Platform
You cannot govern what nobody has counted
Most organisations cannot say how many AI agents they run, which models they depend on, or which service accounts can invoke them. SAF3AI builds that register continuously from the surfaces you have connected — and shows you honestly which parts of the estate it still cannot see.
Capabilities
Key Features
Every agent, wherever it lives
Custom agents, Copilot Studio agents, Gemini Enterprise agents, Bedrock and Vertex agents, and the ones declared in code but not yet deployed — in one register.
Models and providers
Which models your organisation actually calls, through which provider, from which account. The answer to "are we exposed to this provider" becomes a lookup rather than a survey.
Tools, MCP servers and scopes
What each agent can call and whether that scope is read, write or execute — the distinction that determines whether an injection is embarrassing or expensive.
Non-human identities
API keys, service accounts and agent identities with their owner, scope and last use. The register that makes agent offboarding possible instead of theoretical.
Data and knowledge sources
The datastores, vector indexes and document sets each agent grounds in, which is what determines the blast radius when one is compromised.
Coverage and drift
Which parts of the estate you have visibility into and which you do not. Blind spots render as unknown, never as zero — a gap you can see is worth more than a clean dashboard.
Why it matters
The questions an inventory answers
These are the questions that arrive from a board, a regulator or an incident, usually with a deadline attached. Each one is a query against the inventory rather than a two-week exercise.
How many AI agents do we run, and who owns each one?
Every agent with its owner, surface, capability and last activity — including the ones whose team moved on.
Which of our agents can reach regulated data?
Filter the inventory by the classification of the datastores each agent grounds in.
We are dropping a model provider. What breaks?
Every agent, application and account calling that provider, with the volume behind each.
This engineer left last month. What still runs as them?
Every API key, service account and agent identity attributed to that person.
Which agents can write, not just read?
Scope-level tool inventory, so excessive agency is a filter rather than a judgement call.
What AI is running that nobody approved?
Discovered inventory reconciled against your sanctioned list, with the difference as the answer.
Get started with AI-BOM & Inventory
See how Saf3AI can help secure your AI agents.