A useful experiment can keep running after its creator changes teams. That is how a lot of “shadow agents” start. Not malware. Just an agent outside the inventory somebody would actually review.
Microsoft’s agent security guidance calls out the same pattern: untracked deployments, temporary agents left running, and permissions that outgrow the job. Okta’s agentic enterprise blueprint splits the problem in two. Finding the integration is discovery. Deciding what it may do is a separate control.
Here is a concrete version of the mess.
A support team builds an assistant to summarize tickets. Later, an administrator finds its connector still using a staff account, but cannot match the workflow to any approved registry entry. It runs every evening. Somewhere along the way it also started drafting customer replies, not just summaries. The person who built it moved roles. Nobody formally owns the expanded version.
Pause outbound replies while someone reviews the job. That is the easy part. The harder part is the decision after you find it:
- Bring it under governance (named owner, access matched to the task, registry entry).
- Restrict it while gaps get fixed, with an expiry on the exception.
- Retire it if the experiment ended or has no continuing owner.
- Escalate if the evidence looks like compromise, data exposure, or unauthorized changes.
Typing “restricted” into a spreadsheet does not restrict anything. The deployment, gateway, or identity provider has to enforce it.
One more trap: shared credentials. If the connector rides a person’s account, the logs may show that person, not the workflow. Google Cloud’s MCP guidance makes the same point for production: use a separate agent or workload identity, or you will spend your afternoon guessing which automation just touched customer data.
A public name helps after you decide to keep the service. Customers and partners need a maintained reference for the approved offering, not a leftover experiment with the same brand. A domain does not discover hidden runtimes, and it does not grant approval. It only gives the thing you chose to keep a place people can find again.
Full writeup with the discovery sources, triage record, and the “keep / restrict / retire / escalate” paths:
https://headlessdomains.com/blog/shadow-agents/
When you last audited agent connectors in your org, what showed up first: an unowned experiment, a shared staff credential, or a tool grant that had quietly widened?
Source: r/HeadlessDomains · by /u/fannybumper