Resources
Most teams can list their users and IAM identities, but not every AI agent or MCP server acting in their environment. Start with an inventory that discovers agents and MCP connections, maps each agent to its tools and calling identity, and records tool calls. Then put the traffic through a gateway so unsafe calls, spend, and evidence can be governed.
Agent discovery is the prerequisite for agent policy. IAM identifies people and services; it does not by itself identify every agent, MCP server, tool call, or downstream spend path. Pair discovery with the outbound Gateway hook: agents have IAM; spend/tool calls don't. UnitOne Gateway gives teams that control path. Start free.
Agents can be embedded in apps, developer workflows, internal automations, and vendor products. MCP servers add another inventory surface: tools, data access, and dependencies. If you cannot name the agent, owner, tools, and calls, you cannot govern the path.
Which agents and MCP servers exist? Who owns them, where do they run, and which model or provider do they use? Which tools, data sources, identities, and environments can they reach? Keep those relationships — a list of application names is not an inventory you can govern.
Combine deployment and configuration records, network and gateway telemetry, tool registrations, and IAM context. Normalize agent, MCP server, tool, owner, environment, and call relationships. Mark unknown or unmanaged assets for review rather than pretending the inventory is complete.
IAM answers who is authorized. Call-level visibility answers what the agent did. Attribute calls and spend to agent and team, apply tool controls, and retain useful evidence. Use Gateway as the enforcement and observability layer. Discovery alone does not block activity.
Start with the highest-volume agents and MCP servers. Assign owners and risk tiers, review reachable tools, and set a recurring inventory check. Start free with UnitOne Gateway, then expand coverage as the estate becomes legible.
Start free on Gateway so discovery, tool calls, and spend sit on one inspectable path. See Gateway for how the control plane works. Discovery shows what exists and what can be called; Gateway provides the control and attribution path.