More than 80% of the Fortune 500 are already running AI agents. That’s from Microsoft’s own Cyber Pulse research. Most were built with low-code and no-code tools, by people who don’t sit in IT, and nobody drew a map.

That’s not adoption. That’s sprawl.

Here’s how it happens. Finance spins up a copilot to chase invoices. Sales builds a bot to draft follow-ups. Ops wires an agent into a system of record over a weekend. Every one of them solves a real problem. None of them know the others exist.

I’ve walked into orgs that couldn’t tell me how many agents they were running. Not wouldn’t. Couldn’t. Those agents held access to data, could trigger actions, and answered to no one in particular.

We spent fifteen years learning this with identity. Accounts multiplied faster than anyone governed them, and the cleanup was brutal. Agents repeat the pattern, except they don’t just hold access. They act, at machine speed.

The fix isn’t a platform purchase. It’s an inventory.

And it costs nothing to start. One row per agent. For each, name four things: who owns it, what it’s allowed to touch, what it’s allowed to do, and who can shut it off. The first row you can’t fill in is the risk you didn’t know you had.

Most orgs are still counting agents like trophies. The ones who pull ahead can name every one and say who’s accountable for it.

You can’t govern what you can’t see. Right now, most can’t see.