Agent discovery

Shadow AI is an evidence problem.Trustivan reports only what it can prove.

Agents appear wherever someone can connect a model to a credential: a copilot installed in a SaaS tenant, an MCP server started on a laptop, a pipeline that calls a model API. No provider API Trustivan reads reports an agent, so no connector discovers one and no screen registers one. What Trustivan does inventory is what agents depend on: the tools every MCP server lists and the AWS, GitHub, Kubernetes and Vault identities an agent can run as.

Not builtAgent discovery is not built, by design · MCP tools and machine identities are inventoried today

Agents and the identities they run as

demo estate · 3 unowned · synced 2 minutes ago

  • support-copilotAI agent · demo seeder · syntheticOwned2m
  • agent-runtime-roleIAM role · AWS connector · owner tagOwned9m
  • release-orchestratorAI agent · demo seeder · syntheticUnresolved14m
  • agents-workerService account · Kubernetes connectorUnowned31m
  • copilot-approleAppRole · Vault connectorUnowned1h
  • kb-research-agentAI agent · demo seeder · syntheticUnowned3h

Illustrative · synthetic agents; empty on a real deployment

Illustrative · agents come from the synthetic demo seeder; machine identities from connectors

The problem

Shadow AI is an inventory problem before it is a policy problem.

You cannot set policy for agents you have not found, and the ways agents come into existence bypass every gate built for service accounts. A list assembled from guesses does not fix that; it hides it.

No Registration Step

Agents are created by installing an app, cloning a repository or clicking consent, never by a provisioning workflow you can gate

Many Shapes

Copilots, orchestrations, coding agents, MCP servers and OAuth connections look nothing alike to a scanner built for secrets

Borrowed Credentials

Most agents authenticate as the person who set them up, so identity logs show a human where an agent is acting

Sources

Where agents leave signals

No single system lists your agents, and most of the traces they leave sit in systems Trustivan does not read. Each tile says which of them are read today.

View all integrations
  • Cloud

    • Agent runtimes and model endpoints with their invocation roles
    • Roles assumed by orchestration frameworks at machine cadence
    • Read today: AWS IAM roles and machine users an agent can run as; no agent is reported
  • SaaS

    • Connected apps and copilots holding AI-related scopes
    • OAuth tokens issued to agent frameworks, not to people
    • Not read: no SaaS connector exists
  • Identity providers

    • Service principals and app registrations created for agents
    • Consents granted by individual users rather than admins
    • Not read: no identity-provider connector exists
  • Code

    • Agent frameworks and MCP configuration committed next to the code
    • System prompts and tool schemas under version control
    • Read today: GitHub App installations and bot members; file contents are never read
  • CI/CD

    • Pipelines that call model APIs with pipeline credentials
    • Agents that open, review or merge pull requests
    • Not read: no CI/CD connector exists
  • Developer machines

    • Local MCP servers started over stdio with no auth flow
    • Coding-agent configurations that hold personal tokens
    • Not read, by design: endpoint telemetry is refused

How it works

Collect. Classify. Profile. Attribute.

Every sync refreshes identities and tools and marks what a provider stopped reporting as absent. No sync can surface an agent, and the console says so instead of showing an empty estate as a clean one.

  1. Collect

    Five connectors read AWS IAM, GitHub, Kubernetes, HashiCorp Vault and Model Context Protocol servers: machine identities, credential metadata and tool listings. None of them reports an agent.

  2. Classify

    Each MCP tool's effect is read, write or unknown, from the publisher's readOnlyHint or an operator's declaration, never from its name or description.

  3. Profile

    An identity typed as an AI agent that nothing has profiled is itself a finding, so a gap in the inventory is reported rather than passed as clean.

  4. Attribute

    Ownership is read from provider tags or assigned by a person. An agent with no accountable owner raises a finding with the evidence attached.

What you get

An inventory you can act on

Each entry links to the identity graph, so an unowned agent identity is one click from the credentials it holds and the resources it can reach.

MCP Tool Inventory

Every tool each MCP server lists, with its publisher-declared effect, marked absent when the server stops listing it

Machine Identity Inventory

The AWS, GitHub, Kubernetes and Vault identities an agent can run as, with the metadata of the credentials they hold

Unprofiled Agent Findings

An identity typed as an AI agent that nothing has profiled is reported as a finding, never counted as governed

Unowned Agent Findings

An agent with no accountable owner, with the evidence behind its ownership state

Lifecycle Signals

First discovered and last seen per identity, so a stale identity still holding a live credential becomes a finding

An Honest Empty State

On a real deployment the agent inventory is empty, and the console says why instead of reporting a clean zero

Decide what an agent may do before it acts.

See how TRUSTIVAN connects identity, credential, access, agent and action context into one control plane.