Agents work in the background. Liability doesn't.
Every senior leader can see their people and their processes. Nobody can see the agents — what they were given access to, by whom, or where the data goes next. Three exposures, all real, all currently invisible:
Your name, sent from your domain
An agent with email send permission writes as your employee, from your company. One hallucinated message — or one hijacked instruction — reaching your entire client list is an unrecoverable event.
scope: gmail.send + crm.contacts.read
reach: all 1,140 client contacts
Your confidential data, somewhere new
Agents pipe data onward — into automation platforms, spreadsheets and third-party AI tools that were never vetted to hold it. Client financials end up living in places nobody on your board has heard of.
path: xero → make.com → sheet
sheet sharing: anyone with link
Your name on the negligence claim
When data leaks through a chain of integrations, liability lands on the leadership that had no policy. Insurers now ask for documented AI controls at renewal. "We didn't know" is not a control.
"document all AI system access
to client data" · status: unanswerable
This is what you'd see. Try it.
Your whole organisation on one map: people, the agents they've enabled, and every system those agents can reach — including the third parties your data flows through. Click an agent to inspect it.
People
Agents they enabled
Systems & third parties
// interactive example with sample data — after connecting, this is your organisation, live.
Connect once. See everything.
No installs, no network appliances, no security team required. Agent Watch reads the permission grants your platforms already record — it never touches the content behind them.
Connect your workspace
Sign in with Google Workspace or Microsoft 365 admin and approve two read-only scopes. That's the whole setup. Fifteen minutes, most of it kettle time.
Get your exposure map
Every AI agent and automation connected to your business — mapped to the person who enabled it, the systems it touches, and where your data flows next.
Act on the flags
Risky grants, dangerous combinations and unvetted third parties are flagged in real time. Acknowledge, restrict, or revoke — every decision logged, ready for your insurer or auditor.
Agent Watch reads grants, scopes and metadata — never message content, never documents, never data. It can tell you an agent is able to email your clients. It cannot read a single email. That's the point.
"Damages caused by unauthorised AI use may be classified as gross negligence where no AI usage policy exists."
// The direction of cyber insurance underwriting, 2026. Renewals are becoming audits. Agent Watch is the evidence.