First Recon governs coding agents and third-party AI where their traffic crosses the Secure Enterprise AI Workspace, Endpoint Security, or the gateway. The control available depends on which surface carries the interaction.
Endpoint Security can discover AI and SaaS access on managed devices and apply allow, block, or redirect policy at the endpoint boundary. Traffic through the workspace or gateway receives full runtime analysis and enforcement before data reaches a provider. First Recon cannot control activity inside a third-party application unless that vendor exposes, and the customer configures, a compatible integration.
Fig C1 · Three surfaces, and where each AI usage type crosses one.
What governs what
Managed devices
Endpoint Security discovers AI and SaaS access and can allow, block, or redirect it before the application opens.
Workspace & gateway
Every interaction receives full runtime policy and enforcement before content reaches an outside provider.
Inside third-party SaaS
In-product control requires an integration or API that the vendor exposes and the customer configures. This limit applies to every endpoint security provider.
Fig C2Enforcement by surface: today, and through the pilotGo deeperClose
Fig C2 · Enforcement by surface: what lands today, what hardens through the pilot.