Visibility in the Age of Artificial Intelligence
As enterprises rapidly shift toward a cloud-first and AI-driven landscape, the traditional boundaries of the corporate network have dissolved. Employees are accessing sophisticated AI tools from everywhere, making the internet the primary delivery mechanism for business productivity. This transition introduces a critical challenge: a loss of visibility into network paths, user experience, and application performance.
Enter Netskope Digital Experience Management (DEM). DEM is a native component of the Netskope platform designed to provide comprehensive operational status and health visibility for all customer traffic. By leveraging a highly scalable data architecture, DEM pulls telemetry from various back-end sources to deliver real-time, actionable insights into the overall user and application experience. From monitoring tunnel status to tracking client steering and service availability, Netskope DEM ensures that IT teams maintain control in an increasingly decentralized environment. Let’s examine the proactive strategies employed by the Customer Zero team, using DEM to guarantee a high-quality experience for users interacting with AI applications.
The Enterprise AI Implementation Challenge
Organizations are currently engaged in a massive wave of AI implementation, seeking to leverage tools like AI Agents to gain a competitive edge. However, deploying AI Agents and Tools at scale is not without its hurdles. IT, Network and Security leaders must manage performance expectations, ensure consistent uptime, and maintain stringent security protocols without introducing latency that could hinder adoption. Without a robust monitoring solution, triaging performance issues can often lead to prolonged diagnostic cycles and fragmented data across complex service environments.
To address these challenges, the Netskope CustomerZero team utilizes Netskope DEM to supervise the performance of internal AI applications. Simultaneously, Netskope is employed to execute DLP protocols on interactions between users and AI agents or tools. By leveraging Netskope DEM, administrators gain a comprehensive understanding and a transparent view of performance telemetry as users engage with AI platforms such as Claude and Gemini.
You can refer here for more information of DEM Performance Metrics
Six Reasons why Netskope DEM is Essential for AI Implementation
To successfully navigate the complexities of AI deployment, organizations need a solution that bridges the gap between security and performance. Here is why the Customer Zero team feels that Netskope DEM is the recommended foundation for any organization’s AI strategy:
1. Rapid Root Cause Analysis
Determining the precise source of a slowdown—whether it stems from the application, the user's device, or the network path—remains a major hurdle in AI performance management. Netskope DEM resolves this in seconds by providing a hop-by-hop network path view. This is an example from the Netskope Customer Zero tenant where DEM mapped every segment: a fast internal network (2.8 ms to the first hop), followed by the ISP and transit carrier, leading into the Netskope Chennai POP (IN-MAA2) with a 62 ms transit-to-POP hop. By breaking down the connection (DNS at 102 ms, TCP at 3 ms, and TLS at 82 ms), administrators can immediately pinpoint if delays are local, ISP-based, or within Netskope.

This visibility, combined with endpoint telemetry like CPU, memory, and Wi-Fi signal, significantly reduces the "Mean Time to Innocence". When a user reports that an AI tool is slow, IT and Networking teams can quickly demonstrate if the LAN and Netskope paths are clean, avoiding unnecessary war rooms. Furthermore, the Server Response Time metric isolates application latency from network performance. In this instance, response times fluctuated between 238 ms and 313 ms, peaking at 11:05 am; when these metrics rise while the network remains stable, it confirms the delay is due to the model's computation, shifting the focus to the provider rather than internal infrastructure.

2. Proactive Outage Detection
Rather than reacting to a surge in support tickets, organizations can leverage Netskope DEM to flip the script on service interruptions. Through threshold-based, customizable alerting for Generative AI application blackouts and brownouts, DEM tracks critical metrics such as reachability, availability, and Time to First Byte (TTFB) on a per-site and per-app basis. This enables Network Operations Center (NOC) and IT teams to preemptively address performance issues and issue status updates before user productivity suffers. This proactive approach is fully operational within the Customer Zero environment via an alert policy titled [NOC] Generative AI Applications Performance Impact. This policy triggers a Critical alert if a Generative AI application's average TTFB exceeds 500 ms for over 30 minutes at any specific site. For instance, on 28 June 2026, this policy identified a latency issue with Google Gemini at a regional office. Once the application stabilized and TTFB fell back below the 500 ms threshold, DEM automatically resolved the alert and sent a recovery notification without requiring manual intervention (the event opened at 14:55:02 UTC and closed at 15:00:03 UTC). This automated lifecycle—detecting the brownout, notifying the appropriate team, and self-closing upon stabilization—applies to specific Generative AI tools, individual sites, and connectivity to Netskope POPs.

3. Optimized Performance via Peering
High performance is what separates an AI rollout users embrace from one they route around. Netskope's NewEdge network (AS55256) is built to peer and interconnect directly with the networks behind the major AI platforms — Google (AS15169) for Gemini, Anthropic (AS399358) for Claude, and OpenAI — along with the clouds that host them, including Microsoft and AWS. By connecting straight to these destinations' Autonomous System Numbers, NewEdge removes transit providers and the extra hops that add latency between users and the model. And we can see the payoff in Netskope’s Customer Zero telemetry rather than take it on faith. Across a full month of real, steered traffic from one of our offices to Claude, the leg from the NewEdge POP to Claude's edge completes a TCP connection in 6.6 ms and a TLS handshake in 18 ms — single-digit-millisecond round trips that are only possible over a direct or near-direct interconnect, not a multi-hop transit path. Beyond general industry benchmarks, Netskope DEM provides empirical validation of the optimized AI path by breaking down every request into its core components—including DNS, connection, TLS, POP transit, and server response time.

4. Near-Zero-Latency Security & DLP
The primary concern regarding AI adoption is potential data leakage, such as sensitive source code, customer information, or internal prompts being shared with AI tools. Netskope addresses this by deploying industry-leading AI security and inline Data Loss Prevention (DLP). With Digital Experience Management (DEM), organizations can replace vague performance assurances with concrete data such as "Transit time"—the duration a request remains within the Netskope POP for inspection. Performance data from a month of steered Google Gemini traffic from a Netskope office confirms that security does not have to come at the cost of speed. In our observation, the Netskope POP transit time was a mere 29 ms at the 90th percentile, meaning 9 out of every 10 requests clear Netskope in 29 ms or less, accounting for less than 8% of the 371 ms total time to first byte. In contrast, the application's server response time was 290 ms at P90—ten times greater than the Netskope segment. This demonstrates that the majority of end-to-end time is the application's own response generation, not the security layer, allowing users to benefit from protected interactions without experiencing performance degradation.

5. End-to-End Visibility for Self-Hosted AI (via NPA)
AI applications are not restricted to the public internet; many operate within private environments. At Netskope, our teams utilize an internally hosted AI chat tool accessed via Netskope Private Access (NPA), our Zero Trust Network Access solution. Netskope DEM provides the same granular, hop-by-hop visibility for these private paths as it does for public AI applications. While a traditional VPN might only indicate a status of "connected," DEM meticulously maps the entire private route—tracing the journey from the user's device and the Netskope gateway, through the session-brokering stitcher, past the publishers situated near the application, and finally to the host.
The technical detail makes troubleshooting immediate. In the below view, 147 active sessions leave the device with just 8 ms to the gateway, and the stitcher-to-publisher hops run a fast 4–13 ms, while the longer gateway-to-stitcher leg carries the bulk of the path at ~233–247 ms — so if the tool ever feels slow, we know exactly which segment to examine instead of guessing. DEM also shows how the load stays balanced and resilient across four publishers — handling 6, 54, 77, and 10 sessions respectively, each independently monitored — so an overloaded or unhealthy publisher surfaces before it can degrade the experience. The outcome is that our private, self-hosted AI tool is held to the same standard as our public AI apps: measured connection paths, per-hop latency, and continuous publisher health, all in one view.

6. Data-Driven Consolidation
AI sprawl is a natural byproduct of organizational experimentation. As various teams independently adopt assistants and free-tier tools, IT departments often find themselves managing a fragmented ecosystem of overlapping applications. This lack of coordination leads to redundant licensing costs, an expanded data-leakage surface, and a lack of unified standards. Netskope replaces this uncertainty with data-driven clarity by surfacing actual usage telemetry—including session counts, active user data, and adoption trends—to provide a comprehensive inventory of all AI tools in use, specifically identifying the "shadow AI" that bypasses formal review, enabling Security, IT, and Network leaders to transition from speculative management to evidence-based oversight.
Consolidation becomes an objective process when adoption data is paired with granular performance metrics from Netskope DEM such as server response time, availability, TTFB, and regional user experience scores. Organizations can definitively identify which tools are essential, which ones deliver consistent performance across all locations, and which are underutilized or redundant. By integrating adoption, performance, and risk into a single perspective, leaders can confidently standardize on high-value tools while retiring those that are risky or duplicative. This strategic refinement results in a streamlined, high-performance portfolio characterized by reduced licensing expenditure, a narrowed attack surface, and stronger vendor leverage. Furthermore, because Netskope provides a living view of the shifting AI landscape, the portfolio remains optimized as new technologies emerge and existing ones become obsolete.
Conclusion
As Customer Zero, we have utilized our own production data to demonstrate that high-speed delivery and robust security for generative AI are complementary objectives. Netskope provides the critical visibility required to deploy AI with absolute certainty. Through NewEdge, users are positioned just milliseconds away from AI models—achieving a 6.6 ms TCP Connection time from our edge to Claude via direct provider network paths. Netskope DEM further streamlines operations with hop-by-hop diagnostics and server-response tracking, allowing IT and Networking teams to achieve a rapid "Mean Time to Innocence" by eliminating troubleshooting guesswork. Proactive, threshold-based alerts identify performance brownouts or blackouts before users file tickets, automatically resolving once service levels stabilize. Furthermore, comprehensive inline inspection and DLP add only tens of milliseconds to the process—a mere fraction of the model's compute time—ensuring that protection never compromises the user experience. By leveraging continuous performance and usage data, organizations can transform fragmented AI sprawl into a streamlined, high-efficiency portfolio. This represents the ideal for secure AI adoption: a fast, resilient, observable, and protected environment that we validate daily through our own reliance on the Netskope platform.



