Clovie Docs

Concepts

Cloud connections

Connect your cloud accounts and AI platforms so Clovie can find the agents that already run there.

Not every agent starts life registered in Clovie. Teams build agents on cloud AI services, call model providers with their own accounts, or switch on assistants inside business software. Discovery connectors let Clovie look for these agents so you can bring them under governance.

What you can connect

You add connectors from AI Governance → Agents → Discovery: open More and select Connectors.

GroupSources
Cloud providersAmazon Web Services, Google Cloud Platform, Microsoft Azure, Kubernetes
AI platformsOpenAI, Anthropic
SaaS platformsSalesforce Agentforce, ServiceNow, Microsoft 365 Copilot

You can add several connectors for the same provider, for example one per AWS account, Google Cloud organization or Azure tenant.

What Clovie does with a connection

Connectors are read-only. Clovie uses them to:

  • Find agent identities, such as the service accounts, roles and applications that call AI models.
  • Show AI usage that bypasses the gateway, so you can see which teams use AI without governance.
  • Suggest owners, so each discovered agent can be assigned to the right team.

Clovie never changes anything in the connected account.

How connectors sign in

Each connector asks only for what it needs, and never for your personal password:

  • Amazon Web Services: keyless. You create a role in your account that trusts a short-lived token from Clovie, issued for your organization only. No access key or external ID is stored. You can connect a single account or a whole AWS Organization.
  • Google Cloud Platform: keyless, through workload identity federation, scoped to an organization, a folder or a project. No service account key is stored.
  • Microsoft Azure: keyless. Your application trusts a short-lived token from Clovie through a federated credential, scoped to subscriptions or management groups. No client secret is stored.
  • Kubernetes: a kubeconfig for the cluster.
  • OpenAI and Anthropic: an admin API key for your organization.
  • Salesforce Agentforce, ServiceNow and Microsoft 365 Copilot: an app or integration user you create for Clovie.

For the cloud providers, Clovie gives you setup files that create exactly this trust and the permissions you chose; you run them yourself from Identity and access → Connections → Cloud connections. Select Test Connection before you save, so you know the connection works.

From discovery to governance

After a scan, discovered agents appear in AI Governance → Agents → Discovery, and AI usage that did not come through a registered agent appears in AI Governance → Agents → Shadow agents. From either list you can register the agent, give it an owner and a key, and point it at the gateway.

On this page