Acme Corp · all environments · read-only
Every agent running in your organization — and why.
Discovery runs on your infrastructure and sends nothing outward. Attestation, break-glass control, and metering require an attester key this tool deliberately cannot hold.
Attest them to establish an owner and a purpose — or stop them and keep the money.
Export findings report
◀ scroll to see all columns ▶
| Trust | Agent & task | Authorized by | Origin & operation | Deployed & access | Running | Authority | Token spend | Actions |
|---|
How trust is determined
An agent’s own claim about itself is not evidence. Attested means a signature chains to a verified creation record using a key unavailable to the platform executing the agent. Unattested means the agent was observed but can prove nothing. Origin is attested — it comes from the agent's creation record and is cryptographically provable. Operating location is observed from your own infrastructure, never from the agent's claim about itself. An agent is reported in one of three states: created under record, adopted (standing begins at adoption, prior history unverified rather than backdated), or of unproven origin. Where a proven origin and the operating region fall in different jurisdictions, the crossing is flagged. Agents need not be containerized: processes, scheduled jobs, serverless functions, workflows, robot control programs, and credential-holding scripts are all indexed.