Book a Demo

Platform

You cannot govern what nobody has counted

Most organisations cannot say how many AI agents they run, which models they depend on, or which service accounts can invoke them. SAF3AI builds that register continuously from the surfaces you have connected — and shows you honestly which parts of the estate it still cannot see.

Key Features

Every agent, wherever it lives

Custom agents, Copilot Studio agents, Gemini Enterprise agents, Bedrock and Vertex agents, and the ones declared in code but not yet deployed — in one register.

Models and providers

Which models your organisation actually calls, through which provider, from which account. The answer to "are we exposed to this provider" becomes a lookup rather than a survey.

Tools, MCP servers and scopes

What each agent can call and whether that scope is read, write or execute — the distinction that determines whether an injection is embarrassing or expensive.

Non-human identities

API keys, service accounts and agent identities with their owner, scope and last use. The register that makes agent offboarding possible instead of theoretical.

Data and knowledge sources

The datastores, vector indexes and document sets each agent grounds in, which is what determines the blast radius when one is compromised.

Coverage and drift

Which parts of the estate you have visibility into and which you do not. Blind spots render as unknown, never as zero — a gap you can see is worth more than a clean dashboard.

The questions an inventory answers

These are the questions that arrive from a board, a regulator or an incident, usually with a deadline attached. Each one is a query against the inventory rather than a two-week exercise.

How many AI agents do we run, and who owns each one?

Every agent with its owner, surface, capability and last activity — including the ones whose team moved on.

Which of our agents can reach regulated data?

Filter the inventory by the classification of the datastores each agent grounds in.

We are dropping a model provider. What breaks?

Every agent, application and account calling that provider, with the volume behind each.

This engineer left last month. What still runs as them?

Every API key, service account and agent identity attributed to that person.

Which agents can write, not just read?

Scope-level tool inventory, so excessive agency is a filter rather than a judgement call.

What AI is running that nobody approved?

Discovered inventory reconciled against your sanctioned list, with the difference as the answer.

Get started with AI-BOM & Inventory

See how Saf3AI can help secure your AI agents.