Views:
Zero Trust Secure Access (ZTSA) AI secure access can be configured in Zscaler (as proxy chain) to protect AI part.
Selected GenAI (Claude, Gemini, OpenAI…) configured in Zscaler to forward to ZTSA AI secure access for AI traffic inspection & access control.
And it will request end user to authenticate while traffic is forwarded to ZTSA (treat as roaming, default proxy case).

Procedure

  1. Ensure Zscaler has HTTPS inspection enabled.
  2. Configure the upstream proxy in ZScaler and point it to SWG Cloud GW FQDN.
  3. Apply the ZTSA CA to this proxy.
  4. Specify what traffic needs to be forwarded to ZTSA AI secure access (Upstream proxy). Zscaler has AI related service/app category, we just use them directly.
  5. (Optional) It can also support to stamp X-Authenticated-User header if required, but right now SWG cloud GW will just ignore it even if header contains this:

Next steps

The ZTSA default cloud gateway will redirect the end-user to complete the end-user authorization if it has not yet been authorized by SWG.