Skip to main content

Process mapping

Process mapping is how the Endpoint Agent builds an inventory of applications and AI components on each device, ties running processes to those applications, and enforces execution policies. It starts discovery as soon as the agent runs.

Discover
Process monitor (10 s)
File scanner (startup + 30 min)
Correlate
Process to app identity
Cached lookups
Sync
Push discovered apps
Pull governance
Enforce
Allow / Block
Quarantine / Justify
QuilrAI

What it discovers​

MethodWhat it finds
OS installersInstalled apps and programs (macOS apps, Windows installed programs).
Package managersBinaries from npm, pip, go, gem, Homebrew, and Chocolatey.
Process monitoringRunning processes, matched to known applications.
File system scanStandalone executables, AI agent configuration, and project files.
AI agent discoveryMCP servers, skills, plugins, hooks, models, and instruction files.

Discovered items are grouped into these entity types:

EntityExamples
ApplicationDesktop apps, CLI tools, running processes
MCP serverMCP server configurations
HookLifecycle hooks for AI tools such as Cursor and Claude
SkillAgent skill definitions
AgentAI agent configurations
ModelDownloaded or referenced AI models
Controlled repoGit repositories under AI tool control
PermissionTool permission configurations
PluginIDE plugins and extensions

Discovered items appear in Inventory, Agents, and the Discovered tab of the Skills Library.

Policy actions​

ActionWhat happens
AllowThe application runs normally; activity is logged.
BlockThe application is terminated and the user is notified.
QuarantineThe executable is renamed in place (it can be restored) and the event is logged.
JustifyThe user is asked for a justification before continuing.

Policies come from the console (approval status, execution policy, and criticality per application). See App policies. Every decision and enforcement action is recorded for audit.

How it works​

StageWhat happens
Process monitorPolls running processes every 10 seconds and tracks new processes, exits, and PID reuse.
File scannerRuns at startup and every 30 minutes. Walks configured paths and runs sandboxed discovery scripts to find AI entities.
CorrelatorMaps process names and executable paths to application identities, using a cache with a 300-second lifetime per entry.
Entity storeHolds the current inventory in memory and publishes added, updated, removed, and governance-changed events.
SyncUploads discovered entities to the backend and pulls governance overrides. See Backend connectivity.
EnforcerApplies the execution policy when an entity changes: terminates blocked processes (POSIX signals on macOS, process termination APIs on Windows), quarantines, or logs.

The agent snapshots its inventory to disk every 30 seconds. After a crash or restart it reloads the snapshot and resumes syncing from where it left off; replaying governance updates is safe.