Governance fails because the organisation cannot assign ownership, classify scope, or review access for agents it has not discovered. Discovery is the prerequisite for every later control, including approval, auditing, and offboarding. Without an inventory, access decisions become partial and reactive rather than enforceable across the full agent estate.
Why governance fails first when agents are not inventoried
An inventory is the control plane for governance. If an organisation does not know which AI agents exist, it cannot assign ownership, define scope, or decide which requests are legitimate. That means the first failure is not technical execution, but the loss of a trustworthy record that every later control depends on.
Without discovery, approval becomes incomplete because reviewers are evaluating only the agents they can see. The same gap undermines auditability, because access decisions cannot be tied back to a complete asset list, and offboarding becomes unreliable when hidden agents may still hold credentials or active permissions.
Inventory is therefore not a reporting exercise. It is the point where governance becomes enforceable, because it establishes the universe of things that must be reviewed, constrained, and retired.
What breaks in access review, ownership, and offboarding
When access is granted before inventory, the organisation is forced into reactive governance. Ownership cannot be assigned cleanly, so no one can confidently approve, attest, or revoke the agent’s access. In practice, that creates partial control: some agents are known, some are shadowed, and some continue operating without a clear accountable owner.
That same incompleteness affects scope classification. A discovered agent can be separated by purpose, environment, and business function, but an undiscovered agent cannot be placed into the right review cadence or risk tier. The result is that access reviews measure only the known slice of the estate, while the unknown slice remains outside the process.
Offboarding is also weakened because retirement depends on knowing what to retire. If an agent was never inventoried, teams may miss its tokens, service connections, tool permissions, or delegated access paths. That leaves orphaned access in place even after the original business need has ended.
Why discovery has to come before approval, auditing, and least privilege
Discovery is the prerequisite for every downstream governance decision. Approval requires a named owner and a bounded scope. Auditing requires a complete population. Least privilege requires knowing which permissions are actually in use. If the inventory step is skipped, each of those controls becomes selective rather than comprehensive.
That is why governance over agents should be treated as a lifecycle problem, not a one-time intake task. The organisation needs a discover, classify, approve, review, and retire sequence. Shadow AI and AI Agent Discovery Guide is useful here because the core issue is finding unmanaged agents before they accumulate unsanctioned access.
Once agents are found, they can be assigned accountable owners and evaluated for scope. AI Agent Authorisation Guide supports that next step by showing why task-scoped and just-in-time access only works after the agent is identified and placed under policy.
For organisations building a broader operating model, Agentic AI Identity Guide is the natural companion because governance depends on registration, ownership, and retirement, not just on whether an agent can technically authenticate.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Undiscovered agents cannot be retired cleanly, leaving orphaned access and ownership gaps. |
| NHI-05 — Overprivileged NHI | Access granted before inventory tends to skip scope and privilege review, increasing excess access. | |
| Recommendation — Inventory agents before access so offboarding can revoke every permission and dependency. Classify agents first, then apply least privilege and remove excess permissions. | ||
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Unknown agents can hold unchecked authority, making privilege review and accountability incomplete. |
| Recommendation — Tie agent approval to owner assignment and per-action privilege checks. | ||
| CIS Controls v8 | CIS-1 — Inventory and Control of Enterprise Assets | Governance depends on knowing the full asset population before enforcing access control. |
| Recommendation — Maintain a current agent inventory before granting or reviewing access. | ||
| NIST SP 800-53 Rev 5 | CM-8 — System Component Inventory | A complete component inventory is required to govern access and lifecycle actions consistently. |
| Recommendation — Record every agent as a managed component before it receives production access. | ||
Practitioner Guidance
What to prioritise: inventory before privilege. If an agent can already reach a production system, treat discovery gaps as a governance defect, not an admin inconvenience. The immediate question is not “should this agent keep access?” but “who owns it, what scope was intended, and what else depends on it?”
What to verify: the inventory must cover agents that were created informally, embedded in SaaS features, or launched by development and operations teams outside central review. A governance process that only sees centrally registered agents will still miss the highest-risk shadow estate.
Practitioner takeaway: when inventory comes after access, every later control inherits blind spots, so the first reliable governance act is to make the agent visible before deciding what it may do.
Related resources from NHI Mgmt Group
- Why do AI agents create more risk when they are given direct access to raw data schemas?
- How should security teams evaluate credential brokering for AI agents before they let agents access production systems?
- How should security teams test privileged access controls against AI agents before they are exposed to production systems?
- What are the best practices for governing AI agents before they are allowed to access business-critical SaaS applications?