Console
What a security team actually opens
The fleet view, ranked by risk, with the reasons attached. Every agent here is reachable: owner, purpose, permissions, dependencies, the decisions policy made on its behalf, and the incident if there was one.
This is a seeded demonstration fleet, not live customer data. The figures are fixed so the page reads the same for everyone — but the risk scores are summed from the factors shown on each agent, not typed in, because a score you cannot take apart is the thing this product argues against.
Fleet summary
6
Agents under governance
1
Unverified — discovered, not yet claimed
2
Missing a named owner
3
Scoring 65 or above
9
Actions refused or held
1
MCP servers that changed after approval
1
Contained right now
1
Open incidents
Fleet
Ranked by risk, worst first
The agent at the top of this list is not the most important one. It is the one nobody has claimed.
- Sales Outreach AgentQuarantined
ATC-AGT-0005502 · Revenue · Google
Draft and send follow-up mail to inbound leads within one business day.
91
critical - Customer Support AutomationUnverifiedOrphaned
ATC-AGT-0007731 · Unknown · Anthropic
Undeclared. Discovered from model API traffic and an unattributed key.
88
critical - Supplier Risk AgentProduction
ATC-AGT-0004218 · Procurement · Anthropic
Analyze supplier financial risk and raise alerts for procurement managers.
72
high - Accounts Payable AgentProduction
ATC-AGT-0002094 · Finance · OpenAI
Parse supplier invoices, match them to purchase orders and queue payment runs.
64
moderate - Code Review AgentRestricted
ATC-AGT-0009140 · Engineering · Anthropic
Review pull requests for defects and policy violations, and comment on them.
47
moderate - HR Onboarding AssistantUnder ReviewOrphaned
ATC-AGT-0003377 · People · Microsoft
Assemble onboarding checklists and answer new-joiner policy questions.
38
low
Underneath
Every agent runs as something
The fleet above is the visible layer. Each agent authenticates as a machine identity that holds the actual credential, and those identities outnumber the agents — they are also where the dormant accounts, the standing secrets and the shared credentials live.
7
Machine identities
4
Holding a long-lived secret
3
Missing an owner
283
Granted actions never used
Scoring
Ten dimensions, and every one has to say why
A risk score is only useful if it can be argued with. Each agent's score is the sum of its factors, and each factor names the dimension it came from.
Privilege
How much authority does it hold, and how much of it goes unused?
Data
How sensitive is what it can reach?
Action
Can it take irreversible action?
Tool
How dangerous are the tools it can call?
Model
Is the model approved, current and hosted where policy requires?
Dependency
What is it built on, and is any of it compromised?
Behaviour
How far has it drifted from its own baseline?
External exposure
Can it reach, or be reached from, outside the organization?
Incident history
Has it been involved in something before?
Compliance
Are its reviews, owners and certifications current?
Access
Who sees this console
An auditor reads evidence and cannot change what they are examining. A developer sees their own agents. Nobody gets the whole platform by default.
Organization Owner
Everything, including delegation of these roles.
Security Administrator
Policies, agents and incidents.
AI Governance Administrator
Agent approval, certification and compliance.
IAM Administrator
Identity, authentication and access.
Data Security Administrator
Classification, data policy and egress.
SOC Analyst
Monitoring, investigation and forensics.
Auditor
Read-only access to evidence. Cannot change what it examines.
Developer
Their own agents only.
Business Owner
The agents assigned to them.