Start here
Say a number first.
How many agents, automations and assistants are doing real work in your company right now? Not tools people open. Things that run. Pick the range you would give if somebody asked you in a meeting.
You can name everyone who works here. Now try the agents.
An agent inventory is knowing which agents exist, what each one may do, who owns it and what it did last week. By the time agents carry real work, most companies cannot answer the first part of that.
Every person in your company sits in a system. Name, role, manager, access, and a date when all of it ends. For the things that now do the work alongside them, none of that exists.
Start here
How many agents, automations and assistants are doing real work in your company right now? Not tools people open. Things that run. Pick the range you would give if somebody asked you in a meeting.
Wherever your number came from, it counted the ones you commissioned. These are the four places the others live.
How it turns up
Thomas was an operations lead. He was good with this, and over about a year he built four things that quietly took a lot of dull work off his team.
He resigned in March and left in April. Everything was done properly. Laptop back, accounts closed, access revoked the same afternoon. In June somebody in finance noticed that a weekly reconciliation had stopped. It had stopped on the day his account closed. Nobody had known it existed, so nobody had missed it for six weeks.
“The three that kept running were the ones that worried me. Not the one that stopped.”
Three of the four had been set up on a company key rather than on his own account. Those were still going in June. They are probably still going now. Nobody can say which of the two situations is worse, and that is the whole point of this page.
Composite. Real details, more than one source.
What it is
This is not a security topic, and it goes wrong the moment it is handed to security. It is the oldest organisational question there is, asked about something new. Who works here, what are they allowed to do, and who is their manager.
For people, a company answers that without thinking. There is a name, a contract, a manager, a set of permissions, a review, and a date on which all of it ends. For the things that now do the work next to them, most companies cannot produce the list at all.
What the standards bodies are doing
On 17 February 2026 the American National Institute of Standards and Technology announced an AI Agent Standards Initiative through its Center for AI Standards and Innovation. It runs on three pillars, and one of them is fundamental research into agent authentication and identity, so that interactions between humans and agents, and between agents, can be trusted.1
Alongside it sits a concept paper on agent identity and authorisation, open for comment until early April, which proposes applying the identity machinery companies already use for people to agents instead.2 In December, OWASP published a top ten for agentic applications, reviewed by more than a hundred security researchers.3
None of that tells you how common the problem is. It tells you that the people whose job it is to write standards think a company should be able to name its agents, and that today it generally cannot.
Numbers. Plenty circulate, most of them saying that nine in ten companies struggle with this and that two in ten can trace what their agents did. Every source found for those figures sells software that fixes it. They are left out rather than repeated with a caveat.4
How this differs
Three challenges in this set involve agents and they are often treated as one thing. They are not, and the order matters.
That is why this arrives late rather than early. A company on Wild West has agents nobody governs, which is challenge 5. A company on Blueprint has written the rules down. It is only once the rules are good and the ownership is clear that the quiet problem shows up, which is that the rules apply to a list and the list is incomplete.
Where it starts to bite
On the first levels there is nothing to count. On Blueprint there is a policy and usually a register, and the register is right because there are six things in it and everybody remembers all six. It is on Engine and Ecosystem, where agents are built by people who are not in the technical team and arrive inside software you already pay for, that the list quietly stops matching reality.
The uncomfortable part is that this is a symptom of having done the earlier work well. Nobody loses track of agents in a company that has not got any.
What to do
The failure mode here is not doing nothing. It is buying a platform. Start with a spreadsheet that a person maintains, because the discipline is the point and the tooling is not.
Five columns. What it is called and what it does. What it is allowed to do without asking. Whose name is on it. When it last did something. What happens to it when its owner leaves. If a row cannot be filled, that row is the finding.
Getting the list started takes one hour and one question, asked in the right way. Not which agents do we have, because that gets you the official ones. Ask instead: what runs on its own that would be missed if it stopped. Ask it in the finance team, in operations, in support. The answers will not match the official list, and the difference between the two is your actual position.
Every offboarding checklist has a line for the laptop and a line for the accounts. Add a line for what this person built. It costs nothing, it happens at exactly the moment the knowledge is still in the building, and it is the single cheapest thing on this page.
What it costs to leave it
Something will go wrong with an agent eventually. That is not the expensive part. The expensive part is the twenty minutes afterwards in which nobody can say what it was allowed to do, who set it up, or whether there is another one like it.
There are three quieter costs before that. Work stops and nobody notices, because nobody knew it was happening. Two teams build the same agent twice, because neither could see the other. And a client, an auditor or an insurer asks a reasonable question about what makes decisions in your company, and the honest answer takes a week to assemble.
None of that appears on an invoice. It appears as a company that has become slightly harder to explain to itself.
Questions people ask
No named person answers for what an agent sends, books, updates or approves.
Read this one 02Nobody wrote down what an agent may decide on its own, and what it must always hand to a person.
Read this one 07The work that runs through accounts the company never provisioned and cannot see.
Read this oneThe full set of what goes wrong inside a company once people start using AI: work that nobody owns, control that quietly slips, leadership decisions made on an out of date picture, and a culture that shifts before anyone names it. Every one with the research behind it, where it sits in the five levels, and a test you can run this week. One page, no email.
Getting going
If the answer is nobody, that is the finding. Counting is a morning of work and it tells you more about how your company runs than a quarter of dashboards.
First profile free · no credit card · built by emaho