Findings by source

Dialogflow

Google Cloud · organizations/123456789012 Google · Agent platform · audit serviceName dialogflow.googleapis.com

Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Finding · Open
Risk score
51
High
People
1
Principals in Cloud Audit Logs
Audit entries
6
0 invocations · 0 denied · 30 days
First seen
Aug 30, 2026
Last seen 42 h ago
gcpbuildersagentsinvocations-unlogged
Next steps

Recommended actions

  1. 01Only Admin Activity logs were visible for Dialogflow. Enable Data Access audit logs for dialogflow.googleapis.com at the organization level so model calls (GenerateContent, Predict) are recorded and Lantern can count who sends prompts.
  2. 02Data stores, engines, or agents are configured. Review which buckets, sites, and databases they index; an indexed data store is a standing grant of that content to whoever can query the agent.
Billing · Google Cloud

What it costs

Last 30 days
$141
Previous 30
$151
Change
-7%
2026-06-16: 52026-06-17: 52026-06-18: 62026-06-19: 62026-06-20: 22026-06-21: 22026-06-22: 62026-06-23: 62026-06-24: 62026-06-25: 62026-06-26: 62026-06-27: 22026-06-28: 22026-06-29: 62026-06-30: 62026-07-01: 62026-07-02: 62026-07-03: 72026-07-04: 22026-07-05: 22026-07-06: 62026-07-07: 62026-07-08: 62026-07-09: 52026-07-10: 62026-07-11: 22026-07-12: 22026-07-13: 62026-07-14: 62026-07-15: 62026-07-16: 62026-07-17: 62026-07-18: 22026-07-19: 22026-07-20: 72026-07-21: 72026-07-22: 62026-07-23: 62026-07-24: 62026-07-25: 22026-07-26: 22026-07-27: 62026-07-28: 72026-07-29: 62026-07-30: 62026-07-31: 62026-08-01: 22026-08-02: 22026-08-03: 62026-08-04: 62026-08-05: 62026-08-06: 62026-08-07: 72026-08-08: 22026-08-09: 22026-08-10: 62026-08-11: 62026-08-12: 62026-08-13: 62026-08-14: 62026-08-15: 22026-08-16: 22026-08-17: 62026-08-18: 62026-08-19: 62026-08-20: 62026-08-21: 62026-08-22: 22026-08-23: 22026-08-24: 62026-08-25: 62026-08-26: 62026-08-27: 62026-08-28: 62026-08-29: 22026-08-30: 22026-08-31: 62026-09-01: 62026-09-02: 52026-09-03: 62026-09-04: 52026-09-05: 22026-09-06: 22026-09-07: 62026-09-08: 62026-09-09: 62026-09-10: 72026-09-11: 62026-09-12: 22026-09-13: 2
06-1609-13
Google Cloud (demo) · organizations/123456789012

In Google Cloud

2026-08-16: 02026-08-17: 02026-08-18: 02026-08-19: 02026-08-20: 02026-08-21: 02026-08-22: 02026-08-23: 02026-08-24: 02026-08-25: 02026-08-26: 02026-08-27: 02026-08-28: 02026-08-29: 02026-08-30: 12026-08-31: 02026-09-01: 02026-09-02: 02026-09-03: 02026-09-04: 02026-09-05: 02026-09-06: 02026-09-07: 02026-09-08: 12026-09-09: 12026-09-10: 12026-09-11: 12026-09-12: 12026-09-13: 02026-09-14: 0
08-1609-14
data access logs offadmin activity only
Principals
PrincipalTypeEntriesDenied
[email protected]user60
Top methods
Flows.UpdateFlow5
Agents.CreateAgent1
Projects
contoso-support6 entries
Resources
TypeNameProject
Agentsupport-botcontoso-support
Who

People

Identifiers come from device telemetry and proxy logs, so they may be account names rather than full directory entries.

PersonDepartmentSourceSign-ins · 30 dGranted
n/aGoogle Cloud principal0No direct grant
Why

Evidence

  1. audit_activity · Sep 12, 2026
    Google Cloud (demo): Dialogflow, 6 audit entries by 1 principal, 6 write, 1 resource, API enabled in 1 project in 30 days across 1 project
    Detail
    {
      "scopes": [
        "organizations/123456789012"
      ],
      "services": [
        "dialogflow.googleapis.com"
      ],
      "topMethods": [
        {
          "name": "Flows.UpdateFlow",
          "count": 5
        },
        {
          "name": "Agents.CreateAgent",
          "count": 1
        }
      ],
      "dataAccessLogging": false
    }
  2. agent
    Agent 'support-bot' in contoso-support (us-central1)
    Detail
    {
      "name": "//dialogflow.googleapis.com/projects/contoso-support/locations/us-central1/agents/abcd"
    }
  3. api_enabled
    dialogflow.googleapis.com enabled in contoso-support
    Detail
    {
      "project": "contoso-support"
    }