Get early access →
58% of small businesses now use generative AI your data now lives on platforms nobody risk-assessed insurers are reclassifying unmanaged AI as gross negligence most AI grants are approved by employees, never reviewed by anyone API keys in config files outlive the employees who created them 58% of small businesses now use generative AI your data now lives on platforms nobody risk-assessed insurers are reclassifying unmanaged AI as gross negligence most AI grants are approved by employees, never reviewed by anyone API keys in config files outlive the employees who created them
The problem, spelled out

Agents work in the background. Liability doesn't.

Every senior leader can see their people and their processes. Nobody can see the agents — what they were given access to, by whom, or where the data goes next. Three exposures, all real, all currently invisible:

01 — REPUTATION

Your name, sent from your domain

An agent with email send permission writes as your employee, from your company. One hallucinated message — or one hijacked instruction — reaching your entire client list is an unrecoverable event.

AGT-003 · enabled by j.smith
scope: gmail.send + crm.contacts.read
reach: all 1,140 client contacts
02 — DATA

Your confidential data, somewhere new

Agents pipe data onward — into automation platforms, spreadsheets and third-party AI tools that were never vetted to hold it. Client financials end up living in places nobody on your board has heard of.

AGT-007 · enabled by s.patel
path: xero → make.com → sheet
sheet sharing: anyone with link
03 — LIABILITY

Your name on the negligence claim

When data leaks through a chain of integrations, liability lands on the leadership that had no policy. Insurers now ask for documented AI controls at renewal. "We didn't know" is not a control.

renewal question 14(b):
"document all AI system access
to client data" · status: unanswerable
The product

This is what you'd see. Try it.

Your whole organisation on one map: people, the agents they've enabled, and every system those agents can reach — including the third parties your data flows through. Click an agent to inspect it.

Exposure map — Example Ltd (sample data) // click an agent to inspect

People

M. Collins
Marketing
R. Hughes
Sales
J. Smith
Account Mgmt
S. Patel
Finance
T. Wood
⚠ left company

Agents they enabled

AGT-001 · ChatGPT
research assistantLOW
AGT-002 · Claude
drafts & CRM lookupsLOW
AGT-003 · Claude
client commsHIGH
AGT-007 · automation
finance reportingHIGH
AGT-009 · API key
owner unknownMED

Systems & third parties

Gmail
company email
HubSpot
1,140 client records
Xero
company ledger
Google Drive
all shared docs
make.com
3rd party · unvetted
Board pack sheet
⚠ anyone with link

// interactive example with sample data — after connecting, this is your organisation, live.

How it works

Connect once. See everything.

No installs, no network appliances, no security team required. Agent Watch reads the permission grants your platforms already record — it never touches the content behind them.

01

Connect your workspace

Sign in with Google Workspace or Microsoft 365 admin and approve two read-only scopes. That's the whole setup. Fifteen minutes, most of it kettle time.

02

Get your exposure map

Every AI agent and automation connected to your business — mapped to the person who enabled it, the systems it touches, and where your data flows next.

03

Act on the flags

Risky grants, dangerous combinations and unvetted third parties are flagged in real time. Acknowledge, restrict, or revoke — every decision logged, ready for your insurer or auditor.

// PRIVACY BY DESIGN

Agent Watch reads grants, scopes and metadata — never message content, never documents, never data. It can tell you an agent is able to email your clients. It cannot read a single email. That's the point.

"Damages caused by unauthorised AI use may be classified as gross negligence where no AI usage policy exists."

// The direction of cyber insurance underwriting, 2026. Renewals are becoming audits. Agent Watch is the evidence.

Questions

Asked by every sensible buyer.

Is this surveillance of our employees?
No. Agent Watch never reads messages, documents or prompts — only permission grants and connection metadata. It answers "what could this agent do", not "what did this person write". Think access review, not monitoring software. Most teams find it protects employees: exposure is attributed to gaps in process, not blamed on individuals who were never given a policy.
What access does it actually need?
Two read-only admin scopes on Google Workspace or Microsoft 365, plus optional read-only connections to tools like Xero and HubSpot. Every scope we hold is visible in your own admin console and revocable by you at any time — we're held to the same standard we apply.
Will it block tools or slow people down?
No. Agent Watch observes by default — your team keeps using whatever makes them productive. You decide what to act on. When you do restrict or revoke something, it's one click, with the reasoning logged.
We're 40 people with no security team. Is this for us?
You're exactly who it's for. Enterprise tools in this space assume a security operations centre. Agent Watch assumes a busy MD who wants one honest dashboard — flags in plain English, with the recommended action attached.
What does it cost?
Early access partners get their exposure review free and shape the product with us. Paid plans will be priced for 20–500 person organisations — closer to your password manager than your audit fee.