Best Practices for Building Agents Recap
Arthur
Agent Security & Governance

Govern what you
cannot see.

Agents are proliferating faster than any team can track, creating security blind spots, compliance risk, and unmanaged sprawl. Arthur discovers every agent in your environment and brings it under one governance framework.

adg · agent inventorylive discovery
1,284Agents discovered+47 this week
jira-triage-agentOwner · Platform teamOTELLOW
payments-copilotUnowned · accesses PIIMCPHIGH
support-resolverOwner · CX automationOTELMED
3 unowned agents flaggedAuto-triaged into governed applications
The agent explosion is here
“Security and risk are the #1 barrier to scaling AI agents.”
McKinsey, 2026
Pillar 01 · Discovery

Gain full visibility through continuous detection.

Manual self-reporting can't keep pace with agent proliferation. Arthur runs multilayered, automated discovery that catches agents regardless of how they enter the enterprise.

Technique 01

Telemetry-based discovery

Listeners on OpenTelemetry (OTEL) streams detect new agents, tools, and configuration changes across your environment, establishing agent telemetry as a foundational, enterprise-wide capability.

Technique 02

MCP server monitoring

The Model Context Protocol is the standard interface through which agents expose capabilities. Monitor for new MCP servers to flag agents as they come online and detect capability changes in real time.

Technique 03

Network-layer analysis

Analyze network traffic for LLM API call signatures, through a dedicated proxy or general monitoring, to detect AI usage that isn't instrumented through telemetry or MCP, including non-standard frameworks.

Technique 04

API-driven discovery

Cloud AI platforms like AWS Bedrock and Google Vertex AI are beginning to advertise running agents through API endpoints, valuable coverage for agents built on managed cloud services.

Pillar 02 · Governance

From unknown risk to managed operations.

Discovery alone isn't enough. Arthur makes it frictionless to triage a detected agent, give it an owner, classify its risk, and apply the right policies, at the scale of thousands of agents.

Step 01

Discover

Continuously detect every agent across OTEL, MCP, network, and cloud APIs.

Step 02

Triage

Rank by risk, flag unowned agents, and route them for review automatically.

Step 03

Onboard

Assign an accountable owner, classify, and organize into a governed application.

Step 04

Govern

Apply guardrails and policy, then monitor continuously against them.

Arthur control plane  ·  data plane runs inside your VPC; telemetry never leaves your environment
Built for the governance function

One framework. Every oversight role.

Security, audit, and governance teams have shared a blind spot, never a shared source of truth. Arthur gives each the view they need from the same control plane.

CISO & Security

See and secure every agent

Close the visibility gap. Detect unsanctioned and unowned agents the moment they appear, and contain risk before it spreads.

  • Full inventory across OTEL, MCP & network
  • Risk scoring & anomaly detection
  • SIEM-ready: Splunk, CrowdStrike, Elastic
Audit & Compliance

Prove control, on demand

Turn agent sprawl into an auditable record. Every agent has an owner, a risk class, and an enforced policy, with the evidence to show it.

  • Immutable audit logs & lineage
  • Policy enforcement mapped to controls
  • SOC 2, RBAC, SSO & BAA support
Governance Office

Scale oversight, not headcount

Operate a centralized AI governance program across thousands of agents, with frictionless onboarding that keeps pace with the business.

  • Standardized intake & ownership
  • Tiered risk classification
  • Org-wide policy from one plane
Enterprise-grade by default
SOC 2 Type IIRBACSSO / SAMLBAAIn-VPC deploymentImmutable audit logs
Book time

Discover how Arthur can help you build secure, reliable AI at scale.

Arthur’s team brings decades of applied, academic, and enterprise AI experience to support your AI initiatives. Grab a time that works for you.

Turn unknown risk into managed operations.

See how Arthur gives security, audit, and governance one source of truth for every agent in your enterprise.