Endpoint Agent Discovery Isn't Enough: The Case for a Comprehensive Agent Discovery Layer
Endpoint agent discovery is the buzzy entry point for AI security right now. Scan the laptops and workstations across your fleet, look for AI tools employees installed on their own, and build an inventory of what's running. The scan surfaces Claude, Codex, Cursor, OpenClaw, LM Studio, Perplexity, and the rest of the AI applications spreading through a company one download at a time.
That inventory answers a real question: what AI is running on our machines? But it answers only that one question, about one surface. Agents enter the enterprise from many directions, and most of them never touch a managed laptop. If your agent discovery strategy stops at the endpoint, you're looking at a slice of your agent footprint and treating it like the whole picture.
The shadow agents you can't see are the ones you can't govern. Closing that gap means discovering agents wherever they run, not only where a device scanner can reach.
Why endpoint-only discovery leaves gaps
Endpoint discovery catches AI applications installed on managed devices. That's genuinely useful for a specific problem: an employee running a coding agent or a desktop LLM client on a corporate machine. The trouble starts with everything that never lands on an endpoint at all.
A large share of agentic AI runs nowhere near a laptop:
- Agents deployed in cloud environments like Vertex AI, Bedrock, and Agent Foundry, plus agents spun up inside CI/CD pipelines.
- Agents that expose their capabilities through MCP servers, the Model Context Protocol interface other agents and tools call.
- Agent traffic flowing through LLM gateways and proxies that sit between your applications and a model provider.
- Server-to-server and API-driven agent calls that execute entirely in your backend and never hit a monitored device.
None of that shows up in an endpoint scan. The result is an inventory that looks complete on a dashboard but has structural blind spots. A security team can sign off on "we scan every laptop" and still miss the payments copilot calling a model through a gateway, or the retrieval agent running in a cloud job. Comprehensive discovery has to reach every surface an agent can run on, not just the one that's easiest to instrument.
The five surfaces a comprehensive discovery layer covers
No single technique catches every agent. Coverage comes from running several methods together, each tuned to a surface the others miss.
- Endpoint. Device-level detection of AI tools installed across the fleet, the surface most of the current buzz is about.
- Telemetry (OpenTelemetry). Listeners on OTEL streams detect new agents, tools, and configuration changes as they emit traces. OpenTelemetry has become the standard for agent telemetry, which is why instrumenting agents to emit traces is the foundation everything else builds on.
- MCP server monitoring. Watch for new MCP servers appearing in your environment to flag agents as they come online and detect capability changes in real time.
- Network-layer analysis. Inspect traffic for LLM API call signatures, through a dedicated proxy or general monitoring, to catch AI usage that isn't instrumented through telemetry or MCP, including non-standard frameworks.
- API-driven discovery. Query cloud AI platforms like AWS Bedrock and Google Vertex AI, which increasingly advertise running agents through API endpoints.
Endpoint discovery is one column in that list. Run only that column and you inventory installed desktop tools while missing agents in the cloud, behind gateways, and calling each other over MCP. The value is in running all five surfaces under one framework so a new agent gets caught regardless of how it entered.
Discovery fits into your stack, it doesn't replace it
Every enterprise already runs a security stack. There's endpoint detection and response on the laptops, usually more than one agent per machine, one tuned for EDR and another for compliance. There's a SIEM aggregating security signal, and increasingly there's an AI gateway or proxy in front of model traffic. A comprehensive discovery layer plugs into that stack rather than asking a CISO to rip it out.
That plug-in works through direct integration with the SIEM providers security teams already run, including Splunk, Microsoft Sentinel, and CrowdStrike Falcon. Agent discovery signals land where analysts already work, in the tools they already trust. For most teams this is a configuration change, not a rebuild. SIEMs were purpose-built to fork traffic and route it where it needs to go, so pointing agent signal into them takes an hour or two of setup, not a new integration project.
The framing that matters here: close the AI gap in your security stack. Endpoint agents, EDR, and SIEM are strong at what they were built for, but none of them was designed to catch agents proliferating across cloud, network, and MCP. A discovery layer fills exactly what they miss without replacing what already works.
Discovery is step one, not the destination
A raw list of unregistered agents is a starting point. It tells you what exists, not whether any of it is safe to run. Discovery on its own produces an inventory, and an inventory is not governance.
The work that turns discovery into control comes next. Every discovered agent needs an accountable owner, a risk classification, and a place in a governed application rather than floating as an unmanaged entry on a dashboard. From there the runtime controls apply: behavioral analytics against real production traffic, guardrails that intercept bad inputs and outputs in real time, and continuous evaluation of how each agent actually behaves.
This is the throughline that separates a comprehensive strategy from a scanner. Discovery gives you the map of every agent across every surface. Governance is what turns a discovered inventory into a governable agent with an owner, policy, and monitoring, which is what makes those agents safe to operate at scale.
What "comprehensive" should mean when you evaluate a discovery strategy
If you're assessing an agent discovery approach, four questions separate a full strategy from an endpoint scanner wearing a bigger name:
- Does it cover all five surfaces (endpoint, telemetry, MCP, network, and cloud APIs), or just the endpoint?
- Does it integrate with the SIEM and security tooling you already run, so signal lands where your team works?
- Does discovery flow directly into ownership, policy, and continuous monitoring, or does it stop at a list?
- Does your data stay inside your own environment throughout?
Endpoint agent discovery answers one question well. It tells you which AI tools your employees installed on their machines, and that's worth knowing. But an agent footprint spans cloud jobs, MCP servers, gateway traffic, and API calls that no device scan will ever see. A discovery layer built for all of it, wired into the stack you already run and connected straight through to governance, is what gives a security team the full inventory and the controls to act on it.
See every agent in your environment
Arthur discovers agents across endpoint, telemetry, MCP, network, and cloud, then brings them under one governance framework with ownership, policy, and continuous monitoring.
Book a demo with an AI expert to see comprehensive agent discovery on your own stack, or explore the Agent Development Toolkit to start building.