What is running?
Agents appear on laptops, in code, in CI and across infrastructure before security knows they exist.
You can't secure agents you don't know exist. Barrikade finds the agents already running across your company, shows who owns them and what they can touch, then follows them into runtime.
AI agents are becoming a new class of identity inside the enterprise.
Except they often use somebody else's credentials. Nobody knows all of them exist. Nobody necessarily knows who owns them. And unlike ordinary software, they do not just hold data. They act.
Before another guardrail, answer four simpler questions.
Agents appear on laptops, in code, in CI and across infrastructure before security knows they exist.
Many agents borrow a developer's credentials, leaving no clear owner behind the action.
A valid credential does not explain the agent's job, its boundaries or whether this action belongs to either.
When the trail is split across models, tools and services, nobody can reconstruct the full action.
Lens does not hide behind a risk score. Every finding carries the evidence that produced it, how confident Lens is, and what the scan could not inspect.
npx barrikade-lens scan --scope repo --path ..github/workflows/ci.ymlDeployment manifestConfirmedapi/openapi.yamlAPI descriptorConfirmedAGENTS.mdRepository contextNot counted as an agentValid repository descriptor plus high-specificity deployment and API evidence. An instruction file is retained as context, not promoted into an agent finding.
Independent coverage and institutional recognition for the work behind Barrikade.
These are not four disconnected features. They are the steps needed to turn an unknown software actor into something your team can see, bound and hold accountable.
Lens scans endpoints, repositories, CI and Kubernetes to build one inventory of agents, models, MCP servers, tools, APIs and workflows.
Source: Open source · Apache-2.0Explore find →Connect each agent to an owner, a clear purpose, the account it uses and the access it should have.
Source: Platform direction · in developmentCore checks inputs, watches the session for changes in the agent's task and can flag, block or escalate risky activity.
Source: Available in Barrikade CoreExplore protect →Core records the task, permissions, tool use, outside services, warnings, interventions and outcome in one report.
Source: Incident reporting in CoreExplore explain →Scroll through one agent's journey. Barrikade carries context from the first discovery signal to the final record, instead of treating every action as an isolated event.
Lens finds the agent where it actually lives—across code, endpoints, CI, Kubernetes and MCP—and maps the tools and models around it.
The identity layer connects the agent to a responsible owner, a declared purpose and the access it should be allowed to use.
Core follows the task, checks untrusted input and watches for risk or behaviour that moves away from the agent’s approved purpose.
The task, authority, tools, risk signals, response and final outcome stay together—so your team can explain what happened later.
If risk rises, the application can block the action or ask a person to step in. The session record keeps the task, authority, tools, warnings, response and outcome together.
Security starts with an honest account of what exists. That rule applies to our product too.
We do not put available now on roadmap slides.
An agent can pass an identity check and still move outside its job. Barrikade is built to keep the original task beside the action, all the way through runtime.
Identity is platform direction. This passport shows the model Barrikade is building.
In alpha, the application must enforce Core's decision. Barrikade does not claim universal blocking.

Barrikade Core began as an undergraduate research project developed with design input from Jentic. Work on prompt-injection detection exposed the larger problem: organisations were deploying autonomous software without the identity and accountability infrastructure built for people and machines.
Barrikade is the attempt to build that missing layer—starting with evidence of what is already there.
Read the Barrikade story →What works today, what is in alpha and what we are building next.
AI agent security means knowing which agents are running, what they can access, whether they stay within their task and what to do when they do not. It also means keeping enough evidence to explain their actions later.
Lens looks for agents, agent frameworks, MCP servers, skills, models, APIs and workflows. It can scan endpoints, repositories, CI and Kubernetes, then bring the results into one shared inventory.
Lens sends inventory and short, sanitized evidence—not prompt text, source code, command-history lines, environment values, credentials or secrets. It also converts absolute paths into organization-specific hashes.
Core checks input in stages instead of trusting one detector. It starts with fast rules and signatures, then uses embedding and machine-learning checks and can call a local judge when needed. It returns allow, flag or block, plus a record of which stage raised the concern.
Intent drift happens when an agent starts moving away from the task it was given. Core tracks that change across a session and can raise the response as the risk grows.
Core can return a block decision and recommend actions such as halt, reduce access, try again, ask a person to step in or revoke access. In alpha, your application must connect those decisions to the system that controls the agent; Barrikade does not claim universal control.
A service account tells you which credential was used. Agent identity should also tell you which agent used it, who owns that agent, why it was acting and what access it should have. This identity layer is still platform direction for Barrikade.
A WAF or API gateway checks traffic at a network or request boundary. Barrikade adds context about which agent acted, what task it was given, which tools it used and how its behaviour changed. It is designed to work alongside gateways, identity systems and security monitoring tools.
Yes, the Lens Hub and its collectors are designed for self-hosting. Core is available as a Python package and API container. Production requirements still need to be checked for each environment; Barrikade does not currently offer an air-gapped or availability guarantee.
Join the waitlist for product updates, early-access opportunities and release news. If you want to discuss a current environment, book a discovery call.
Run Lens today. Join the waitlist for the platform Barrikade is building around it, or book a call to assess your current agent environment.
Find your agents with LensRun an agent security assessment