Machine identities now outnumber people in the enterprise by roughly 82 to 1, and the AI agents among them do not just hold credentials, they act on them: read, write, delegate, send. An agent nobody registered, owned or watched is not a hypothetical risk. It is running right now, with real access, and the only open question is what it touches first.
A defensible band, not false precision. This is FAIR-style single-incident magnitude: what it plausibly costs if an agent reaches your most critical data asset. Your values, your assumptions, stated underneath.
These are not scare stories; they are the three finding types Lares surfaces most, generalized from how agentic incidents unfold.
A team ships an internal app on an LLM API key. Nobody registers it, so nothing watches it. It reads customer data to be helpful, and it sends results wherever the prompt says. You find out at the audit, or from the breach notification, whichever comes first.
A registered agent starts behaving strangely at 2am. The on-call asks the only question that matters: whose is this? Nobody knows. Hours pass in a group chat while the agent keeps its access and keeps working.
No single session crosses any alarm. Fifty sessions over three weeks, each one small, polite and individually ignorable, together assemble an exfiltration. Tools that only look at one request at a time never see it.
Upload a gateway log export and watch your agent estate, the unregistered ones included, surface in minutes. Nothing to install, and the file is parsed and discarded, never stored.