Sweet Product

Sweet Enables Improved Shadow AI Discovery and Control with AI Agents Catalog

Chris Lentricchia

October 7, 2026

Share

Today, we are pleased to announce the release of the Sweet AI Agents Catalog. The catalog enables security teams to discover AI agents - including shadow AI - understand their capabilities and risks, and bring them under protection. Using live runtime traffic, Sweet connects agents and their sub-agents to the cloud workloads they run on, giving teams the visibility needed to take control of their AI environment.

Closing the Visibility Gaps That Leave AI Outside Your Control

AI adoption is moving faster than the processes built to govern it. Teams can deploy agents that access sensitive data, carry credentials and take actions through connected tools without security knowing they exist. Even an approved agent can delegate work to sub-agents whose access and behavior have never been reviewed. Security teams are responsible for protecting this expanding environment, but developer documentation and manually maintained inventories cannot reliably tell them what is running, what it can do or whether it is protected.

Knowing an agent exists is only the beginning. Security needs to understand its capabilities and the environment around it. An agent that searches customer records presents a different concern from one that can change them. An agent running on a restricted workload presents a different concern from one on an internet-exposed workload with an active incident. Without that context, teams struggle to determine where protection is needed most.

Discover Shadow AI and Understand Where It Puts You at Risk

The Sweet AI Agents Catalog, accessible from the catalog subsection of the AI section, builds an inventory from model calls observed by the Sweet sensor, without requiring developers to register each agent. It identifies the entry point that receives requests, the sub-agents that use tools or delegate work, and the tasks that perform individual model calls. Sweet groups these components into an agent with a generated name and description, bringing previously unreported agents into view alongside known deployments.

Security teams can see how an agent’s members work together, which models they use and whether they have gateway coverage. A delegation graph follows the flow from the entry point through the components it invokes. That gives teams a practical starting point for investigating unfamiliar AI activity and reviewing deployments that might otherwise remain outside their security processes.

Sweet maps an agent’s sub-agents and tasks alongside its cloud workload context, helping security teams understand the full system they need to protect.

The catalog also records the tools each sub-agent offers to the model, including their descriptions, parameters and schemas. It distinguishes between tools that were Declared and those actually Invoked, helping teams identify capabilities that may be unnecessary. For example, an agent might regularly search customer records while also carrying an unused tool that changes them. Security and development teams can use that evidence to review whether the additional access is justified.

Sweet shows the tools available to a sub-agent, including their parameters and schemas, helping security teams assess its capabilities and review unnecessary access.

Sweet captures system prompts and separates developer instructions, runtime context and user input. Teams can see where untrusted text enters an agent’s context and review it alongside the tools available at that step. Captured invocation samples show what the agent was asked and how it responded, providing evidence for a security review grounded in actual runtime activity.

To help teams prioritize, Sweet connects AI Risks, such as credential access, code execution and tools that change systems or data, with Workload Risks, including vulnerabilities, incidents, internet exposure and external egress. These risks roll up to the agent so teams can assess its capabilities alongside the environment in which it operates. An attacker who compromises the hosting workload may gain access to the agent’s prompts and credentials, making cloud context essential to understanding AI risk.

Sweet shows a sub-agent’s AI and workload risks alongside its prompts, helping security teams understand where protection is needed.

Together, these details help teams focus on the agents that present the greatest concern, with evidence to guide their next action.

Turning Agent Visibility into Enforced Protection

An inventory helps you understand your AI environment. Its security value comes from what you can do with that understanding. Discovering a shadow agent, identifying a dangerous capability or finding a gap in protection should give your team a path to reducing that risk.

The AI Agents Catalog connects discovery to Sweet’s AI policies and runtime enforcement. Teams can identify agents without gateway coverage and bring them under protection, using policies to block unsafe interactions and tool use. The agent you investigate is the same one you can protect, with visibility into which controls govern it.

That is the purpose of bringing agent discovery into Sweet’s runtime platform: give security teams the context to decide where protection is needed and the ability to enforce it. As AI adoption expands, teams can uncover shadow AI and bring it under control.

Keep Your AI Environment Under Your Control

Security teams need to support AI adoption while protecting the systems and data agents can reach. The Sweet AI Agents Catalog helps teams uncover unreported deployments, understand the capabilities agents carry and prioritize protection using cloud context. By connecting that visibility to runtime enforcement, Sweet helps teams turn what they learn about their AI environment into control over it.

Request a customized demo to see how Sweet helps you discover, assess and protect the AI agents running in your environment.

‍

Share the Sweetness