Agent Trust Discover
Find the AI agents, copilots, service accounts and machine identities already operating in the organization, without asking anyone to register them first.
What it does
Capabilities
- Connectors across AI platforms, cloud, identity providers, source control, enterprise applications and infrastructure
- Shadow agent discovery from model API traffic, AI keys, MCP configuration, SDK dependencies and automation credentials
- An inventory record per agent: owner, purpose, model, framework, tools, MCP servers, data sources, permissions and secrets
- Ten lifecycle statuses from Discovered through Quarantined and Retired
What it leaves behind
Evidence produced
- A first-day discovery report naming agents nobody had registered
- An unregistered-agent alert with provider, data reach and risk
The ten statuses an agent can hold
An agent is discovered long before it is governed, and the first three statuses all describe something that is already running. That is the uncomfortable part of discovery: finding it does not stop it.
- Discoveredcan act
Found by a connector or a traffic signal. Nobody has claimed it yet.
- Unverifiedcan act
Known to exist, but its owner, purpose and reach are still unconfirmed.
- Registeredcan act
Entered in the registry with an identity, and attached to a person.
- Under Reviewlimited
Its permissions, data reach and dependencies are being assessed.
- Approvedlimited
Reviewed and cleared, but not yet running production traffic.
- Productioncan act
Operating under policy, monitored, and inside its certification.
- Restrictedlimited
Still running, with specific capabilities withdrawn after a finding.
- Suspendedcannot act
Stopped pending a decision. Credentials held, evidence retained.
- Quarantinedcannot act
Contained during an incident. Tokens revoked, sessions closed, evidence preserved.
- Retiredcannot act
Decommissioned. Its record and evidence outlive it for the retention period.
Specification
Where this is specified
2 blueprint pages carry the specification for this module.
Agent Discovery
Discovery is the entry point because enterprises cannot govern agents they do not know exist. The engine should combine API enumeration, cloud metadata, identity/service-account analysis, source-code/config scanning and observed runtime traffic to identify both sanctioned and shadow agents.
LANDING FEATURE →
Agent Registry
The registry is the system of record for agent identity, ownership, purpose, risk and lifecycle. It should feel like a purpose-built CMDB for autonomous software, but with dynamic fields for models, tools, delegation, policies and business intent.
SYSTEM OF RECORD →
13 modules and services make up the platform. See how they fit together.