Level one · the estate
The roster you wrote down, against the estate you actually run.
You maintain a list of the agents you know about. Agenor builds a second list from behaviour alone, out of telemetry you are already emitting, then reconciles them. An asset takes its kind from your declared roster, and an undeclared one is reported as a shadow rather than quietly typed. Every finding carries its app and its environment, so a shadow in dev reads differently from the same shadow in production, and neither is hidden from you. It is not only agents: tools, MCP servers, skills, identities and permissions are inventoried the same way, because that is where an agent's real reach comes from. Sources are first-class too, and a collector with no owner reads owner null, since an unowned source is a finding rather than a blank to fill with a default.
What a trace-based inventory cannot seeWe find agents from the telemetry they emit. An agent that emits nothing is invisible to us, so this is a floor on your estate and never a certified ceiling. Where a framework or a gateway can be made to emit, we will tell you which one and what it costs; where it cannot, that gap is named in the report rather than rounded away.
ESTATE · RECONCILED5 declared7 undeclared
billing-opsprodstripe · ledger-dbdeclared
support-triageprodzendesk · customer-db(read)declared
invoice-botprodnetsuite · s3://invoicesdeclared
deploy-helperstggithub · k8s-stagingSHADOW
crm-writerprodsalesforce(write)declared
spend-guardprodstripe(read) · slackdeclared
eval-harness-3devopenai · s3://eval-outSHADOW
mcp-filesystemdevlocal-fs · repo checkoutSHADOW
notebook-runnerdevwarehouse(read) · pypiSHADOW
media-buyerstggoogle-ads · stripeSHADOW
intern-copilotdevgithub · jira · customer-db(read)SHADOW
prod-debug-agentprodk8s-prod · logs · secrets-managerSHADOW
7 of 12 observed in telemetry appear on no declared roster · specimen data