Discovery · DNS
Nudge Security Turns Agent Discovery Inward: Finding the Agents Employees Already Built
Most agent-discovery infrastructure being built right now — DNS records, agent:// URIs, directory entries — assumes agents are things you deliberately register. Nudge Security's new AI agent discovery feature starts from the opposite assumption: employees are already creating agents inside Copilot Studio, Salesforce Agentforce, n8n, and similar platforms, often with no security team in the loop, and the first job of governance is just finding them.
The feature uses two discovery channels. Nudge Security uses two complementary discovery channels to find agents created across popular agentic AI platforms: connected apps enable API-based discovery for platforms like Salesforce Agentforce, Microsoft Copilot Studio, Google Gemini, ServiceNow, n8n, Tines, ChatGPT, Abacus.AI, and Workato, while a browser extension passively observes agent creation on platforms that don't expose API hooks, including Cursor automations, OpenAI Agents Workflows, Zoom AI Workflows, Atlassian Rovo, Retool, and Zapier Agents.
The accountability angle is the more interesting part. The system doesn't just log that an agent exists — it maps the agent back to the human who built it and prompts that person for context on what the agent is for, populating an intent field automatically so accountability is documented without manual follow-up. Every discovered agent, regardless of which channel found it, lands in one inventory view, giving security teams a single place to check permissions, connected data, and ownership.
The framing from Nudge is blunt about the problem this solves: employees are deploying AI agents faster than security teams can track them, and the company says this has already produced real exposure, with a large share of organizations reporting unauthorized access or data exposure tied to agent permissions. CEO Russ Spitler frames this as a structural bet — that organizations building a real inventory now will have an advantage as agentic AI becomes the fastest-growing enterprise priority.
What's notable is the shape of the solution: no new deployment burden for the platforms it already monitors, and browser-level observation as a fallback for the platforms that don't expose clean APIs. That's a pragmatic answer to a problem the DNS- and protocol-layer discovery efforts (agent registries, .well-known files, directory entries) don't really touch — those systems help you find agents that want to be found. Nudge's bet is that a large fraction of the agents actually running in a given company right now don't want to be found at all, because nobody making them thought about visibility in the first place. It's currently labeled a research preview, meaning the platform coverage and detection logic are still expanding based on what customers are actually running into.
The distinction matters for anyone thinking about agent accountability as a protocol problem. Registries and signed identities work when creation is intentional. Shadow-agent sprawl inside SaaS tools is a different failure mode, and it's the one enterprises are apparently already living with.