The new sprawl
Every enterprise platform now ships an agent builder. Copilot Studio lets a business user wire a conversational agent to live data in an afternoon. Microsoft Foundry turns a subscription into a deployment target for autonomous workloads. Power Platform automations call models and act on the results. Salesforce Agentforce puts agents directly into customer-facing workflows. None of these require a ticket to IT, an architecture review, or a security sign-off to exist.
The result is a new category of estate: not devices, not applications, but semi-autonomous actors with identities, permissions and data access — created by anyone, owned by no one, and visible to the security team only by accident.
Shadow IT was infrastructure you didn't know about. Shadow AI is infrastructure that acts on its own initiative.
Why agents multiply faster than servers ever did
Three forces compound. First, the barrier to creation has collapsed: an agent is a form, not a project. Second, the platforms actively encourage it — agent creation is the growth metric every vendor is optimising for. Third, agents beget agents: a working pattern gets copied across teams, departments and geographies within weeks, each copy acquiring its own connections and credentials along the way.
Traditional asset management assumed a procurement chokepoint: things entered the estate through a process. Agents enter the estate through enthusiasm. There is no chokepoint to instrument — which means discovery has to go and look, continuously, everywhere agents can exist.
The question nobody can answer
Ask a CISO how many endpoints the organisation has and you'll get a number. Ask how many AI agents, and you'll get a pause. The honest answer at most organisations is that nobody knows — not the count, not the owners, not what data each agent can reach, and not which ones were abandoned by their creators months ago but still hold live credentials.
That last category deserves emphasis. An abandoned agent is the worst of both worlds: it retains its access and keeps acting, but no human is watching its behaviour or renewing the justification for its existence. It is standing privilege with no standing owner.
Why surveys and spreadsheets fail
The first instinct is to ask: send a survey, build a register, make teams self-report. It fails for the same reason it failed for shadow IT, only faster. Self-reporting captures what people remember, in the shape they remember it, at the moment they were asked. It misses the agent built by the contractor who left, the flow cloned into a personal environment, the deployment in the subscription nobody audits. And it is stale before the results are collated.
A register that is 80% complete is arguably worse than none at all — it converts an known-unknown into a false assurance, and the missing 20% is precisely the population most likely to hurt you.
An inventory you can't prove complete isn't an inventory. It's a sample.
Discovery is an evidence problem
Real discovery inverts the model: instead of asking people, ask the platforms. Every environment where agents can exist — Microsoft Graph and Entra, Defender XDR, Power Platform, Microsoft Foundry, Salesforce — exposes authoritative records of what has been created, what identities it holds and what it is connected to. Read-only collectors can sweep those sources continuously and normalise the results into one canonical inventory, with every fact traceable to the source observation that produced it.
The read-only constraint matters more than it sounds. A discovery tool with write access to the estate it audits is a new risk in its own right; one that observes without touching can be granted the visibility it needs without becoming an attack path itself.
Honest about the gaps
No discovery is ever total, and the trustworthy systems are the ones that say so. A source can be unreachable, a permission missing, an API throttled. The difference between a governance tool and a dashboard is what happens next: a dashboard shows you what it found and stays quiet about the rest, while a governance tool keeps a coverage ledger — which sources were swept, when, with what confidence, and where the known blind spots are. Evidence of absence, not just absence of evidence.
From unknown to accounted for
Shadow AI is not a reason to slow adoption down — the agents are being built because they're useful. It is a reason to make discovery continuous, evidence-backed and honest about its own limits, so that "what agents do we have?" becomes a question with a defensible answer. That answer is the foundation everything else in AI governance stands on: you cannot assign owners, evaluate policy or remediate risk on a population you haven't found.
Apex Warden was built to give that answer: read-only collectors across Microsoft and Salesforce estates, a durable coverage ledger, and one canonical inventory in which every agent is — finally — accounted for.
See your estate's agents
Book a walkthrough of evidence-backed agent discovery across a live Microsoft tenant.
Get a demo