Find every AI agent running in your company
Most security teams can't produce that list today. In one week, you'll have it, with the login each agent uses and a human name next to every one.
Why can't we just ask our teams what agents they're running?
You can ask. The list that comes back is short, and it's wrong.
Agents get built by people who don't think of them as agents. A script holding an API key. A copilot someone wired into a shared drive on a Saturday. None of that shows up on an inventory request.
What is an agent identity census?
It's a one-week search for every AI agent running in your environment. We read six places: your identity provider, your secret store, your CI/CD accounts, your AI gateway logs, your endpoint telemetry and your expense records.
Each agent gets a row that says what it does and which human owns it.
The week ends with a working session for your team and a readout for your leadership.
What do we get at the end of the week?
Four things, all in writing.
- 01
The census
One row per agent. What it does, the login it uses, the credential type, the human owner, the backup owner, and what it can reach.
- 02
The four findings
Named and counted, with the agents listed under each: agents running under a person's login, agents sharing one login, stored keys that never expire, and agents whose owner has left the company.
- 03
The first fixes
What to do in 30 days, 60, and 90, ordered by risk.
- 04
The leadership page
One page in plain words. How many agents, who owns them, what the worst one could reach, and what's being fixed first.
Why start with identity instead of everything else?
Because the rest of your AI controls sit on top of it.
You can't contain an agent you can't name. And you can't run an incident when the audit log points at a person who was asleep at the time.
Identity is the first element of the Agentic Trust Framework for that reason. Fix it and the other four get easier. Skip it and they don't work.
See how the Agentic Trust Framework compares to other AI frameworks →
Who is this for?
Security and technology leaders at regulated companies between 1,000 and 10,000 people, with AI agents already running and something forcing the question. That's usually an audit finding, a question from the board, a customer security questionnaire, or an incident that's still fresh.
If your agents are still in planning, you're early for this. Take the free assessment instead and come back when they're live.
Who runs it?
We wrote the Agentic Trust Framework. The Cloud Security Alliance published it in February 2026 under an open license.
Thirty days later, Microsoft built its Agent Governance Toolkit against the spec, in Microsoft's own GitHub organization, without coordinating with us. Berlin AI Labs has since documented 12 production deployments mapped to all five elements.
John Kindervag, who created Zero Trust, wrote the foreword to our book, Agentic AI + Zero Trust: A Guide for Business Leaders.
Our founder, Josh Woodruff, is Co-chair of the CSA Zero Trust Working Group and Founding Chair of the Agentic Trust Framework at the CSAI Foundation. We still lead the identity architecture for an aerospace defense contractor today.
What this week doesn't cover
- No changes to your identity provider. We find and recommend. Your team makes changes.
- No credential rotation or migration. That's the work after this.
- No agent code review.
- No tool purchases. We're vendor-neutral and have no software to sell.
Frequently asked questions
How much of our team's time does this take?
A kickoff call and read access to the systems above, plus someone available for questions during the week. Plan on a few hours across your identity and platform people, plus the working session on the last day.
We already have a CMDB and an inventory process. Do we need this?
Those cover systems your teams registered. Agents get built outside that process, which is why the census reads the identity provider and the expense records directly instead of trusting a registry.
Can you just give us the template and we'll run it ourselves?
The census table is simple. Finding what's missing from it is the part that takes experience. Teams that run it alone usually find the agents they already knew about.
Does this certify us against the Agentic Trust Framework?
No. This week covers one element, identity. A formal conformance review against all 25 ATF requirements is separate, larger work.
What happens after the week ends?
Most clients pick up the 30-day list with their own team and bring us back for the harder items. Some move into a full posture review across all five elements.
What does it cost?
The census is the first week of our AI Readiness Assessment. We scope it against your environment, then quote it. The free assessment and the Advanced ATF Assessment at $5,000 sit ahead of it if you want a smaller first step.
The list of every agent in your company exists somewhere.
Right now it's spread across six systems and three people's memories. One week and it's on one page with your name on it.