Cost of inaction

The most expensive agent
is the one nobody owns.

Machine identities now outnumber people in the enterprise by roughly 82 to 1, and the AI agents among them do not just hold credentials, they act on them: read, write, delegate, send. An agent nobody registered, owned or watched is not a hypothetical risk. It is running right now, with real access, and the only open question is what it touches first.

82:1 ratio: CyberArk, 2025 Identity Security Landscape.
Put your own numbers in

What one reached crown jewel is worth.

A defensible band, not false precision. This is FAIR-style single-incident magnitude: what it plausibly costs if an agent reaches your most critical data asset. Your values, your assumptions, stated underneath.

Your most critical asset

Think of the one system you would call the board about: the customer database, the payments store, the source repository.
Customer rows, patient records, whatever a breach notification would count.
Industry breach-cost studies put a defensible anchor in this range. Use your own if you have it.
Only if the asset going down stops revenue or operations.

Worst-plausible loss, one incident

Exposure band
$132.0M – $528.0M if a rogue or hijacked agent reaches this one asset
Assumptions on the table
  • 2,000,000 records at $165 per record
  • the band brackets estimate uncertainty at 0.4x to 1.6x of that magnitude
  • single incident, single asset; a campaign across assets stacks bands
This is the same arithmetic Lares ships. In the product, findings are priced with operator-declared asset values over observed reachability, and every dollar band carries its assumptions with it. Lares never invents a value for your data; you declare it once, and every finding that can reach it arrives priced.
How the bill actually arrives

Three patterns, all quiet until they are not.

These are not scare stories; they are the three finding types Lares surfaces most, generalized from how agentic incidents unfold.

Unregistered

The shadow agent

A team ships an internal app on an LLM API key. Nobody registers it, so nothing watches it. It reads customer data to be helpful, and it sends results wherever the prompt says. You find out at the audit, or from the breach notification, whichever comes first.

With Lares: the unknown credential surfaces on the See page the first time it acts, with what it touched, and a one-click register or dismiss.
Unowned

The agent nobody answers for

A registered agent starts behaving strangely at 2am. The on-call asks the only question that matters: whose is this? Nobody knows. Hours pass in a group chat while the agent keeps its access and keeps working.

With Lares: every agent carries a named owner, unowned agents are a counted gap before the incident, and the decision routes to the owner when it matters.
Slow

The patient campaign

No single session crosses any alarm. Fifty sessions over three weeks, each one small, polite and individually ignorable, together assemble an exfiltration. Tools that only look at one request at a time never see it.

With Lares: agents are remembered across sessions; the accumulation itself becomes an evidence-backed finding while the campaign is still incomplete.
Why price it at all

What the band buys you.

Priority you can defend. Fix by dollars at risk, not by alert count. Two findings, one touching a $50K wiki and one a path to the payments store, stop being the same severity.
A before-and-after for the board. "An agent had a path to the customer database, worst plausible case in this band. We broke the chain in minutes, reversibly, and here is the record." That is a complete sentence.
Exposure that never lands. A contained chain is a band you never pay. The decision log keeps the running total of what was cut off, with who approved it and when.
What we will not tell you: a made-up ROI percentage, a fabricated breach probability, or a promise that a tool equals a program. The honest claim is narrower and stronger: ungoverned agents carry real, boundable exposure; Lares makes the exposure visible, priced on your numbers, and cheap to cut off, with the evidence to prove you did.

See your own number move.

Upload a gateway log export and watch your agent estate, the unregistered ones included, surface in minutes. Nothing to install, and the file is parsed and discarded, never stored.