Dialogflow
Google Cloud · organizations/123456789012 Google · Agent platform · audit serviceName dialogflow.googleapis.com
Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Finding · Open
Risk score
51
High
People
1
Principals in Cloud Audit Logs
Audit entries
6
0 invocations · 0 denied · 30 days
First seen
Aug 30, 2026
Last seen 42 h ago
gcpbuildersagentsinvocations-unlogged
Next steps
Recommended actions
- 01Only Admin Activity logs were visible for Dialogflow. Enable Data Access audit logs for dialogflow.googleapis.com at the organization level so model calls (GenerateContent, Predict) are recorded and Lantern can count who sends prompts.
- 02Data stores, engines, or agents are configured. Review which buckets, sites, and databases they index; an indexed data store is a standing grant of that content to whoever can query the agent.
Billing · Google Cloud
What it costs
Last 30 days
$141
Previous 30
$151
Change
-7%
06-1609-13
Google Cloud (demo) · organizations/123456789012
In Google Cloud
08-1609-14
data access logs offadmin activity only
Principals
| Principal | Type | Entries | Denied |
|---|---|---|---|
| [email protected] | user | 6 | 0 |
Top methods
Flows.UpdateFlow5
Agents.CreateAgent1
Projects
contoso-support6 entries
Resources
| Type | Name | Project |
|---|---|---|
| Agent | support-bot | contoso-support |
Who
People
Identifiers come from device telemetry and proxy logs, so they may be account names rather than full directory entries.
| Person | Department | Source | Sign-ins · 30 d | Granted |
|---|---|---|---|---|
| n/a | Google Cloud principal | 0 | No direct grant |
Why
Evidence
- audit_activity · Sep 12, 2026Google Cloud (demo): Dialogflow, 6 audit entries by 1 principal, 6 write, 1 resource, API enabled in 1 project in 30 days across 1 project
Detail
{ "scopes": [ "organizations/123456789012" ], "services": [ "dialogflow.googleapis.com" ], "topMethods": [ { "name": "Flows.UpdateFlow", "count": 5 }, { "name": "Agents.CreateAgent", "count": 1 } ], "dataAccessLogging": false } - agentAgent 'support-bot' in contoso-support (us-central1)
Detail
{ "name": "//dialogflow.googleapis.com/projects/contoso-support/locations/us-central1/agents/abcd" } - api_enableddialogflow.googleapis.com enabled in contoso-support
Detail
{ "project": "contoso-support" }