AI Agent Allowlist
Home Page-Types Database Agent Guardrails 2026 Incidents API Docs Pricing
Resources
Use Cases (15) Industries & Buyers (12) Learn: Core Concepts (12) Implementation Guides (15) Comparisons (8) Agent Security Guides (22) Market & Frameworks (9) Schema & Data Reference (6) FAQ Glossary
Why It Matters
2026 Agent Incidents Category Targeting Database Refreshes Contact Customer Login
Download Free Sample
buyer's guide, no vendor rankings

AI Agent Discovery Tools

Discovery tools find the AI agents running in your organisation. Each type sees a different slice, and none sees everything.

This guide compares the five types, shows how to test one in a week, and explains how to add web activity by page type using an AI agent allow list.

5Tool types
7Sources compared
10Buyer questions
7 daysProof of value
The job

What a discovery tool should tell you

A good tool answers four questions about every agent it finds. Most tools answer the first two well and the last two poorly.

Questions three and four matter most for security. An agent that exists but only reads documentation is a registration task. An agent that signs up for services with no owner is an incident waiting to happen.

1

That it exists

Where it runs and when it was first seen.

2

What it can reach

Its keys, grants and connected systems.

3

What it actually does

Which tools it calls and which web pages it opens.

4

Who answers for it

A probable owner, so someone can decide its fate.

The market

Five types of discovery tools

Types are named by where they look. A product may combine two or three of them.

Where a tool looks decides what it can find. That is why the same estate produces very different lists from different tools.

Cloud AI posture tools

Scan cloud accounts for AI services, models and agent runtimes.

  • Strong on cloud-built agents
  • Weak on SaaS and browser agents

SaaS security tools

Read SaaS admin settings and OAuth grants.

  • Strong on vendor agents and connected apps
  • Weak on custom scripts on servers

Identity and NHI tools

Inventory service accounts, keys and tokens.

  • Strong on credentials agents hold
  • Weak on what agents do with them

Network and gateway tools

Watch traffic to model APIs and the web.

  • Strong on activity, whatever built the agent
  • Weak on agents that never leave the network

Endpoint and browser tools

See extensions, local agents and AI browsers on devices.

  • Strong on staff-facing agents
  • Weak on server-side agents

The missing enrichment

Page-type data added to any of the five, so web activity shows login, signup and checkout attempts, not just URLs.

Coverage

Which type sees which source

Green means the type usually covers the source well, yellow partly, red rarely. Use it to spot gaps in the tools you already own.

Tool type
Egress
Keys
SaaS grants
Cloud
Code
Browsers
Vendor settings
Cloud AI posture
rarely
partly
rarely
yes
partly
rarely
rarely
SaaS security
rarely
partly
yes
rarely
rarely
partly
yes
Identity and NHI
rarely
yes
yes
partly
partly
rarely
partly
Network and gateway
yes
rarely
rarely
partly
rarely
partly
rarely
Endpoint and browser
partly
rarely
rarely
rarely
rarely
yes
rarely

No row is green everywhere. Pair a network view with an identity or SaaS view to cover most agents.

Check the tools you already own against this grid before buying anything new. Many teams find they already cover four or five of the seven sources.

Buyer questions

Ten questions for any discovery tool

Ask these in the first call. The answers show quickly whether a product fits your agents.

Write the answers down. Comparing two vendors side by side on these ten questions usually makes the choice obvious.

1

How do you tell an agent from an app?

Model calls plus self-directed steps are the usual test.

2

Which of the seven sources do you read?

Ask for a list, not a diagram.

3

Do you find vendor agents in SaaS?

They are often the largest group.

4

Do you show what the agent did on the web?

URLs alone are not enough. Ask for page types.

5

How do you suggest an owner?

Ownership is the first thing triage needs.

6

Can you export to our registry?

Findings must flow into governance.

7

How often do you rescan?

New agents appear weekly.

8

What access do you need?

Read-only access should be enough.

9

Can you pause an agent?

Or do you only report? Both are valid, but know which.

10

Where does our data go?

Discovery tools see sensitive configuration.

Proof of value

Testing a tool in seven days

Plant known agents before the trial starts. Then you can measure what the tool finds instead of trusting its dashboard.

Keep the planted agents harmless: point the signup-trying bot at a test site you control.

1

Day 0: plant five test agents

A script on a server, a cloud agent, a SaaS agent, a browser extension, and one that tries a signup page.

2

Days 1 to 2: connect read-only

Give the tool the minimum access it asks for.

3

Days 3 to 5: collect findings

Count planted agents found, and real agents found that nobody knew about.

4

Day 6: check the web view

Did it flag the signup attempt as a signup, or just as a URL?

5

Day 7: score it

Planted agents found, unknown agents found, owners suggested, false alarms.

Do it yourself

Discovery with logs you already have

Before buying anything, a week with your own proxy logs finds most server-side agents.

# 1. sources that call model APIs (AI Tools Blocklist data helps recognise the domains) grep -E "model-api|llm|inference" proxy.log | awk '{print $src}' | sort | uniq -c | sort -rn # 2. sources that use headless browsers grep -i "headless" proxy.log | awk '{print $src}' | sort -u # 3. tag every URL those sources opened with its page type agent-egress-guard check "$URL" --api-key $KEY --json # page_type: signup, checkout, upload...

What it finds

Server-side agents, scheduled scripts, forgotten pilots.

What it misses

Vendor agents inside SaaS and agents that never leave the network.

What it costs

A few days of an analyst's time, plus page-type lookups.

The model API domains and patterns shown are placeholders. Use your own list of AI service domains.

Run the same commands every week and compare the lists. New sources are your new agents.

Web activity

Why page types matter in discovery

Two agents can make the same number of requests. What they request is what separates harmless from urgent.

Agent A

900 requests to pricing, documentation and status pages.

Register it and move on.

Agent B

40 requests, including 6 signups, 2 uploads and a comment.

Pause it today and find the owner.

Without page types, both look like "an agent browsing the web". With them, triage takes seconds.

Ask any discovery vendor to show you this view during the trial. If they cannot, plan to add page-type tagging yourself.

After discovery

Turning findings into control

Discovery is only useful if something happens next. Four steps close the loop.

The last step is what keeps discovery cheap over time. Once unregistered agents cannot reach the web, they report themselves.

Triage

Owner known? Touching action pages? Decide within days.

Register

Every kept agent gets a registry entry.

Enforce

Every registered agent gets a web policy at the proxy.

Default-deny

Unregistered agent identities lose web access, so new ones surface.

Pitfalls

Mistakes when buying discovery tools

These show up after the contract is signed. Check for them during the trial instead.

Each one is easy to test for in a week, and expensive to discover after a year.

Buying for the demo estate

The demo shows cloud agents. Your agents live in SaaS.

Counting findings, not decisions

A thousand findings without owners is noise.

No web view

You find agents but cannot tell which ones are acting.

No registry link

Findings live in one tool, rules in another, and they never meet.

Over-broad access

A tool that needs write access to find things is a new risk.

One-time scan

Discovery must run continuously to stay true.

Build or buy

When each approach makes sense

Many teams start with their own logs and buy a tool once the number of agents grows.

The table suggests a starting point for five common situations. Most estates match one of them closely.

SituationStart withAdd later
Fewer than 20 agents, mostly in-houseProxy logs plus page-type taggingAn identity view of agent keys
Heavy use of SaaS with built-in agentsA SaaS security toolNetwork view for server agents
Agents built mainly in one cloudCloud AI posture toolSaaS and browser views
Many staff using AI browsers and extensionsEndpoint and browser toolProxy page-type policy
Regulated, large estateTwo tool types plus logsRegistry integration and default-deny
Measuring it

How to tell discovery is working

Track these monthly, whatever tool or method you use. Falling times and rising registration show real progress.

New agents found

Should rise at first, then settle.

Time to owner

Days from finding to a confirmed owner.

Registered share

Found agents that made it into the registry.

Action-page agents

Found agents that touched signup, checkout or upload pages.

Terms

Words used on this page

Short definitions for teams new to agent discovery and its vocabulary.

Discovery

Finding agents from evidence rather than asking people.

Planted agent

A test agent you create to check whether a tool finds it.

Enrichment

Adding context, such as page types, to raw findings.

Vendor agent

An agent built into a product you buy, acting for your staff.

Read-only access

Permissions to look, never to change.

Default-deny

Blocking web access for any agent not registered.

A trial, week by week

What a good discovery trial looks like

A composite of a typical seven-day proof of value, not a specific product. Use it as a template for your own trial plan.

Monday: five planted agents ready

A server script, a cloud agent, a SaaS agent, a browser extension and a signup-trying bot.

Tuesday: read-only connections

Cloud accounts, identity provider and proxy logs connected. No write access granted.

Wednesday: four of five found

The browser extension was missed, which shows the tool's blind spot clearly.

Thursday: real surprises

Several unknown agents appeared, two of them with no owner.

Friday: the web view

The signup bot showed as "signup attempts" only after page-type tagging was added.

Next week: decision

Buy, pair with an endpoint view for extensions, and link findings to the registry.

Roles

Who owns discovery

Discovery touches several teams' systems. Agree clear roles before the first scan starts.

TaskSecurity operationsIdentity teamSaaS administratorsAI platform team
Run network discoveryDoes itInformedInformedInformed
Export keys and grantsReviewsDoes itConsultedInformed
Check SaaS agent settingsReviewsInformedDoes itInformed
Confirm ownersLeadsHelpsHelpsHelps
Register kept agentsInformedInformedInformedDoes it
Objections

Common pushback, and the answer

Discovery projects stall for predictable reasons. These answers keep them moving.

"We already have a CASB"

It likely sees SaaS use by people. Ask whether it separates agents from people, and whether it knows page types.

"Our cloud tool covers AI"

It covers cloud-built agents. Vendor agents and browser extensions usually sit outside its view.

"Logs are too noisy"

Filter to model API calls and headless browsers first. The list becomes short quickly.

"We will do it next quarter"

Agents multiply faster than quarters pass. A one-week log sweep is a cheap start.

Budget

What discovery actually costs

Costs are mostly people's time. Tools reduce the time, but they never remove it entirely.

Analyst time

A few days for a first log sweep, then a few hours a week.

Owner time

Minutes per agent to confirm ownership and purpose.

Tool licences

Varies widely by type and estate size. Compare against analyst hours saved.

Page-type data

API from $99 a month, or an on-premise database for large volumes.

Discovery tells you who. Page policy stops what.

  • In the 2026 incidents, the agents were known. Their web actions were not stopped.
  • Discovery plus page-type policy covers both halves.
  • In our replay, page data plus egress rules would have stopped almost all of the incidents.
Every 2026 agent escape, mapped to the rule that stops it The evaluation environment incidents

The honest fine print — the same two assumptions we publish, plus two operational ones

  1. The policy engine must see every request — an agent with raw socket access or a second network path bypasses everything; enforcement belongs at the egress proxy/network layer, not only in an SDK hook.
  2. Default-deny must be on. In flag-only mode these become alerts within minutes rather than prevention — still a large improvement on a timeline measured in weeks (the DseWiki edits ran from late May to late June 2026, per the researchers), but not a block.
  3. For full URL+method matching on HTTPS you need to be the proxy or in-process hook — SNI alone shows only the host, which still catches the entire host-list layer.
  4. Policy can’t read intent inside a legitimately allowed action: an agent whose job is publishing packages keeps registry access. In our replay of the 2026 incidents, no crossing fits any plausible allowlist for the agents’ documented tasks.
Related

Keep reading

FAQ

Discovery tool questions

What are AI agent discovery tools?
Tools that find the AI agents running in an organisation, from cloud accounts, SaaS settings, identity data, network traffic or devices.
Which type of discovery tool is best?
None covers everything. Pair a network view with an identity or SaaS view, and choose based on where your agents actually run.
Can I discover agents without buying a tool?
Yes, for server-side agents. Proxy logs show sources that call model APIs or use headless browsers. SaaS vendor agents usually need admin settings or a SaaS tool.
How do I test a discovery tool?
Plant five known test agents before the trial, then count how many the tool finds, including one that tries a signup page.
Why do page types matter for discovery?
They separate agents that only read from agents that sign up, buy or upload. An AI agent allow list provides page types for 40M+ domains.
What should happen after an agent is found?
Triage it, register it or retire it, and put its web access behind a page-level policy.
How often should discovery run?
Continuously where possible, and at least weekly for network logs and monthly for SaaS and identity sources.
Do discovery tools need write access?
They should not. Read-only access is enough to find agents. Treat any request for write access as a separate risk decision.
Can discovery find agents that run inside SaaS products?
SaaS security tools and admin settings usually can. Network views alone often miss them, because the agent runs on the vendor's servers.
Where can I try page-type tagging?
Download the free 100-domain sample or use the lookup API from $99 a month. See pricing.

See which discovered agents are acting, not just reading

Page types for 40M+ domains, added to the logs you already have.

Download the sample