AI agent discovery
Use the ISPM console to discover AI agents in your org, assess their ownership and permissions, and view the resources they can impact.
AI agents often run as shadow AI. Your users connect them to company accounts and data without going through IT or security, so no single team has visibility into what exists. An agent acts on behalf of a user or a non-human identity (NHI), and it reaches company data through OAuth grants, managed platforms, or agentic AI tools running on employee devices.
ISPM discovers these agents wherever they run, so you can bring them under Okta's control instead of leaving them invisible. For every agent it finds, ISPM performs a deep analysis of what it can actually do: who owns it, what it can access, and the resources it can impact. For example, a user grants a third-party AI tool full access to your Salesforce data. ISPM detects the connection and surfaces it for review, so you can act on it right away.
How ISPM discovers AI agents
| Supported platform | Category | Integration guide |
|---|---|---|
| CrowdStrike Falcon | Locally running agents and MCP servers | CrowdStrike Falcon |
| Salesforce Agentforce | Builder platforms | Salesforce integration |
| Microsoft Copilot Studio | Builder platforms | Microsoft Copilot Studio |
| Secure Access Monitor (SAM) plugin | Shadow AI (Browser) | Set up the Secure Access Monitor plugin |
What each source discovers
- Locally running AI agents and MCP servers
- These are AI agents running directly on employee endpoints, along with the MCP servers they connect to for access to external tools, data, and APIs. ISPM discovers them through the CrowdStrike Falcon connector, and surfaces the results on the endpoint agents and MCP servers pages, where you can pivot between an agent and the MCP servers it connects to.
- AI agents in managed agent builder platforms
- These are AI agents your teams build inside platforms you already manage, such as Salesforce Agentforce, Microsoft Copilot Studio, and AWS Bedrock. After you connect one of these platforms, ISPM collects and analyzes AI agent metadata from the connected org and surfaces it on the Builder platform agents page, with the AI agent's owner, its status in the platform, the permissions it holds, and more.
- Shadow AI apps OAuth grants
- These are AI tools your users connect to company accounts through browser OAuth grants, without going through IT or security. ISPM discovers them using the Secure Access Monitor (SAM) plugin, which runs in managed Chrome browsers and captures the OAuth grants in real time. ISPM tags the AI-related grants and surfaces them on the Browser OAuth grants page, with the app, the granting user, and the scopes it received.
Availability and relationship to Okta for AI Agents
AI agent discovery is included with Okta for AI Agents, where it forms the discover stage of the product. If you have either ISPM or Okta for AI Agents, these discovery capabilities are included. You don't need both licenses.
Continue the lifecycle
Okta for AI Agents adds the later stages: register AI agents, connect them to resources, and govern their access. These stages are exclusive to Okta for AI Agents and aren't included with ISPM.