Discover and assess AI agents
Agent discovery is the first stage of the AI agent lifecycle. Finding the AI agents operating across your environment helps you assess their ownership, permissions, and the resources they can affect. You can decide which agents to register, connect, and govern.
The discovery capabilities, the procedures, and the console pages are documented in the Okta Identity Security Posture Management (ISPM) AI Agents section. See AI agent discovery.
What discovery covers
ISPM discovers AI agents from several sources. Each source surfaces a different category of AI agent and is powered by an ISPM integration. The table below maps each category to the platforms that surface it and the guide for setting up that integration.
| Supported platform | Category | Integration guide |
|---|---|---|
| Secure Access Monitor (SAM) plugin | Shadow AI (Browser) | Set up the Secure Access Monitor plugin |
| CrowdStrike Falcon | Locally running agents and MCP servers | CrowdStrike Falcon |
| Salesforce Agentforce | Builder platforms | Salesforce |
| Microsoft Copilot Studio | Builder platforms | Microsoft Copilot Studio |
Continue the lifecycle
ISPM finds shadow AI agents, and lets you assess the risk each one poses. From there, you can register the AI agent, or import it into Okta Universal Directory (UD), to bring it under Okta's governance and start securing its access.
After you discover and assess an AI agent, continue through the rest of the Okta for AI Agents lifecycle:
Okta Identity Security Posture Management (ISPM) is excluded from the Okta for AI Agents - Core SKU, which is the version of Okta for AI Agents available to FedRAMP Moderate and FedRAMP High customers. Okta for AI Agents - Core is not available in Okta for US Military cells. For a current list of features that are excluded from the Okta for AI Agents - Core SKU, see Okta US Public Sector Limitations or Exceptions.