Agentic Inventory Matrix
What agents exist, what they touch, what threats they face?
Filter
Layers, by what they can actually enforce
- Self-declared — advisory
The agent reports itself. It can be wrong, stale, or absent entirely.
- Operator-declared — deterministic-when-invoked
The operator registered it. Accurate only as far as the operator knows.
- Discovered — deterministic-and-external
Found independently by scanning the target. Trusts neither of the above.
Showing 5 of 15.
Identity at Discovered
CloudTrail / GCP Audit Logs of SA and IAM principal usage. K8s controller watching SA+RoleBinding by naming pattern. Reverse-lookup from credential fingerprints in Sentinels.
Authorization at Discovered
K8s RBAC API list, AWS IAM Access Analyzer effective permissions, Kyverno PolicyReports of policies actually applied.
Blast radius at Discovered
Threat-modeling output (MAESTRO Layer 7, MITRE ATLAS, lateral-movement path analysis). Behavioral observation of what the agent has touched.
Approval gating at Discovered
Registry of charter files in source control. Last-modified, last-PR-merged. Cross-reference with self-declared and operator-declared.
Supply chain at Discovered
Image-registry pull events, package-manager logs, runtime introspection of loaded models and connected MCP servers, SBOM scanning. Drift between actual and authorized = alert.