AI agent inventory and exposure
Read-only discovery across production, edge, and managed endpoints.
Material findings
| Class | Agent | Exposure | Spend / mo |
|---|---|---|---|
| No owner | unknown-llm-worker prod-us-east / vm-114:8080 |
Outbound calls to an external model endpoint. Purpose unknown. Egress not attributable to any approved workload. Running 9d. | $4,310 |
| No owner | (unidentified) prod-eu-west / cron-runner-02 |
Scheduled export writing to external object storage. No approver of record. Running 16d. EU data residency implications. | $2,240 |
| Shadow | sales-copilot-poc shadow / laptop-jdoe / localhost |
Credential-holding script on an unmanaged endpoint with a live CRM API key. Not seen in 9h. Off-boarding risk. | $880 |
| Tampered | Support Triage (patched) prod-eu-west / ns-cx / pod-13 |
Presented a creation record whose governance policy was modified after creation. Record fails verification. Holds customer PII read access. | $1,490 |
| Stale | Security Log Analyst prod-us-east / ns-sec / pod-4 |
Attested, but last attestation 7.5h old against a 15-minute policy. Operating at reduced authority; incident-response coverage degraded. | $3,120 |
Recommended actions
Terminate the two unowned production agents
No approver exists; no business process depends on them. Effect: $78,600 annualized spend stopped, two external egress paths closed.
Revoke the CRM credential on the unmanaged endpoint
Remove the shadow script. Effect: $10,560 annualized, one off-boarding exposure closed.
Quarantine the tampered agent
Pending investigation of who modified its governance policy and when. Effect: PII access suspended; chain-of-custody evidence preserved.
Restore attestation cadence for the security agent
Effect: incident-response coverage restored to full authority.
Require an owner and stated purpose for every agent
Standing control, with unowned agents refused at deployment. Effect: this finding does not recur.
Method and limits
- Classification. An agent’s own claim about itself was not treated as evidence. Attested means a signature chains to a verified creation record using a key unavailable to the platform executing the agent.
- Consumption figures are attributed from provider billing and metering-proxy records produced independently of the agents themselves, not from agent self-report.
- Scope. Production Kubernetes, edge gateways, managed VMs, and enrolled endpoints. Unmanaged networks and offline systems were not in scope.
- Absence of a finding is not assurance that no agent exists. This is an inventory and exposure assessment, not a security certification or a legal opinion.
- Discovery ran read-only inside the environment. No inventory data was transmitted externally.