Start Here

Begin with Synoptikon

A short guide to Synoptikon, organised around Big Reads, Explainers, Perspectives, and Workbench.

What is Prompting Trust?

The weekly companion to Synoptikon, for current developments and shorter notes.

Feeds

Follow Synoptikon by feed, email, or curated sources without relying on the homepage.

The unaudited agent economy

A high-level toolkit for creating an inventory of AI agents and their permissions

Related Big Read: The enterprise agent economy has no audit trail

Related assets: Shadow agents as shadow workforce risk; The permission-based attack surface; Agentic blast radius

You cannot control what you do not know. For AI agents, a simple inventory is the first control layer for non-human authority.

AI agents are appearing in the enterprise faster than organisations can inventory and govern them.

Some are sanctioned. Some are embedded in SaaS platforms. Some sit in developer environments. Some are little more than scripts with model access. Others can query data, call APIs, trigger workflows, or act on behalf of users.

Together they form an unaudited agent economy.

The first governance failure is often simple: nobody can produce a reliable list of agents.

Why an agent inventory matters

Traditional asset inventories were built around devices, applications, users, and services.

Agents do not fit neatly into those categories. They may exist as features, automations, connectors, tools, workflow steps, or model-mediated interfaces. They may inherit human access or operate through service accounts. They may query data in ways that existing role-based access control (RBAC) models do not distinguish or constrain.

If the organisation cannot identify agents, it cannot scope them. If it cannot scope them, it cannot monitor them. If it cannot monitor them, it cannot revoke them under pressure.

An agent inventory is not administration for its own sake. It is a control.

Use this toolkit to establish a reliable view of non-human authority. Follow the steps in this toolkit in sequence. Start with the agents that can reach sensitive systems or data, then record their owners, permissions, behaviour, and revocation path.

The toolkit

Enumerate agents

List sanctioned and suspected agents across SaaS platforms, developer tools, data platforms, workflow engines, local agent frameworks, and security tooling.

  • Owner
  • Business purpose
  • Systems accessed
  • Data classes reached
  • Tool calls available
  • Credential or identity used
  • Review cadence

Test RBAC fit

Ask whether current access roles were designed for a human, a service account, or a model-mediated query actor. If the role gives the agent more reach than the task requires, it is not fit for purpose.

Scope query behaviour

Record what the agent normally asks for, retrieves, transforms, exports, or acts on. Monitor deviations in query volume, sensitivity, target system, and timing.

Prioritise by data sensitivity

Start with agents touching regulated, customer, financial, security, HR, source-code, or crown-jewel operational data.

Build the registry

A minimum viable registry should show where non-human authority exists, what it can reach, what it can do, and how it can be revoked.

  • Agent name
  • Owner
  • Identity
  • Permissions
  • Systems reached
  • Data class
  • Actions available
  • Monitoring owner
  • Revocation path

Best first step

Enumerate agents touching the highest-priority systems and apply rate limits or access narrowing where an agent can query sensitive data at scale.

Maturity path

Level 1: register

An agent registry exists and is reviewed quarterly.

Level 2: observe

Query behaviour monitoring operates on all LLM-accessible APIs.

Level 3: enforce

Automated scoping enforcement limits agent access to the task rather than an inherited role.

The executive test

Ask for the agent register.

If the answer is a product list, a vendor list, or a policy document, the organisation is not ready.

The register should show where non-human authority exists, what it can reach, and how it is revoked.

Previous Post
The enterprise agent economy has no audit trail - featured image

The enterprise agent economy has no audit trail

Next Post
The blast radius problem: how agentic AI broke the permissions model - featured image

AI blast radius: how agentic AI is breaking the permissions model

Subscribe to Prompting Trust

Subscribe to Prompting Trust to receive The Weekly Context.

Prompting Trust is the newsletter layer connected to Synoptikon. It carries current developments, useful links, and shorter notes, while Synoptikon holds the longer arguments and working library.

Learn more about Prompting Trust.