Related Big Read: The enterprise agent economy has no audit trail
Related assets: Shadow agents as shadow workforce risk; The permission-based attack surface; Agentic blast radius
You cannot control what you do not know. For AI agents, a simple inventory is the first control layer for non-human authority.
AI agents are appearing in the enterprise faster than organisations can inventory and govern them.
Some are sanctioned. Some are embedded in SaaS platforms. Some sit in developer environments. Some are little more than scripts with model access. Others can query data, call APIs, trigger workflows, or act on behalf of users.
Together they form an unaudited agent economy.
The first governance failure is often simple: nobody can produce a reliable list of agents.
Why an agent inventory matters
Traditional asset inventories were built around devices, applications, users, and services.
Agents do not fit neatly into those categories. They may exist as features, automations, connectors, tools, workflow steps, or model-mediated interfaces. They may inherit human access or operate through service accounts. They may query data in ways that existing role-based access control (RBAC) models do not distinguish or constrain.
If the organisation cannot identify agents, it cannot scope them. If it cannot scope them, it cannot monitor them. If it cannot monitor them, it cannot revoke them under pressure.
An agent inventory is not administration for its own sake. It is a control.
Use this toolkit to establish a reliable view of non-human authority. Follow the steps in this toolkit in sequence. Start with the agents that can reach sensitive systems or data, then record their owners, permissions, behaviour, and revocation path.
The toolkit
Enumerate agents
List sanctioned and suspected agents across SaaS platforms, developer tools, data platforms, workflow engines, local agent frameworks, and security tooling.
- Owner
- Business purpose
- Systems accessed
- Data classes reached
- Tool calls available
- Credential or identity used
- Review cadence
Test RBAC fit
Ask whether current access roles were designed for a human, a service account, or a model-mediated query actor. If the role gives the agent more reach than the task requires, it is not fit for purpose.
Scope query behaviour
Record what the agent normally asks for, retrieves, transforms, exports, or acts on. Monitor deviations in query volume, sensitivity, target system, and timing.
Prioritise by data sensitivity
Start with agents touching regulated, customer, financial, security, HR, source-code, or crown-jewel operational data.
Build the registry
A minimum viable registry should show where non-human authority exists, what it can reach, what it can do, and how it can be revoked.
- Agent name
- Owner
- Identity
- Permissions
- Systems reached
- Data class
- Actions available
- Monitoring owner
- Revocation path
Best first step
Enumerate agents touching the highest-priority systems and apply rate limits or access narrowing where an agent can query sensitive data at scale.
Maturity path
The executive test
Ask for the agent register.
If the answer is a product list, a vendor list, or a policy document, the organisation is not ready.
The register should show where non-human authority exists, what it can reach, and how it is revoked.