Security policies continuously evolve.
New applications are deployed, network segments change, temporary exceptions become permanent, and new Access Control rules are added to support changing business requirements.
Over time, this can create policy drift - where the policy enforced by the gateways no longer fully reflects the organization's intended segmentation model.
Finding these gaps manually can be difficult, especially across large rulebases with hundreds or thousands of rules.
AI Auditor helps administrators validate Access Control policies against defined network segmentation guidelines, providing a visual way to identify where actual policy enforcement no longer aligns with organizational intent.

How AI Auditor Works
AI Auditor connects two important elements of policy management: the organization's intended segmentation model and the Access Control policy that actually enforces it.
Administrators define network segments and specify how those segments are expected to communicate. AI Auditor then calculates the selected Access Control policy against these guidelines and presents the results through a visual segmentation matrix.
This creates a simple operational workflow:
Define segmentation intent -> Calculate the policy -> Identify violations -> Investigate the relevant rules -> Approve justified exceptions or remediate the policy
Instead of reviewing the entire Rule Base manually, administrators can focus their attention on the communication paths and rules that do not match the expected segmentation model.
Define the Intended Segmentation Model
AI Auditor starts with something security teams already understand - how different parts of the network should communicate.
Administrators define the relevant network segments and specify the expected communication between them.
For each relationship, the guideline can define whether:
- All traffic is allowed
- All traffic is not allowed
- The decision should be made later
AI Auditor represents these relationships in a matrix, where each cell describes the expected access between two network segments.
This creates a clear baseline representing the organization's intended segmentation model.

Validate the Policy Against Security Intent
Once the segmentation guidelines are defined, AI Auditor calculates the Access Control policy and identifies the rules associated with each communication path.
Instead of manually reviewing the Rule Base and trying to determine whether every rule follows the segmentation architecture, administrators can use the matrix to quickly identify areas that require attention.
For each communication path, AI Auditor provides visibility into:
- All rules associated with the selected segments
- Rules that violate the defined segmentation guidelines
- Violations that were previously reviewed and approved
This turns a potentially complex rulebase review into a much more focused auditing workflow.
Investigate Violations and Unintended Access Paths
When a rule does not comply with the defined guidelines, AI Auditor identifies it as a violation.
Administrators can select the relevant cell in the matrix and investigate the rules responsible for the communication between those network segments.
The Violating Rules view provides the information needed to understand why the access exists and determine whether the rule should remain.
From there, administrators can modify supported rule properties directly or navigate to the Access Control Rule Base for additional changes.
This provides a direct path from:
Segmentation intent -> Policy validation -> Violation -> Relevant rule -> Remediation
Rather than searching through the entire policy, administrators can focus directly on the rules that do not match the expected access model.
How AI Auditor Helps in Daily Operations
This becomes particularly useful as part of ongoing policy management.
After policy changes, new application deployments, network segmentation changes, or the introduction of new access requirements, administrators need to understand whether the resulting Rule Base still follows the organization's intended security model.
AI Auditor provides a focused way to perform that validation without repeatedly reviewing the complete Access Control policy.
For example, an administrator can use AI Auditor to:
- Check whether a newly introduced rule creates communication between segments that should remain isolated
- Investigate unexpected access paths without manually searching through the entire Rule Base
- Review policy changes against the organization's established segmentation guidelines
- Separate legitimate business exceptions from violations that still require remediation
- Revisit approved exceptions as the environment and business requirements evolve
This helps move policy auditing from a large manual review exercise toward a more focused and repeatable operational process.
Manage Legitimate Exceptions Without Losing Visibility
Not every violation means that a rule is incorrectly configured.
There may be legitimate business requirements that require communication between segments that would normally be restricted.
AI Auditor allows administrators to approve a violation and document the reason for the exception. The approval can apply to the selected relationship or, when appropriate, across the guideline.
Approved violations remain visible separately from active violations, helping security teams distinguish between known exceptions and access that still requires investigation.

Administrators can also filter calculated results by service, making it easier to investigate specific types of communication between network segments.
For example, a security team reviewing administrative access could filter the results for a specific service and immediately see the rules and violations associated with that traffic.
From Policy Auditing to Continuous Validation
The operational value of AI Auditor goes beyond identifying individual problematic rules.
It provides a repeatable way to compare the policy you intended to enforce with the policy that is actually configured.
Administrators can define segmentation guidelines, calculate the policy against them, investigate violations, document justified exceptions, and remediate rules that no longer meet organizational requirements.
Policy Auditor can also automatically recalculate guidelines every 24 hours, helping teams reassess the policy as the environment and Rule Base evolve.
The result is a more structured approach to:
- Validate network segmentation
- Identify unintended access paths
- Reduce policy drift
- Maintain policy consistency
- Strengthen Zero Trust enforcement
- Simplify policy reviews and audit preparation
Together with AI Insights, AI Auditor extends Check Point's approach to continuous policy optimization: AI Insights helps administrators identify opportunities to tighten and optimize security policies, while AI Auditor validates whether Access Control policies continue to follow the organization's defined segmentation intent.
Instead of asking:
"Which rules should I review?"
security teams can focus on the more important question:
"Does the policy we enforce still match the security architecture we intended?"
Learn More
Explore the official Check Point documentation for AI Auditor / Policy Auditor and Check Point AI-powered Security Management to learn more about policy validation, segmentation guidelines, and continuous policy optimization.
For additional demonstrations and explanations, watch these videos:
▶️ Part 1 - Policty Auditor Introduction
▶️ Part 2 - Policy Auditor Configuration
▶️ Part 3 - Policy Auditor In Action
Technical Marketing Engineering Team