Your Business Runs on AI Agents. Can You Account for Them?
Most IT teams can't name every AI agent running in their environment. Here's how to find out, fast.
Most IT teams can't name every AI agent running in their environment. Here's how to find out, fast.
TL;DR: AI agents are already running inside most businesses, doing real work that never passed through IT's front door. Ask most teams what's actually out there and you'll get a guess, not an answer. This piece looks at why that gap opened up and what it takes to close it: a short list, kept current, that tells you exactly what agents you're running, what each one can touch, and who's responsible for it.
Most businesses can't actually rattle off every server, every laptop, and every login the second someone asks, not once you're past three people. But somebody usually knows where to go find the answer, because all of it came in through a process that left a trail: a purchase order, a setup ticket, an IT admin who remembers. AI agents almost never arrive that way. Nobody's holding a list, because nothing about how they showed up required one.
Every business has a rough sense of who's got keys to the building. A landlord, a manager, maybe the cleaning crew. AI agents are like an extra set of keys that got cut and handed out without anyone writing down who has them or what doors they open. Unlike keys, though, an AI agent can let itself in whenever it wants, and some of them can pick up whatever they find inside and mail it to someone else entirely.
That's roughly where AI agents sit right now. A marketing coordinator hooks a chatbot up to the CRM. Someone flips on a copilot buried in a software update. A person in accounting builds a script that files invoices on its own, and it's been running unsupervised since spring. Each one solved a real problem for somebody, and each one slipped in without the paperwork a new hire or a new laptop would've gotten.
That gap matters more this year than it used to. These agents can read email, touch client files, and act without waiting on a person, and 2026 has already handed the security world more than one example of exactly how that goes wrong. This was covered directly in an earlier piece on the AI agent that ran a ransomware attack by itself, and the line worth carrying forward from it is simple: you can't govern what you haven't mapped.
This post is that map. What actually counts as an agent, what to write down for each one, and how to put a real list together this week.
Traditional IT tracking follows a pretty simple path. Someone asks for a tool, procurement signs off, IT sets it up, and it lands in a spreadsheet with a name next to it. That process leaves a paper trail without anyone trying very hard.
AI agents skip all of that. They show up baked into software you already pay for, through a toggle nobody flipped on purpose. An employee builds one over a weekend with a low-code tool, and there was never a form telling them to ask first. Or it starts as a quick experiment, works better than expected, and turns into something the business actually leans on, without anyone standing up to announce it. Ask five people in the building and you'll get five different half-answers, and that's the real problem here.
NIST built its AI Risk Management Framework around four steps: govern, map, measure, and manage. Map comes second because it has to. You can't measure a risk you haven't found, and you sure can't manage it. For an agent, mapping means writing down what it's allowed to touch and who else it can call on by itself, not just what vendor sold it to you. That's different homework from counting license seats, and it's homework almost nobody's done yet.
Widen your definition before you go looking, because most people picture something flashy, like a chatbot, and stop there. For this exercise, an agent is anything that takes an action on its own, without a person clicking approve in the moment. That's a wider net than most folks expect.
It catches RPA tools moving data around on a timer. Copilots baked into your CRM or your email platform, the ones you flipped on without reading the fine print. Chatbots hooked into a knowledge base, answering questions with information nobody double-checked. One-off scripts an employee wrote to fix a headache and then forgot about are still running today. And multi-step AI workflows that call other tools on their own, no human in the loop at all.
If your gut reaction is "we probably don't have that many," go check department by department before you settle on that answer. Nobody sees the whole picture from one desk. Finance knows about their invoicing script. Marketing knows about their chatbot. Nobody's added it all up in one place, and that's exactly the gap this inventory closes, and it's also exactly why watching what these agents actually do day to day only works once the list itself is real.
Once you find an agent, four fields turn "yeah, we know about that one" into something you can actually manage. Skip any of these and you're back to guessing the moment something goes wrong.
Owner comes first. A real person's name, not a department, and definitely not "whoever set it up." If that person's left the company, reassign it today, not next quarter.
Credentials come next, and it's the most common gap out there. What login, API key, or service account does the thing actually run under? A team hands an agent a person's existing login because it's the fastest way to get it working, and now the agent's carrying every permission that person has, whether the job needs it or not.
Then there's the data it can reach. Not what it's supposed to touch on paper, what it can actually get to, given the credentials and connections it's got right now.
Last is authorized actions. Can it only look at things, or can it write, delete, send, or move money? Does anything require a human to sign off first, or does it run start to finish with nobody watching? That last question tells you fast whether you're dealing with a low-risk helper or something that needs your attention this week, and it's the exact question scoping an agent's access down to what it actually needs is built to answer.
You don't need a six-month audit to get a real first pass done. Here's how to move fast and get it mostly right by Friday.
Start with your bills. Scan recent invoices and renewals for anything mentioning AI, automation, or Copilot features. That surfaces the tools people actually paid for, which is a faster starting point than most teams expect.
Check your identity provider next, for service accounts and API keys sitting with standing access. Non-human logins with real access are one of the clearest fingerprints an agent leaves behind, and they're often the ones nobody's looked at in months.
Then ask every department head one direct question: What tool do you use that does something on its own, without you clicking a button each time? Frame it as curiosity, not an audit, and people open up a lot faster.
Look at the connected apps settings inside your CRM, your document system, and your email platform. Approved integrations and AI features hide there more often than people expect.
Last, cross-check against any vendor reviews you've already done. An AI feature bolted onto a tool you vetted two years ago is easy to miss, because the paperwork predates the feature, and it's exactly the kind of gap a proper vendor risk assessment is built to catch going forward.
Run those five steps in a single day, and you'll have a more complete inventory than most businesses have ever put together. It won't be flawless, and that's fine. Eighty percent done and getting updated beats perfect and never started.
You don't need fancy software for this part, just a place to write things down and the discipline to keep it current. A shared spreadsheet handles it just fine, and honestly, fancy software is usually where good intentions go to get abandoned three weeks in.
For each agent you find, capture the name, the owner, and what job it actually does day to day. Add the credentials it runs under, the data it can reach, and what actions it's authorized to take. Note whether a human has to sign off on any of those actions, or if it runs on its own without anyone checking in. And write down the date you last reviewed it, so staleness is visible at a glance instead of a surprise six months later.
That's eight columns, nothing complicated. The format matters far less than actually keeping it current, ideally checked every quarter, and again any time a new tool or integration gets the green light.
This whole post has been about one simple idea: you can't govern, secure, or fix what you don't know exists. Most businesses have AI agents running right now that never showed up on a purchase order or a setup ticket, and that gap between what's actually running and what anyone can account for is exactly what an inventory closes.
That gap doesn't shrink on its own, and it tends to widen the longer it goes unaddressed. Every week without a real list is another chatbot, script, or copilot added to the pile nobody's tracking, and another chance for one of them to touch something it shouldn't, or to be treated like just another IT ticket instead of the kind of insider risk it actually is.
Heroic Technologies specializes in security and IT strategy for law firms and other compliance-heavy businesses across the West Coast, which means an unmapped AI agent isn't a hypothetical risk to Heroic's team; it's a familiar starting point. Building the inventory is where Heroic begins with clients facing this exact problem, before moving into scoping access, setting up monitoring, and building a response plan around what the list turns up.
Whether you're starting the Clean Break from another MSP or just trying to figure out where your business stands for the first time, you don't have to sort it out on your own. Get in touch with Heroic's team before an incident forces the conversation instead.
1. What if we find an agent nobody remembers setting up?
That's more common than most teams expect, especially with tools that arrived through a free trial or a setting nobody turned off. Assign a real owner right away, even if that means asking around until someone claims it, and check what it can actually access before deciding whether it keeps running, gets scaled back, or gets shut off. Don't leave it in limbo just because it's been working fine so far.
2. Do we need special software to build this list?
No. A shared spreadsheet handles it just fine, especially for a first pass. What matters is capturing the same details for every agent, owner, credentials, data access, authorized actions, and keeping it on a real review schedule instead of building it once and letting it go stale.
3. How often should we update it?
At a minimum, once a quarter, since agents get added, changed, or retired more often than people expect. Update it immediately any time a new tool or integration gets approved too, rather than waiting for the next scheduled review to catch up.
Most IT teams can't name every AI agent running in their environment. Here's how to find out, fast.
The first AI-run ransomware attack wasn't the story. What followed, and what it means for every organization deploying AI agents, is.
Your IT provider's response time promise is only worth what they actually deliver. Here's how to read your SLA, what good looks like, and how to...