This feature is not available in Cyera for Government environments.
To enable Agent Security prompt analysis and AI discovery for Gemini Enterprise Agent Platform (formerly Vertex AI), Cyera needs read access to your Gemini Enterprise Agent Platform invocation logs. Gemini Enterprise Agent Platform writes those logs to a BigQuery table, and Cyera reads that table to provide visibility into AI model usage, including prompts, responses, and caller identity.
This guide covers the four things needed to make that work:
- Configuring BigQuery slot-based billing, so Cyera's recurring collection queries run at a fixed, predictable cost.
- Enabling Agent Platform request-response logging to BigQuery.
- Setting the BigQuery billing project Cyera runs its queries in, and granting it two additional roles.
- Providing the project, dataset, and table details to Cyera.
Note: Agent Platform logging is configured per project, region and model, so repeat Step 2 for every model, region and GCP project that uses Agent Platform. The slot reservation and the billing project can be shared across all of them.
Prerequisites
Before you begin, ensure you have:
- Cyera DSPM installed, with the GCP organization or project already connected to Cyera. If not, complete the GCP SaaS Deployment Guide first.
- Permission in the GCP project to enable APIs, create BigQuery reservations, and change Agent Platform settings.
- The following APIs enabled in the GCP project where AI models are used — check each under APIs & Services → Library in the GCP Console and click Enable if it is not already active:
- Agent Platform API
- BigQuery API
- BigQuery Reservation API — required for the slot-based billing setup in Step 1
Step 1 — Configure BigQuery slot-based billing
Why this is required
Cyera's collection runs periodic queries against the BigQuery logging table to read Agent Platform invocation logs. BigQuery offers two billing models for queries:
| Billing model | How it works | Cost structure |
|---|---|---|
| On-demand (default) | Pay per bytes scanned by each query | ~$6.25 per TB scanned |
| Editions (slot-based) | Reserve dedicated compute capacity (slots) | Flat rate for reserved slots |
With on-demand billing, every collection query incurs a per-TB charge. Because Cyera queries the logging table on a regular schedule, on-demand billing creates unpredictable and potentially significant costs. Slot-based billing is required, so that collection queries run against reserved capacity at a fixed cost.
How many slots are needed?
Cyera's collection queries are lightweight — they read recent rows from a time-partitioned table. Recommended configurations:
| Scenario | Baseline slots | Max slots (autoscale) | Edition |
|---|---|---|---|
| Cyera collection only (no other BigQuery workloads) | 0 | 50 | Standard |
| Cyera + light analytics | 50 | 100 | Standard |
| Cyera + heavy BigQuery usage | 100+ | 400+ | Enterprise |
Note: If you already use BigQuery Editions for other workloads, you likely already have a reservation — skip to Create an assignment and create an assignment for your billing project.
Create a reservation
- In the GCP Console, navigate to BigQuery (from the left navigation menu).
- In the left panel, click Workload management.
- Open the Slot reservations tab.
- Click Create reservation.
- Fill in the fields:
-
Reservation name — for example
cyera-collection. -
Location — the region that matches your BigQuery logging dataset (for example
us (multiple regions in United States), or a specific region such asus-east1). - Edition — Standard is sufficient for Cyera collection. Choose Enterprise only if you need advanced features such as BigQuery ML or a higher SLA.
- Max reservation size — Extra Small (50 slots) or higher. This sets the autoscale ceiling; you are billed for slots actually used, not the maximum.
-
Baseline slots (optional) — set to
0if the reservation is used only for Cyera collection. Baseline slots are always on and always billed; autoscale slots spin up on demand.
-
Reservation name — for example
- Click Save.
Using the bq CLI instead:
bq mk \ --reservation \ --project_id=PROJECT_ID \ --location=LOCATION \ --edition=STANDARD \ --slots=0 \ --autoscale_max_slots=50 \ cyera_collection
Commitment options: By default, autoscale slots use pay-as-you-go pricing — no commitment, billed per second of use. For lower rates you can purchase a 1-year (20% discount) or 3-year (40% discount) commitment under Workload management → Slot commitments → Buy commitment. This is optional for Cyera collection.
Create an assignment
The assignment binds the reservation to your billing project — the project Cyera runs its collection queries in, covered in Step 3 — so that those queries use the reserved slots instead of on-demand billing.
BigQuery selects the reservation based on the project the query job runs in, not the project holding the data, so the assignment must target the billing project. If your billing project is the same project as the Agent Platform logging dataset — the default — assign it to that project.
Reservations can also be administered centrally: a reservation created in a dedicated admin project and assigned to the billing project, or to a parent folder or organization, works too. Cyera resolves the assignment through the resource hierarchy.
- In the Slot reservations tab, find the reservation you created.
- In the Actions column, open the three-dot menu and select Create assignment.
- Under Select an organization, folder or project, click Browse and select the billing project (see Step 3).
- Set Job type to
QUERY. - Click Create.
Using the bq CLI instead:
bq mk \ --reservation_assignment \ --project_id=PROJECT_ID \ --location=LOCATION \ --reservation_id=PROJECT_ID:LOCATION.cyera_collection \ --assignee_id=PROJECT_ID \ --job_type=QUERY \ --assignee_type=PROJECT
Important: After creating an assignment, wait at least 5 minutes before running queries. The assignment takes time to propagate, and queries run before propagation completes fall back to on-demand billing.
Verify slot-based billing is active
Run a test query:
bq query \ --project_id=PROJECT_ID \ --use_legacy_sql=false \ --format=json \ 'SELECT 1'
Then check the job's reservation usage:
bq show --format=prettyjson -j <JOB_ID> | grep -A2 reservation
If reservation_id shows your reservation name — rather than unreserved — slot-based billing is active.
For full details on BigQuery capacity pricing, see Introduction to BigQuery editions and Get started with reservations.
Step 2 — Enable Agent Platform data logging
Agent Platform can log all model invocation requests and responses to a BigQuery table. This is the data source Cyera reads.
Enable request-response logging
Before running the command, create a BigQuery dataset if you do not already have one (for example vertex_ai_logs). Create it in the same region as the reservation from Step 1, and in the same project where the Agent Platform models run.
Enable logging by calling the REST API:
curl -X POST \
"https://REGION-aiplatform.googleapis.com/v1beta1/projects/PROJECT_ID/locations/REGION/publishers/google/models/MODEL_ID:setPublisherModelConfig" \
-H "Authorization: Bearer $(gcloud auth print-access-token)" \
-H "Content-Type: application/json" \
-d '{
"publisherModelConfig": {
"loggingConfig": {
"enabled": true,
"bigqueryDestination": {
"outputUri": "bq://PROJECT_ID.DATASET_NAME"
}
}
}
}'For example: REGION=us-central1, MODEL_ID=gemini-2.5-flash.
Note: setPublisherModelConfig is only available on the v1beta1 API. Calling it on /v1/ returns an HTML 404.
A successful call returns an operation, for example:
{ "name": "projects/123456789/locations/us-central1/operations/790178...", ... }Data governance notice: When request-response logging is enabled, both the full prompt (input) and the full completion (output) are stored in the BigQuery table. This includes any sensitive data users send to, or receive from, AI models. Confirm this is acceptable under your organization's data governance policies before enabling.
Verify logging is active
After enabling logging, make a test Agent Platform API call — any model invocation. Then:
- Navigate to BigQuery → SQL workspace.
- In the Explorer panel, expand your project and the logging dataset.
- You should see a table. Agent Platform creates the table automatically and derives its name from the model publisher and configuration.
- Click the table and select Preview to confirm rows are appearing.
Logging table schema
The BigQuery logging table contains the following columns:
| Column | Type | Description |
|---|---|---|
logging_time |
TIMESTAMP | When the response completed |
request_id |
NUMERIC | Unique identifier per invocation |
model |
STRING | Model path — for example publishers/anthropic/models/claude-opus-5
|
request_payload |
REPEATED STRING | Request body — used by partner models such as Claude |
response_payload |
REPEATED STRING | Response body — used by partner models such as Claude |
full_request |
JSON | Structured request — used by Gemini models |
full_response |
JSON | Structured response — used by Gemini models |
metadata |
JSON | Call metadata, including latency |
api_method |
STRING | API method used |
The table is partitioned by hour on logging_time.
Step 3 — Configure the BigQuery billing project for Cyera
Cyera runs its collection queries in the billing project — also called the cost project. The query jobs, the slot usage, and the cost all belong to it. The logging table itself always stays in the project where Agent Platform models run; the data never moves.
The billing project can be the project where Agent Platform models run (the default), a dedicated Cyera billing project, or an existing central billing project — but it must be the project you targeted with the slot reservation assignment in Step 1.
The Cyera DSPM service account created during your initial GCP onboarding already has the permissions needed to read BigQuery data (roles/bigquery.dataViewer). Two additional roles are required on the billing project only:
| Role | Why it is needed |
|---|---|
BigQuery Job User (roles/bigquery.jobUser) |
Lets Cyera run query jobs in the billing project. Without it, collection fails with Access Denied: bigquery.jobs.create before any data is read. This role is not part of the standard DSPM deployment. |
BigQuery Resource Viewer (roles/bigquery.resourceViewer) |
Lets Cyera verify the slot reservation assignment before collecting (bigquery.reservationAssignments.search), so queries never silently fall back to on-demand billing. |
To grant them:
- Go to IAM & Admin → IAM in the billing project.
- Add the Cyera service account with the BigQuery Job User and BigQuery Resource Viewer roles.
For general background on billing projects, see GCP Billing Project for BigQuery Scans — Deployment Guide.
Important — the logging table cannot live in the billing project. GCP accepts a request-response logging destination in a project other than the model project, but the log rows are silently never delivered there (verified September 2026). Always create the logging dataset in Step 2 in the same project where the Agent Platform models run. If the two projects differ, only the query jobs run in the billing project — cross-project reads are handled automatically and need no setup beyond the two roles above.
Deployment level: The two roles above are needed on the billing project regardless of whether DSPM was deployed at the organization or the project level — neither deployment mode includes them. Organization-level deployment covers reading the logging table in any project. Project-level deployment requires the project where Agent Platform models run to be a DSPM-connected project — that is where the read permission comes from.
Step 4 — Provide details to Cyera
Once the steps above are complete, share the following with your Cyera account team:
| Item | Example / notes |
|---|---|
| GCP project ID | my-project-123456 |
| BigQuery dataset name | vertex_ai_logs |
| BigQuery table name | The table created by Agent Platform logging — visible in the dataset after enabling logging and making at least one model invocation |
| Billing project ID — if different from the GCP project ID |
my-billing-project — the project holding the slot reservation assignment and the two extra roles from Step 3
|
| Confirmation that slot-based billing is configured | Edition, number of reserved slots, and that the assignment is bound to the billing project |
Cyera uses this information to configure collection for your environment.
Verification
To confirm logging is producing data:
- Make one or more Agent Platform API calls — for example, a prompt to any model.
- Wait 2–5 minutes for the data to appear in BigQuery. There is a short ingestion delay.
- Navigate to BigQuery → SQL workspace.
- Run the following query:
SELECT logging_time, request_id, model FROM `PROJECT_ID.DATASET_NAME.TABLE_NAME` ORDER BY logging_time DESC LIMIT 10
If rows appear, logging is working correctly.