sources working.

  • Flag any sensitive port open to all addresses
  • Flag rules with no traffic for 60 days
  • Require an owner tag for every exposed rule
  • Roll back on any failed connectivity test

Make it yours

Every agent is a starting point. You choose these settings for your own situation.

  • Sensitive ports list
  • Unused rule days (default: 60)
  • Scan frequency
  • Cloud accounts in scope

What keeps you in control

It always asks you first

  • Owner approves each change

Hard limits

  • Never changes a rule without the owner's approval
  • Never opens a new port

It stops when

  • Done: no unapproved public exposure remains
  • Stop: owner cannot be found, so the item goes to security

Set it up

We guide you through the set-up, step by step

Members get the full set-up guide for this agent. No technical skills needed: you copy, paste and upload.

10 minto set it up in your AI
5 AIsChatGPT, Claude, Copilot, Gemini, Grok
  • One set of instructions to paste into your AI, with the clicks for ChatGPT, Claude, Microsoft 365 Copilot, Gemini and Grok
  • The agent then walks you through connecting your own data, one source at a time
  • A downloadable copy with the flow chart, the rules and the full guide
Get access to this agent

An example run

What happensThe scan found a database port open to 0.0.0.0/0. The tag showed a vendor integration. The agent asked for the vendor's range and proposed limiting access to it. After the owner approved, the connectivity test from the vendor address failed, so the agent rolled back. It added the vendor's second address range, and the test passed.

More agents for manager of its