Discovery comes first because you cannot tune monitoring for tools you have not found. Once agents are identified, telemetry becomes the control that turns visibility into evidence, alerting and investigation. A programme that does both in parallel is stronger, but undiscovered agents are the higher immediate risk.
Why Discovery Has to Come Before Telemetry for AI Coding Agents
For AI coding agents, telemetry is only useful after you know which tools, plugins, CLIs, IDE extensions and automation accounts actually exist in your environment. Discovery establishes the inventory and ownership picture, while telemetry turns that inventory into evidence, detection and investigation. In practice, discovery is the prerequisite for tuning, scoping and prioritising the monitoring that follows.
Undiscovered agents create a blind spot: security teams cannot set log sources, retention or alert thresholds for assets they have not identified. That makes discovery the first control step, not because telemetry is unimportant, but because telemetry without inventory is usually partial, noisy or mis-scoped.
When teams discover agents first, they can distinguish sanctioned assistants from shadow tools, decide which accounts and tokens matter, and identify where agent activity should be observable. That lets telemetry focus on the highest-value behaviours, such as command execution, repository changes, secret access and unusual API use, rather than generating undifferentiated noise.
What Discovery Changes About the Monitoring Problem
Discovery changes the problem from “Can we see everything?” to “Can we see the right things?” For AI coding agents, the relevant surface often spans IDE extensions, local CLIs, containerised development environments, CI/CD automation and connected SaaS integrations. Once those entry points are known, teams can map which shadow AI and agent discovery signals expose them and then decide what should be logged, reviewed or blocked.
That inventory work also determines scope. A developer workstation agent with access to source code has very different monitoring needs from a CI helper with deployment rights or a repository assistant with write access. Discovery is what reveals those privilege boundaries, so telemetry can be tied to the right identities, repositories, pipelines and command channels.
Discovery also improves signal quality. If an agent is discovered only after a suspicious event, the team is forced into retrospective forensics with incomplete context. If the agent is known early, telemetry can be configured to capture the exact prompts, tool invocations, credential use and file paths that matter. That is the difference between best-effort logging and evidence that can support an incident decision.
How to Use Telemetry Once Agents Are Found
Telemetry becomes the control layer once discovery has produced a usable inventory. The goal is not to log everything, but to make agent actions attributable, reviewable and alertable. For AI coding agents, that usually means binding logs to the discovered toolchain, recording prompt and tool events, and preserving enough context to explain why the agent touched code, secrets or infrastructure.
Security teams should treat telemetry as a prioritisation exercise. An agent that can open pull requests may need different logging from one that can execute shell commands or reach cloud APIs. Where an agent can change code or invoke external tools, telemetry should capture the action, the trigger and the surrounding context so reviewers can distinguish normal automation from misuse or compromise. AI agent observability and incident response becomes most valuable after discovery has identified which agents deserve that level of scrutiny.
Telemetry should also be validated against the real failure modes of coding agents: prompt injection, over-scoped credentials, unsafe repository instructions and unintended destructive actions. If the logs do not show tool calls, identity context or output that influenced execution, they will not support investigation when the agent behaves badly. Good telemetry proves what the agent saw, what it did and what access it used.
Risk and Threat Considerations
Undiscovered AI coding agents are a material exposure because they can act with developer credentials, repository access or deployment authority before defenders know they exist. In that state, telemetry gaps are not just an observability issue, they are an attacker opportunity: malicious instructions, poisoned repositories or stolen tokens can drive autonomous actions without clear monitoring.
Failure mechanism: Security teams focus on telemetry first, but the agent estate is incomplete, so logs are wired to the wrong places, alerts miss the real tools and attacker activity blends into unmonitored automation.
Impact: The organisation keeps false confidence in its monitoring while exposed agents retain the ability to modify code, exfiltrate secrets or trigger destructive changes before detection.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while CIS Controls v8 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Discovery and ownership are needed to remove obsolete AI coding agents cleanly. |
| NHI-02 — Secret Leakage | AI coding agents often touch secrets, so telemetry must expose secret-access events after discovery. | |
| NHI-05 — Overprivileged NHI | Discovery reveals where coding agents have excessive access before telemetry is tuned. | |
| Recommendation — Inventory agent accounts and revoke access promptly when tools are retired. Log and alert on agent access to secrets, tokens and keys. Map each agent to least-privilege access and remove unnecessary permissions. | ||
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Coding agents become risky when discovered identities or privileges are broader than intended. |
| ASI02 — Tool Misuse | Telemetry must capture tool calls once discovery identifies which agent tools exist. | |
| Recommendation — Constrain agent identity and privileges to the minimum required for each task. Monitor tool invocations and flag unexpected or unsafe tool use. | ||
| CIS Controls v8 | CIS-5 — Account Management | Discovery establishes which accounts and automation identities need governance and logging. |
| CIS-8 — Audit Log Management | Telemetry is the audit layer that becomes useful after agent discovery has defined scope. | |
| Recommendation — Maintain an authoritative inventory of agent-related accounts and remove unneeded ones. Collect and retain logs for discovered agent actions and high-risk events. | ||
| OWASP ASVS | V16 — Security Logging and Error Handling | Agent telemetry must record execution context, errors and security-relevant actions. |
| Recommendation — Log agent actions with enough context to support detection and investigation. | ||
Practitioner Guidance
What to prioritise: Build a complete, ownership-linked inventory of AI coding agents, then attach telemetry to the discovered tools, identities and execution paths that can actually change code or infrastructure.
What to verify: Confirm that each discovered agent has a named owner, a defined access boundary and at least one logging path that captures tool use, authentication context and high-risk actions. Where an agent can reach production resources, verify that alerting and review are in place before broadening rollout.
Practitioner takeaway: Discovery is the control that makes telemetry trustworthy; until you know what exists, monitoring for AI coding agents is more approximation than evidence.
Related resources from NHI Mgmt Group
- Should security teams prioritise shadow AI discovery or policy writing first?
- Should teams prioritise runtime validation or cloud discovery for AI security first?
- How should security teams prioritise NHI remediation in cloud environments?
- How should security teams handle risks from AI browser extensions?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org