Pattern 05 · Shadow AI
It was already calling. Nobody had approved it.
An agent starts making real calls before anyone files the paperwork for it. A server starts fielding them before anyone has reviewed what it is. Neither of those stops anything from acting — it only stops anyone from knowing, unless something is built to notice exactly that.
It was already acting before anyone knew it existed.
None of this requires anything unusual. It is simply faster to start something calling than to finish the process meant to review it, and a credential is easy to reuse and hard to attribute to one specific caller once it is shared.
Registration lags reality
An agent goes live, or a server starts fielding real calls, the day a team needs it. Whatever process is supposed to review it happens afterward, if it happens at all.
A shared credential hides who is really calling
Several agents commonly sit behind one service account or API key. The identity a system sees is the credential, not the specific piece of software actually using it that day.
It surfaces during an incident, not before
The usual moment anyone learns an unapproved agent or server existed is while reconstructing what happened afterward — under time pressure, from logs, rather than from something anyone could have checked in advance.
A roster only knows who was entered into it.
Most inventories — of agents and of servers — are declared, not observed. If something was never entered into the system that tracks it, it does not appear there, no matter how much activity has already passed through it.
Network gateways and traffic proxies can often see that a call happened. Seeing traffic is not the same as knowing whose agent made it or whether the destination was ever reviewed — most of that layer routes calls, it does not keep a status for the caller or the server behind them.
Approval is not a precondition for being seen or governed.
The same idea applies on both sides of the call. Neither an agent nor a server has to be reviewed first to enter the picture — each is treated as real the moment it exists, and dealt with accordingly.
Agents
Found from the calls themselves
Every governed call carries a caller identity. That identity is checked against the roster of known agents, and anything that does not match becomes a new record automatically — not because someone filled out a form for it.
Checked continuously, not once a quarter
The check runs on a short, fixed interval rather than waiting for the next access review, with a rolling lookback so a restart does not lose track of what happened while it was down.
Precise about what counts as an agent
Only traffic carrying an actual agent or service identity is ever materialized. A person calling a system directly under their own login is never mistaken for a phantom agent.
A decision, not just a data point
A newly found actor sits with what it has actually done so far — first seen, last seen, how many calls — until an operator approves it or blocks it. Once blocked, it stays blocked.
Servers
An unapproved server is a real state, not an edge case
A server carries the same status model already used for agents: approved by default, with an explicit state for one that exists in the picture but has not been reviewed. It does not quietly pass as something it is not.
Flagged everywhere the graph is used
It renders visibly differently — its own color, a dashed outline, a marker that it has not been vetted — in the full estate view and in the focused view for the specific server, person or agent it touches. Never blended in with what has been reviewed.
Not a special case for policy or reachability
Nothing in how a rule is evaluated or a path is traced checks whether a server has been approved. The same mechanics that govern an approved server apply to this one — only how it is drawn is different.
What was seen, kept separate from what was adopted
The endpoint actually behind an unapproved server — a hostname, an address, sometimes only an identifier — is recorded on its own, so approving it later does not overwrite the record of how it first appeared.
Finding an agent does not depend on the day someone remembers to register it. Governing a server does not depend on someone approving it first. Both are treated as real from the moment they appear, not from the moment they are reviewed.
Where this control ends.
- We see an agent the moment it makes a governed call, not before.If something never calls through a path we are attached to, there is no activity to check against the roster, and it stays invisible the same way it was invisible to everyone else.
- A newly found actor is unverified, not proven safe.Being found is not the same as being trusted. It sits as a flagged, unverified record until an operator makes the call to approve or block it.
- A server still has to enter the picture somehow.The model is built to treat an unapproved server correctly the instant it exists in the catalog — flagged clearly, governed like anything else, never blended in with what has been reviewed.
If you cannot say who all of your agents are, or what all of your servers are.
Most organizations cannot answer either question fully, and the activity already happening is usually the fastest way to start closing the gap.

