Governance guide

How to govern Security in Gemini

A step-by-step guide to governing Security in Gemini with Rencore: detect, review by owner and severity, and remediate with an audit trail.

Definition

Governing Security in Gemini means finding where it goes wrong, reviewing the findings by owner and severity, and remediating with an audit trail. Rencore covers this concern for Gemini with the pre-built controls below, so it becomes a repeatable check rather than a one-off cleanup. The steps that follow apply the same detect, review, remediate loop to Security.

Steps

  1. Inventory Gemini

    Connect Gemini and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.

  2. Detect with policies

    Turn on the pre-built policies that cover Security in Gemini to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.

  3. Review by owner and severity

    Use the Gemini reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.

  4. Remediate and automate

    Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.

Gemini controls for Security

Grounded in the Rencore catalog. See the full Gemini catalog on the Gemini connector page.

  • Gemini user is an external identity

    External (guest) users are a more probable attack vector, raising the likelihood that reachable Vertex AI resources are exploited

    Severity: Medium
  • Gemini notebook runtime is running

    Running notebook runtimes are a live, reachable compute surface, raising the likelihood that any weakness is exploited

    Severity: Medium
  • Gemini endpoint is serving traffic

    Endpoints with deployed models are a live, callable prediction surface, raising the likelihood that any weakness is exploited

    Severity: Medium
  • Gemini model is deployed and live

    Models deployed to endpoints are actively serving predictions, raising the likelihood that any weakness is exploited

    Severity: Medium
  • Gemini engine is live with data stores

    Engines connected to data stores actively serve content to callers, raising the likelihood that any weakness is exploited

    Severity: Medium
  • Gemini agent is live and in use

    Agents updated within the last 90 days are live, callable surfaces, raising the likelihood that any weakness is exploited

    Severity: Medium
  • Gemini user is deactivated in Entra ID

    Detects Gemini users who are deactivated in the parent Entra ID

    Severity: Medium
  • Gemini user is external user in Entra ID

    Detects Gemini users which are guest in the Entra ID directory

    Severity: Medium
  • Gemini notebook runtime in unhealthy state

    Detects notebook runtimes that are reporting an unhealthy health state

    Severity: High
  • Gemini agent not updated in 90 days

    Detects deployed reasoning engines (agents) that have not been updated in the last 90 days

    Severity: Medium
  • Gemini agent without description

    Detects deployed reasoning engines (agents) that have no description set

    Severity: Low
Explore the full Gemini governance catalog | All guides

Trusted by

MAPALBAMVille de LuxembourgWACKERGRUNDFOSAMGENOsramLufthansaThyssenKruppSunrisePattern