It's Launch Week at Axonius! Get Decision-Grade AI Context.

Read the Product Announcements

Announcing Axonius MCP Server and Axonius AI Agent for security and IT

Frederico Hakamine

Technical Evangelist Director, Axonius

Avidor Bartov

Co-Founder and Chief Architect

Security and IT teams have moved past experimenting with chatbots. They’re deploying AI that reasons across systems, chains steps together, and coordinates work from investigation through response and Model Context Protocol (MCP) has become the standard way that those AI assistants and AI agents plug into the tools where your data actually lives. The question isn’t whether AI belongs in the security operations center (SOC) anymore. It's whether you're giving it the data to do the job right. An AI agent is only as good as the context it can reach.

An AI assistant that can't see your environment is guessing. An AI agent that acts on incomplete or conflicting data doesn't reduce risk. It automates mistakes at machine speed. In asset intelligence, context means the full picture: every device, user, application, code repository, cloud workload, operational technology (OT) sensor, and exposure across your environment. 

The missing layer is durable context. Every AI system carries its own short-term context (the prompt, the session, whatever you paste in), but an AI agent has no independent way to verify that what it’s acting on is current or complete. The Axonius Asset Cloud is that durable context layer. It sits above the stack and continuously reconciles every enterprise data source into one authoritative, decision-grade asset model that AI systems can reason from. 

Axonius has spent years building the authoritative asset foundation that AI needs; now we're putting it directly in the hands of the AI agents and AI tools your security and IT teams are already adopting. Queryable from wherever the work happens. 

Today, we're announcing three new capabilities that do exactly that: 

  • Axonius AI Agent: A native, context-aware security partner built directly into the Axonius Asset Cloud.

  • Axonius MCP Server: Opens the entire Axonius asset model to the AI tools you already use in natural language. 

  • Docs for AI: Machine-readable and public documents, which help your AI work with Axonius without wasting time and inference.

Axonius AI Agent

The Axonius AI Agent is a native, context-aware security partner built directly into the Axonius Asset Cloud. 

It understands and reasons with your environment at a deeper level, leveraging our expertise and, critically, auditing AI reasoning without bleeding your context to an AI harness. 

Blog_Image_-_Axonius_AI_-_AI_Landing.jpg

Getting started with the Axonius AI Agent

Axonius expertise as a building block

The Axonius AI Agent is equipped with the Axonius expertise and best practices (in the form of skills) that are curated and continuously improved by our team of specialists (security professionals, engineers, and cyber researchers) derived from our experience of over 7 billion asset interactions per year, across the most complex organizations. Under the hood, the AI agent will ship with a growing library of skills including curated playbooks that teach the agent how to answer a class of questions correctly, with guardrails built in so it follows proven query patterns instead of guessing. Because skills are modular, the same framework extends cleanly as capabilities grow. 

Out-of-the-box, Axonius ships pre-configured specialist AI agents for the highest-value hygiene and coverage workflows. 

  • Inventory hygiene: Surfaces long-running cloud virtual machines (VMs) with no active owner or project, so you can reduce cost and attack surface. 

  • Agent coverage: Provides the classic “does asset X have agent Y?” check (e.g. “Your Production-Web-Servers group has 687 devices, but 68 aren't reporting to your endpoint detection and response tool.”). 

  • Adapter health: Flags stale or failing data sources (e.g. “The Jamf adapter has failed its last 3 fetch attempts due to an expired API secret”), before a data gap surprises you in an audit. 

  • Compliance drift: Watches for movement away from a gold standard, turning a scary quarterly audit into a minor weekly check-in.

Beyond the specialist agents, the Axonius AI Agent understands Axonius itself including the documentation, the data models, and the fields behind every asset. With this knowledge, it's able to translate a plain-language question into a query and help you define classifications within your data (what’s a crown jewel, a “production” system, and so on). 

Chain multiple queries about your environment

Built for agentic workflows

Agentic workflows are where security operations are heading, and the Axonius AI Agent is built to work in that world.

  • From one AI agent to many: A core AI agent handles broad questions and hands off to purpose-built specialist AI agents when a task calls for domain depth: always with your explicit consent. Instead of a single monolithic chatbot, you get a coordinated team of AI agents working a problem together.

  • Memory that doesn’t drift: A generic AI agent’s context ends at the end of a session. The Axonius AI Agent reasons from the continuously reconciled asset model and learns about the user, so its understanding of your environment stays current and authoritative between every interaction.

  • Built to interoperate: Because the Axonius AI Agent and Axonius MCP Server share the same governed foundation, Axonius AI agents can contribute trusted asset context to the broader agentic workflows your security and IT teams are building. Whether in Slack, ticketing, or your own orchestration layer.

What it means for security and IT teams

Security and IT leaders with any level of Axonius proficiency can get answers to their questions straight from the Axonius AI Agent instead of building queries from scratch. Power users can offload the comparison work that used to take hours of dashboards, exports, and VLOOKUPs. Every AI agent operates within the asking user's permissions including data scopes and role-based access control (RBAC). If a user can't see certain data in Axonius, neither can their AI agent. Activities are fully logged to ensure auditability.

Using the Axonius AI Agent IRL 

Because Axonius reconciles every adapter source into one model, the Axonius AI Agent answers questions that span your entire environment, not just what a single tool can see. A few examples on how security and IT teams can get started:

  • Close coverage gaps

    • Find devices that are alive on the network, but whose security agent stopped reporting or was never installed. 

    • Prompt: “Show me my broken agents: devices that are still active but their security agent stopped reporting.”

  • Catch cross-adapter contradictions

    • Surface the conflicts no single source can see on its own. 

    • Prompt: “Find zombie devices that are disabled in my directory, but still active on the network.” 

  • Summarize for executive leadership in seconds

    • Turn the whole estate into a leadership-ready summary. 

    • Prompt: “Give me an executive asset report: totals, protection gaps, exploited-CVE exposure, and what’s new this week.”

  • Spot integration gaps: 

    • Get clarity on tools that may be helpful, but that haven’t been connected to Axonius yet so you can close category gaps at the source. 

    • Prompt: "Can you think of more adapters I should connect? Check my category gaps and products already installed in my network."

Axonius MCP Server

MCP is the standard way for AI assistants and AI agents to connect to external systems. The Axonius MCP Server makes your entire Axonius environment queryable in natural language from the AI tools your security and IT teams already use, whether that's a desktop AI assistant, an Integrated Development Environment (IDE), low code platforms, or your own agentic workflows. 

Because Axonius has already collected, correlated, and reconciled exposure and asset data across 40+ asset types, the Axonius MCP Server exposes a foundation that's decision-grade. It is the same correlated ground truth that powers the rest of the Axonius Asset Cloud. 

What you can query

Connected to a live Axonius MCP integration, an AI tool like Anthropic Claude can query your environment in real time across assets of every type: Compute, Exposures, Identities, Networks, Apps, and Storage. 

  • Compute: Devices (operating system, software, CVEs, network interfaces, and certificates), compute services, databases and containers.

  • Exposures: Security findings and aggregated findings.

  • Identities: Users, groups, roles, and permissions.

  • Networks: Networks, network devices, load balancers, network services, and firewall rules.

  • Apps: Software, SaaS applications, licenses, and expenses.

  • Storage: Object storage, file systems, and disks.

How security and IT teams put it to work

  • Investigate with speed: The Axonius MCP Server translates questions into Axonius Query Language (AQL) and returns the answer from your live environment. 

    • “How many devices are running Windows and have a CRITICAL CVE?” 

    • “Which adapters are currently failing or have errors?” 

    • “Find all certificates expiring in the next 30 days.”

  • Meet analysts where they work: Your security and IT teams don't have to context-switch into the Axonius user interface (UI) to get an answer. They can ask from the AI assistant they use day-to-day, or wire Axonius context into a broader agentic workflow that reasons across multiple systems. 

  • Ground your own AI agents in truth: If you're building AI workflows, the Axonius MCP Server gives them a reliable, governed source of asset context instead of stale exports or brittle point-to-point API integrations.

Docs for AI

AI tools need context to deliver value, and that includes documentation on how to interact with the Axonius Asset Cloud. This sounds like an obvious requirement (and it is), but most security tools fail in providing documentation for both humans and AI.

At Axonius, we take pride in saying our documentation is public. We believe it’s your right, even before becoming a customer, to understand what a platform can do for you. Today, we extend that right to your AI, with our docs publicly available for humans and machines alike. No need to set up an MCP, sign-up to a portal, or buy software to use it. 

You can serve your AI with our documentation via docs.axonius.com/llms.txt, via our MCP, and directly by starting AI prompts from our docs.

Blog_Image_-_Axonius_AI_-_Docs.jpg

Open Axonius docs directly in an AI tool (desktop)

Our approach gives you freedom of choice at cost

We're building Axonius AI with freedom of choice in mind. For that, we:

  • Support AI usage at any phase: Our breadth of AI integration points (through Axonius AI Agent, Axonius MCP Server, and Docs for AI) allow you to leverage AI at any point: from before adopting Axonius, all the way to daily use. Our docs are public and machine-friendly, our MCP gets full access to all asset inventory types, exposures, and adapter configurations, and AI agents are set to tackle the hardest issues on day one.

  • Deliver context for AI of all asset types and exposures: The Axonius MCP Server and the Axonius AI Agent can access asset intelligence across 40+ asset types supported by Axonius, regardless of where these assets live. This greatly reduces your effort to deliver full context for AI to work. 

  • Establish a single source for asset and exposure context: Through the Axonius MCP Server and Axonius AI Agent, AI gets the full context of assets through a single place. This reduces the need to connect multiple siloed MCPs and time spent on reasoning and inference/token costs.

Guardrails: built to be trusted

Putting AI on top of your asset data only works if it's safe by default. Both the Axonius MCP Server and Axonius AI Agent ship with guardrails. 

  • AI access is granular (by function and data): The Axonius AI Agent inherits access from the logged user roles and data scopes. Axonius MCP from its service account. This ensures least privilege is applied across all AI interfaces.

  • Granular and centralized audit: Both the Axonius MCP Server and Axonius AI Agent log activities tied to their respective identities: MCP audited as service account activity; AI Agent audited as user level with a clear distinction of which tasks were executed by the user or by the AI Agent on behalf of the user.

Best practices for prompting

Both the Axonius MCP agent and Axonius AI experience reward specificity. A few patterns will get you dramatically better results:

Prompting the Axonius AI Agent

  • Leverage our example prompts: Axonius AI comes with example prompts across different categories on its landing page. Leverage these prompts to answer popular questions and also provide guidelines on where the system yields the best results

  • Ask consultative questions: Favor “Where are my biggest EDR coverage gaps and what should I do about them?” over just a data pull. The AI agent is at its best when it reasons, not just retrieves.

  • Avoid needle-in-a-haystack lookups: The AI agent shines at synthesis and pattern-finding across the estate, not at fetching one obscure record you could pull with a direct query search.

Prompting the Axonius MCP Server 

  • Be specific about asset type: Name whether you mean devices, users, software, containers, and so on.

  • State your filters: Call out the OS, severity, date range, adapter, or tag directly in the prompt.

  • Ask for counts: First when you're unsure of scale, before requesting full records.

Prompts that work well

  • Simple counts: 

    • “How many devices are missing Crowdstrike?”

    • “How many saas apps miss our SSO (Okta), but are actively expensed (in our Netsuite)”

    • “How many deactivated employees (workday) are still active”

  • Infrastructure and health: 

    • “Which adapters are currently failing or have errors?”

    • “When did the last discovery cycle finish?

  • Investigation-style: 

    • “Are there super admin accounts without SSO/MFA? Any of those are non-human identities?”

    • “How many cloud containers are in our environment, and what adapters are discovering them?”

Blog_Image_-_Axonius_AI_-_Example_Prompt.jpg

Prompt the Axonius AI Agent for contextualized details about your environment

Guide your AI with a foundation it can trust

The most capable AI agents can still ticket the wrong team, chase a ghost asset, or miss a live exposure if the data underneath it is stale or contradictory. Grounding is the hard part, and it’s where most AI security efforts break down. 

This is what Axonius has solved. The Axonius MCP Server opens our asset foundation to the AI agents and AI tools your security and IT teams choose to run; the Axonius AI Agent puts a governed, context-aware partner inside the Axonius Asset Cloud. In security, trust is earned by being right. The fastest way to lose that trust is to let AI act on data no one has verified. Give your AI agents something they can trust, and they’ll give you answers you can act on.

Want to try Axonius AI out in your environment? Get a demo.

Availability

  • Axonius AI Agent is in preview. 

  • Axonius MCP Server is available to customers in early access. 

  • Docs for AI is generally available to customers.

Additional Resources

Categories

  • Artificial Intelligence Ai
Get Started

Get Started

See how to make asset intelligence actionable with a guided demo:

  • Stop chasing data — work from one asset model your entire team can trust.
  • See what's exposed before it's a problem — surface coverage gaps automatically.
  • Turn alert noise into action — cut thousands of alerts down, to the ones that matter.