How to govern Security in Gemini
A step-by-step guide to governing Security in Gemini with Rencore: detect, review by owner and severity, and remediate with an audit trail.
Governing Security in Gemini means finding where it goes wrong, reviewing the findings by owner and severity, and remediating with an audit trail. Rencore covers this concern for Gemini with the pre-built controls below, so it becomes a repeatable check rather than a one-off cleanup. The steps that follow apply the same detect, review, remediate loop to Security.
Steps
-
Inventory Gemini
Connect Gemini and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.
-
Detect with policies
Turn on the pre-built policies that cover Security in Gemini to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.
-
Review by owner and severity
Use the Gemini reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.
-
Remediate and automate
Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.
Gemini controls for Security
Grounded in the Rencore catalog. See the full Gemini catalog on the Gemini connector page.
-
Gemini user is an external identity
External (guest) users are a more probable attack vector, raising the likelihood that reachable Vertex AI resources are exploited
Severity: Medium -
Gemini notebook runtime is running
Running notebook runtimes are a live, reachable compute surface, raising the likelihood that any weakness is exploited
Severity: Medium -
Gemini endpoint is serving traffic
Endpoints with deployed models are a live, callable prediction surface, raising the likelihood that any weakness is exploited
Severity: Medium -
Gemini model is deployed and live
Models deployed to endpoints are actively serving predictions, raising the likelihood that any weakness is exploited
Severity: Medium -
Gemini engine is live with data stores
Engines connected to data stores actively serve content to callers, raising the likelihood that any weakness is exploited
Severity: Medium -
Gemini agent is live and in use
Agents updated within the last 90 days are live, callable surfaces, raising the likelihood that any weakness is exploited
Severity: Medium -
Gemini user is deactivated in Entra ID
Detects Gemini users who are deactivated in the parent Entra ID
Severity: Medium -
Gemini user is external user in Entra ID
Detects Gemini users which are guest in the Entra ID directory
Severity: Medium -
Gemini notebook runtime in unhealthy state
Detects notebook runtimes that are reporting an unhealthy health state
Severity: High -
Gemini agent not updated in 90 days
Detects deployed reasoning engines (agents) that have not been updated in the last 90 days
Severity: Medium -
Gemini agent without description
Detects deployed reasoning engines (agents) that have no description set
Severity: Low