Security teams should treat discovery as a continuous control, not a one-time inventory project. Cover the main places agents appear, including browser-based AI apps, desktop or coding agents, OAuth-connected AI tools, MCP connectors, and SaaS audit logs. The goal is a unified, current inventory that ties each agent to an owner, data reach, and risk so governance can start with evidence, not assumptions.
Why This Matters for Security Teams
AI agent discovery is not a neat asset-management exercise. Browser assistants, endpoint coding agents, OAuth-connected tools, and SaaS-native automations all create different identity footprints, and each can expand data access without passing through traditional procurement or endpoint controls. That is why security teams need a live discovery model that maps where the agent runs, what it can reach, and which human owns the risk.
This problem is already visible in current research. NHIMG’s AI Agents: The New Attack Surface report shows that only 52% of companies can track and audit the data their AI agents access, leaving a large compliance and investigation blind spot. That aligns with the broader direction of the OWASP Agentic AI Top 10 and NIST AI Risk Management Framework, both of which treat runtime behavior and traceability as core governance issues.
In practice, many security teams encounter agent sprawl only after a token, browser plugin, or SaaS connector has already touched sensitive data.
How It Works in Practice
Effective discovery starts by treating each environment as a different telemetry source, then normalizing the results into one inventory. In browsers, look for extensions, embedded copilots, and web apps that request SSO, clipboard, file, or page-content access. On endpoints, identify locally installed assistants, IDE plugins, and code agents that can read repositories, shells, or local files. In OAuth, inspect consent grants, refresh tokens, delegated scopes, and app-to-app connections that let an agent act outside the browser session. In SaaS, mine audit logs for service accounts, automation rules, connected apps, and unusual API call patterns.
A practical discovery program usually combines:
- Identity signals: app registrations, OAuth grants, service principals, and workspace-owned tokens.
- Execution signals: browser inventory, endpoint agent processes, and installed plugins or extensions.
- Data signals: SaaS audit events, file access, message access, and export activity.
- Ownership signals: business owner, technical owner, approved use case, and data classification.
The key is correlation. A single agent might appear as a browser app, a desktop process, and a SaaS connector, so discovery should deduplicate by workload identity, token lineage, and connected resource graph. That is where workload identity concepts from SPIFFE-style patterns and runtime policy thinking from CSA MAESTRO agentic AI threat modeling framework become useful: the goal is to know what the agent is, what it can do right now, and how that changed over time. NHIMG’s CoPhish OAuth Token Theft via Copilot Studio illustrates why OAuth-connected agents cannot be discovered by endpoint tooling alone. These controls tend to break down when cloud apps issue long-lived delegated tokens without central logging, because the agent’s real activity may never touch a managed device.
Common Variations and Edge Cases
Tighter discovery often increases operational overhead, requiring organisations to balance coverage against privacy, SaaS API limits, and false positives. That tradeoff is unavoidable because not every “AI-enabled” app is an autonomous agent, and not every connector deserves the same risk response.
Current guidance suggests separating three categories: passive assistants, delegated automation, and autonomous agents. Passive assistants may only need asset registration. Delegated automation needs scope review, ownership, and revocation playbooks. Autonomous agents need continuous monitoring, just-in-time approval paths, and tighter data boundaries. Best practice is evolving here, but the discovery outcome should still answer the same questions: who approved it, what data can it reach, and how quickly can it be shut down?
Edge cases matter. Browser-based agents can disappear into personal profiles and unmanaged devices. Endpoint agents can be packaged inside developer tools that security teams do not classify as “AI.” SaaS agents can be created by business users through low-code automation without central IT visibility. OAuth visibility is especially weak in many environments; NHIMG research notes that 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which makes token review and consent governance essential. In practice, discovery programs fail when teams rely on a single source of truth instead of reconciling browser, endpoint, OAuth, and SaaS evidence into one control plane.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, CSA MAESTRO and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | A1 | Agent discovery is needed to expose unsafe agent behavior and hidden tool access. |
| CSA MAESTRO | TRM-1 | MAESTRO supports threat modeling and lifecycle visibility for agentic systems. |
| NIST AI RMF | GOVERN | Discovery underpins governance by establishing accountability and traceability. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Discovery is required to find unmanaged non-human identities and tokens. |
| NIST CSF 2.0 | ID.AM-1 | Asset management covers discovery and tracking of AI agents across environments. |
Extend asset inventories to include agents, connectors, service principals, and SaaS automations.
Related resources from NHI Mgmt Group
- How should security teams implement shadow AI inventory across cloud, endpoint, and SaaS environments?
- How should security teams implement continuous data discovery for GDPR compliance across SaaS, cloud, and AI tools?
- How should security teams implement SSN protection across cloud, SaaS, and endpoint environments?
- How should security teams govern machine identity credentials in agentic AI environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org