Discovery tools find the AI agents running in your organisation. Each type sees a different slice, and none sees everything.
This guide compares the five types, shows how to test one in a week, and explains how to add web activity by page type using an AI agent allow list.
A good tool answers four questions about every agent it finds. Most tools answer the first two well and the last two poorly.
Questions three and four matter most for security. An agent that exists but only reads documentation is a registration task. An agent that signs up for services with no owner is an incident waiting to happen.
Where it runs and when it was first seen.
Its keys, grants and connected systems.
Which tools it calls and which web pages it opens.
A probable owner, so someone can decide its fate.
Types are named by where they look. A product may combine two or three of them.
Where a tool looks decides what it can find. That is why the same estate produces very different lists from different tools.
Scan cloud accounts for AI services, models and agent runtimes.
Read SaaS admin settings and OAuth grants.
Inventory service accounts, keys and tokens.
Watch traffic to model APIs and the web.
See extensions, local agents and AI browsers on devices.
Page-type data added to any of the five, so web activity shows login, signup and checkout attempts, not just URLs.
Green means the type usually covers the source well, yellow partly, red rarely. Use it to spot gaps in the tools you already own.
No row is green everywhere. Pair a network view with an identity or SaaS view to cover most agents.
Check the tools you already own against this grid before buying anything new. Many teams find they already cover four or five of the seven sources.
Ask these in the first call. The answers show quickly whether a product fits your agents.
Write the answers down. Comparing two vendors side by side on these ten questions usually makes the choice obvious.
Model calls plus self-directed steps are the usual test.
Ask for a list, not a diagram.
They are often the largest group.
URLs alone are not enough. Ask for page types.
Ownership is the first thing triage needs.
Findings must flow into governance.
New agents appear weekly.
Read-only access should be enough.
Or do you only report? Both are valid, but know which.
Discovery tools see sensitive configuration.
Plant known agents before the trial starts. Then you can measure what the tool finds instead of trusting its dashboard.
Keep the planted agents harmless: point the signup-trying bot at a test site you control.
A script on a server, a cloud agent, a SaaS agent, a browser extension, and one that tries a signup page.
Give the tool the minimum access it asks for.
Count planted agents found, and real agents found that nobody knew about.
Did it flag the signup attempt as a signup, or just as a URL?
Planted agents found, unknown agents found, owners suggested, false alarms.
Before buying anything, a week with your own proxy logs finds most server-side agents.
Server-side agents, scheduled scripts, forgotten pilots.
Vendor agents inside SaaS and agents that never leave the network.
A few days of an analyst's time, plus page-type lookups.
The model API domains and patterns shown are placeholders. Use your own list of AI service domains.
Run the same commands every week and compare the lists. New sources are your new agents.
Two agents can make the same number of requests. What they request is what separates harmless from urgent.
900 requests to pricing, documentation and status pages.
Register it and move on.
40 requests, including 6 signups, 2 uploads and a comment.
Pause it today and find the owner.
Without page types, both look like "an agent browsing the web". With them, triage takes seconds.
Ask any discovery vendor to show you this view during the trial. If they cannot, plan to add page-type tagging yourself.
Discovery is only useful if something happens next. Four steps close the loop.
The last step is what keeps discovery cheap over time. Once unregistered agents cannot reach the web, they report themselves.
Owner known? Touching action pages? Decide within days.
Every kept agent gets a registry entry.
Every registered agent gets a web policy at the proxy.
Unregistered agent identities lose web access, so new ones surface.
These show up after the contract is signed. Check for them during the trial instead.
Each one is easy to test for in a week, and expensive to discover after a year.
The demo shows cloud agents. Your agents live in SaaS.
A thousand findings without owners is noise.
You find agents but cannot tell which ones are acting.
Findings live in one tool, rules in another, and they never meet.
A tool that needs write access to find things is a new risk.
Discovery must run continuously to stay true.
Many teams start with their own logs and buy a tool once the number of agents grows.
The table suggests a starting point for five common situations. Most estates match one of them closely.
| Situation | Start with | Add later |
|---|---|---|
| Fewer than 20 agents, mostly in-house | Proxy logs plus page-type tagging | An identity view of agent keys |
| Heavy use of SaaS with built-in agents | A SaaS security tool | Network view for server agents |
| Agents built mainly in one cloud | Cloud AI posture tool | SaaS and browser views |
| Many staff using AI browsers and extensions | Endpoint and browser tool | Proxy page-type policy |
| Regulated, large estate | Two tool types plus logs | Registry integration and default-deny |
Track these monthly, whatever tool or method you use. Falling times and rising registration show real progress.
Should rise at first, then settle.
Days from finding to a confirmed owner.
Found agents that made it into the registry.
Found agents that touched signup, checkout or upload pages.
Short definitions for teams new to agent discovery and its vocabulary.
Finding agents from evidence rather than asking people.
A test agent you create to check whether a tool finds it.
Adding context, such as page types, to raw findings.
An agent built into a product you buy, acting for your staff.
Permissions to look, never to change.
Blocking web access for any agent not registered.
A composite of a typical seven-day proof of value, not a specific product. Use it as a template for your own trial plan.
A server script, a cloud agent, a SaaS agent, a browser extension and a signup-trying bot.
Cloud accounts, identity provider and proxy logs connected. No write access granted.
The browser extension was missed, which shows the tool's blind spot clearly.
Several unknown agents appeared, two of them with no owner.
The signup bot showed as "signup attempts" only after page-type tagging was added.
Buy, pair with an endpoint view for extensions, and link findings to the registry.
Discovery touches several teams' systems. Agree clear roles before the first scan starts.
| Task | Security operations | Identity team | SaaS administrators | AI platform team |
|---|---|---|---|---|
| Run network discovery | Does it | Informed | Informed | Informed |
| Export keys and grants | Reviews | Does it | Consulted | Informed |
| Check SaaS agent settings | Reviews | Informed | Does it | Informed |
| Confirm owners | Leads | Helps | Helps | Helps |
| Register kept agents | Informed | Informed | Informed | Does it |
Discovery projects stall for predictable reasons. These answers keep them moving.
It likely sees SaaS use by people. Ask whether it separates agents from people, and whether it knows page types.
It covers cloud-built agents. Vendor agents and browser extensions usually sit outside its view.
Filter to model API calls and headless browsers first. The list becomes short quickly.
Agents multiply faster than quarters pass. A one-week log sweep is a cheap start.
Costs are mostly people's time. Tools reduce the time, but they never remove it entirely.
A few days for a first log sweep, then a few hours a week.
Minutes per agent to confirm ownership and purpose.
Varies widely by type and estate size. Compare against analyst hours saved.
API from $99 a month, or an on-premise database for large volumes.
The honest fine print — the same two assumptions we publish, plus two operational ones
Page types for 40M+ domains, added to the logs you already have.