AI Agent Allowlist
Home Page-Types Database Agent Guardrails 2026 Incidents API Docs Pricing
Resources
Use Cases (15) Industries & Buyers (12) Learn: Core Concepts (12) Implementation Guides (15) Comparisons (8) Agent Security Guides (22) Market & Frameworks (9) Schema & Data Reference (6) FAQ Glossary
Why It Matters
2026 Agent Incidents Category Targeting Database Refreshes Contact Customer Login
Download Free Sample
for security teams who need the real number

AI Agent Inventory: Find Every Agent

You cannot secure agents you do not know about. An inventory is the list of every agent actually running, found from evidence rather than surveys.

This page covers where agents hide, the signals that give them away, and how the list becomes control through a registry and an AI agent allow list.

7Places agents hide
12Discovery signals
10Inventory fields
30 daysTo a first full list
Definition

What an agent inventory is

Inventory and registry are often used as synonyms. It helps to keep them apart.

Inventory

What is actually running, found from evidence.

Owned by security. Updated by discovery.

Registry

What is allowed to run, with owners and rules.

Owned by governance. Updated by approvals.

The gap between them

Agents in the inventory but not the registry are your shadow agents.

Closing that gap is the whole job.

Where agents hide

Seven places to look

Each place catches a different kind of agent. Network logs find scripts and servers, SaaS settings find vendor agents, browsers find extensions.

Agents rarely announce themselves. They appear as traffic, grants, keys and settings spread across many systems.

Network egressCalls to model APIs
API keysModel provider keys
SaaS grantsApps with delegated access
Cloud accountsAI services switched on
Code reposAgent frameworks in use
BrowsersAI extensions and browsers
Vendor settingsBuilt-in agents enabled

No single source finds everything. Most teams need at least four of the seven to get close to the real number.

Start with the sources your team can query today. Add the rest over the following weeks as access is arranged.

Signals

Twelve signals that reveal an agent

Each signal on its own is weak. Two or three pointing at the same source are usually enough to call it an agent.

SignalWhere you see itWhat it suggests
Regular calls to model provider APIsEgress proxy or firewall logsSomething is using a model, often on a schedule
Model API keys in code or secrets storesSecrets scanning, vault auditAn agent or app built in-house
Agent framework packages in repositoriesDependency manifestsAn agent under development or running
OAuth grants to AI appsIdentity provider, SaaS admin consolesA third-party agent acting for a user
AI features switched on in SaaS toolsSaaS admin settingsVendor agents inside products you already use
AI services enabled in cloud accountsCloud billing and configurationAgents built on cloud platforms
Headless browser traffic from serversProxy logs, user-agent stringsBrowser automation, often an agent
AI browser extensionsEndpoint managementAgents acting inside staff browsers
Service accounts with unusual request patternsDirectory and access logsA script that decides its own steps
Traffic to AI tool domainsDNS and proxy logsStaff or agents using AI services
New signups from company addressesMail logs, finance invoicesAn agent creating accounts elsewhere
MCP server processes or configsEndpoint and container inventoriesAgents connected to tool servers

Score each source by how many signals point at it, then investigate the highest scores first. For recognising AI tool domains in logs, our sibling AI Tools Blocklist classifies tens of thousands of AI services.

What to record

Ten fields for each inventory item

Ten fields are enough to triage. Everything else can wait until the agent is registered.

Keep the inventory lighter than the registry. Its job is to be complete, not detailed.

Identifier

A stable ID, matched to a registry ID once registered.

How it was found

Which source and signal revealed it.

First and last seen

Shows whether it is still active.

Probable owner

A best guess, to be confirmed.

Where it runs

Server, cloud account, SaaS tenant or browser.

Credentials seen

Keys, tokens or grants it uses.

Web activity

Whether it reaches the public web, and which page types.

Model or service

What it calls to think.

Registered?

Yes, no, or pending.

Action taken

Registered, paused or retired.

Method

A first full inventory in 30 days

Work from the widest net to the narrowest. Network logs catch the most agents for the least effort, so they come first.

1

Days 1 to 5: network first

Pull a month of egress logs. List every source that called a model API or used a headless browser.

2

Days 6 to 10: keys and code

Scan repositories and secrets stores for model keys and agent frameworks.

3

Days 11 to 15: SaaS and identity

Export OAuth grants to AI apps and list AI features switched on in SaaS tools.

4

Days 16 to 20: cloud and endpoints

Review AI services in cloud accounts, AI browser extensions and MCP configs.

5

Days 21 to 30: merge and confirm

Merge duplicates, find owners, and compare against the registry.

Web activity

The inventory field most teams leave empty

Knowing an agent exists is step one. Knowing what it does on the web decides how urgent it is.

Read-only agents

Only pricing, documentation and similar pages. Register and review.

Agents near action pages

Seen near signup, checkout or upload pages. Prioritise.

Agents on unknown hosts

Traffic to sites nobody classified. Investigate first.

# tag each proxy log line with its page type, then group by source source=svc-research pricing=412 documentation=188 signup=6 unknown=31 source=svc-support help_center=902 status=77 source=10.2.4.19 upload=3 post_create=2 unknown=140

The third source has no known owner and already tried to upload and post. That is the agent to find today.

This view needs nothing new on the agent side. Your existing proxy logs plus page-type data are enough to produce it.

Triage

What to do with each agent you find

Speed depends on two things: whether anyone owns the agent, and whether it touches pages where it can act.

FindingActionWithin
No owner, touching action pagesPause its egress, then find the ownerSame day
No owner, read-onlyFind the owner, register or retireOne week
Known owner, not registeredRegister with a web policyTwo weeks
Registered, activity outside its purposeReassess risk, tighten policyTwo weeks
Registered and behavingKeep, review on scheduleNext review
Vendor agent switched on by one personDecide at tenant level, record itOne month
A typical first result

What most first inventories show

First inventories follow a familiar pattern. Knowing it in advance helps you plan the triage work.

A composite of common findings, not any specific company.

The survey said a handful

Team leads remember the agents they built on purpose.

The logs said several times more

Scheduled scripts, forgotten pilots and personal experiments on servers.

SaaS settings added more again

Vendor agents switched on per user or per team.

A few had no owner at all

Nobody would claim them. They were paused, and nobody complained.

The rest became registry entries

Each with an owner and a web policy.

Keeping it current

From a project to a standing process

A one-off inventory is out of date within weeks. Four routines keep it current with little effort.

Weekly log sweep

New model API callers and headless browser sources go straight to triage.

Monthly grant export

New OAuth grants to AI apps are reviewed.

Pipeline checks

New agent frameworks in code trigger a registry reminder.

Default-deny at the proxy

Unregistered agent identities cannot reach the web, so they surface themselves.

The last point changes the game. When unregistered agents are denied web access, owners come to you.

It also means the inventory stops depending on detective work. The proxy log of denied, unregistered agents becomes the list of agents still to register.

Pitfalls

Six ways inventories go wrong

Each of these mistakes leaves agents out of the list, usually the riskiest ones.

Survey only

Surveys find what people remember, not what runs.

Counting apps, not agents

One app can host several agents with different access.

Ignoring vendor agents

They act for staff inside tools already approved.

No web activity field

The most urgent agents look the same as harmless ones.

One-off project

The list is stale within weeks.

No action on findings

A list nobody triages changes nothing.

Roles

Who runs the inventory

Security operations leads, but three other teams hold sources it needs.

TaskSecurity operationsIdentity teamAI platform teamAgent owners
Log sweepsDoes itInformedInformedInformed
Grant exportsReviewsDoes itInformedInformed
Code and key scansReviewsConsultedDoes itInformed
Owner confirmationAsksConsultedConsultedConfirms
Triage decisionsDecidesConsultedConsultedConsulted
Measuring it

Numbers to report

Five numbers, reported monthly, show whether the inventory is shrinking the shadow.

Agents found

Total, and new this month.

Registration gap

Found but not registered.

Ownerless agents

The target is zero.

Agents near action pages

Found agents that touched signup, checkout or upload pages.

Time to triage

Days from discovery to decision.

Terms

Words used on this page

Shadow agent

An agent running without a registry entry or owner.

Egress logs

Records of traffic leaving your network.

OAuth grant

Permission a user gives an app to act on their behalf.

Headless browser

A browser run by code with no visible window.

Page type

What a URL is on its site, such as pricing or signup.

Triage

Deciding quickly what to do with each finding.

Objections

What teams say when security starts looking

Four objections come up in almost every first inventory. Each has a short, honest answer that keeps teams cooperating.

An inventory can feel like surveillance to the teams building agents. Clear answers keep them on side.

"We will tell you about our agents"

Thank you, and please do. Discovery exists for the ones nobody remembers, including old pilots.

"This will block our work"

Finding an agent does not stop it. Only agents with no owner that touch action pages get paused.

"It is just a script"

If it calls a model to decide what to do next, it acts like an agent and needs an owner.

"The vendor switched it on"

Then it still belongs in the inventory, with the person who manages that vendor as owner.

Tooling

What you probably already have

Six sources, most of them already paid for and already running.

Most of the seven sources already exist in a typical security stack. The work is joining them, not buying new tools.

Proxy or firewall logs

Show model API calls, headless browsers and page-level web activity.

Identity provider

Lists OAuth grants and service accounts.

Code and secrets scanning

Finds model keys and agent frameworks in repositories.

Endpoint management

Lists browser extensions and local tool servers.

Cloud configuration

Shows which AI services are enabled in each account.

Page-type data

Turns raw URLs in logs into page types, so risky activity stands out.

Worked triage

Three findings from one log sweep

A composite example of how triage works in practice, week by week.

Finding A: unknown server, upload attempts

A server nobody claims called a model API and tried to upload files to a paste site.

Action: egress paused the same day, owner found in a week, agent retired.

Finding B: known team, not registered

The analytics team runs a report agent that reads documentation and status pages only.

Action: registered with a read-only web policy within two weeks.

Finding C: vendor agent in a CRM

Switched on by one sales manager, it drafts emails and can browse.

Action: browsing disabled at tenant level, email drafting kept, entry recorded.

Three findings, three different answers. The deciding factors were ownership and web activity, not how clever the agent was.

Audits

What auditors ask to see

Auditors care less about the number of agents than about whether the method would catch a new one.

Method

Which sources were searched, and how often.

Completeness

Evidence that inventory and registry were reconciled.

Decisions

What happened to each unregistered agent, with dates.

Controls

Proof that unregistered agents cannot reach the web.

Inventory is where incident response starts

  • In the 2026 incidents, the first question was which agents did what, and where.
  • An inventory with web activity by page type answers it in minutes.
  • In our replay, page data plus egress rules would have stopped almost all of the incidents.
See the incident-by-incident prevention analysis The account takeovers

The honest fine print — the same two assumptions we publish, plus two operational ones

  1. The policy engine must see every request — an agent with raw socket access or a second network path bypasses everything; enforcement belongs at the egress proxy/network layer, not only in an SDK hook.
  2. Default-deny must be on. In flag-only mode these become alerts within minutes rather than prevention — still a large improvement on a timeline measured in weeks (the DseWiki edits ran from late May to late June 2026, per the researchers), but not a block.
  3. For full URL+method matching on HTTPS you need to be the proxy or in-process hook — SNI alone shows only the host, which still catches the entire host-list layer.
  4. Policy can’t read intent inside a legitimately allowed action: an agent whose job is publishing packages keeps registry access. In our replay of the 2026 incidents, no crossing fits any plausible allowlist for the agents’ documented tasks.
Related

Keep reading

FAQ

Agent inventory questions

What is an AI agent inventory?
A list of every AI agent actually running in an organisation, found from evidence such as network logs, keys, grants and settings.
How do you find AI agents in a company?
Combine at least four sources: egress logs, API keys and code, SaaS and identity grants, and cloud and endpoint settings. Surveys alone miss most of them.
How is an inventory different from a registry?
The inventory shows what runs. The registry shows what is allowed to run, with owners and rules. The gap between them is your shadow agents.
Which agents should be handled first?
Agents without an owner that touch signup, checkout or upload pages. Pause their web access the same day.
How do I see which page types an agent visits?
Tag each URL in your proxy logs with its page type. An AI agent allow list covers 28 page types on 40M+ domains. Try the free sample.
Can we pause an agent we find without an owner?
Yes, pause its web access at the proxy. Legitimate owners usually come forward within a day, and nothing breaks for agents nobody needs.
Do AI browser extensions count as agents?
Extensions that read pages and take actions for the user behave like agents. Record them, especially if they can fill forms or post.
How often should the inventory be refreshed?
Log sweeps weekly, grant exports monthly, and a full review each quarter.

See what your agents actually do on the web

Tag every URL in your logs with its page type, on 40M+ domains.

Download the sample