Discovery
What it does
Finds what AI is running, from the gateway and the tools you already run; see every agent, including shadow ones.
Discovery works two ways at once. From the gateway's own audit stream it reconstructs every agent that already routes through IntentGate, with the tools it calls and the data it touches. In parallel it ingests logs from tools you already run, Zscaler, Netskope, Defender, Infoblox DNS, and flags anything talking to a known AI endpoint, surfacing shadow agents that never touched the gate. Both feeds converge into one inventory that de-duplicates automatically.
When it applies
From the moment IntentGate is connected, before any routing, and continuously as new agents, tools, and egress sources appear.
How it works
The gateway sees the agents in the estate from its own traffic, and shadow agents are imported from CASB, proxy, DNS, and cloud logs, so unsanctioned AI is surfaced rather than hidden.
In practice
A team spins up an unsanctioned agent; it appears in discovery as shadow, not routed, with an owner to assign.
What you get
The inventory shows every agent, the tools it touches, and its risk signals.
Why it matters
See every agent, including the unsanctioned shadow ones.
You cannot govern or secure what you cannot see, and most organisations have no inventory of the AI agents already calling tools and models, including shadow AI stood up by teams without approval. Discovery removes that blind spot so every agent has an owner and a risk tier before it can do harm, which is the precondition for every other control.