AI agent discovery

Inventory is useful only when the evidence and blind spots are visible.

Agent discovery identifies autonomous systems, the capabilities connected to them and the surfaces where they operate. A credible inventory also states confidence, provenance and coverage.

Discovery Snapshot 1.1
EndpointRepository / CIKubernetes
↓ sanitized evidence ↓
System inventoryEntitiesRelationshipsCoverageChange
No prompts, credentials or configuration bodies

Discovery is broader than a registry

A registry describes systems that someone deliberately registered. Brownfield discovery also has to find local coding agents, repository-defined agents, MCP configuration, model servers, agent frameworks, workflow descriptors and deployed workloads across different teams.

The objective is not to label every AI-related file as an agent. Supporting runtimes, framework use and explicit autonomous-agent definitions should remain distinct facts.

Confidence requires evidence rules

Product names and filenames are useful hints, but weak signals create misleading inventories. Higher-confidence discovery validates authoritative descriptors or combines independent evidence families such as configuration shape, process state and a recognized deployment artifact.

Each finding should keep its supporting locator, collection source, observation time and confidence. That evidence makes review and correction possible.

Coverage is part of the result

A count without a denominator can look complete when entire surfaces were never scanned. Discovery should report the targets reached, partial collectors, unavailable locations and expected population when the organization knows it.

Lens implements these principles through its Discovery Snapshot contract, coverage views and factual attention queue. It does not convert uncertainty into a risk grade.