AgentCensus
A self-serve SaaS that discovers every AI agent and automation bot operating inside a startup's SaaS stack, scores each by data-access risk, and exports a compliance-ready inventory — so the first…
AgentCensus
A self-serve SaaS that discovers every AI agent and automation bot operating inside a startup's SaaS stack, scores each by data-access risk, and exports a compliance-ready inventory — so the first time security meets your AI fleet isn't during an incident.
Problem
By mid-2026, the average startup has dozens of autonomous AI agents and bots connected to its SaaS stack — n8n workflows, Zapier automations, GitHub Actions runners, Slack apps, Make.com scenarios — each deployed ad hoc by individual engineers, ops managers, or PMs with no central review. When a breach occurs or a compliance audit lands, the security team discovers these agents for the first time in incident logs. The EU AI Act's deployer obligations (Articles 9–17 and 26) require organizations to maintain technical documentation and risk records for high-risk AI systems in operation — obligations that are structurally impossible to meet without a real-time inventory of which agents are running and what data they touch.
Target user
A Head of Security or IT Director at a 50–300-person SaaS startup or digital agency who owns SOC 2 compliance and is now responsible for EU AI Act obligations. They have no dedicated team for manual SaaS audits and no budget for enterprise-tier shadow-AI platforms that start at five-figure annual contracts. Their job-to-be-done: produce an accurate, auditable list of every AI agent touching company data before the next compliance review or board-level security briefing — in under an hour.
MVP scope
- Connect to OAuth-compatible SaaS platforms (GitHub, Slack, Google Workspace, Notion, HubSpot, Linear) and enumerate installed bots, OAuth apps, and automation tokens with write access
- Discover Make.com, Zapier, and n8n automation scenarios via API and flag those accessing first-party data sources (CRM, email, cloud storage)
- Assign a risk score per agent across four dimensions: data scope (PII access?), action scope (read-only vs. write/delete), identity hygiene (running under a real user's credentials vs. a service account), and staleness (last reviewed date)
- Generate a downloadable agent inventory report (PDF + JSON) suitable as SOC 2 evidence and EU AI Act Article 26 deployer documentation
- Alert via Slack or email when a net-new agent is discovered that was absent from the previous scan
- Dashboard showing total agent count, high-risk agent count, and count of agents unreviewed for more than 30 days
Monetization
Freemium: free tier covers up to 3 SaaS integrations and 20 discovered agents, scan-on-demand only. Starter at $49/month adds 10 integrations, unlimited agents, weekly automated scans, and PDF export. Pro at $199/month adds unlimited integrations, daily scans, Slack alerts, SOC 2 evidence bundles, and the EU AI Act Article 26 inventory template. Annual plans at 20% discount; agency tier allows managing multiple client workspaces under one subscription.
Why now
The EU AI Act's conformity-assessment obligations for high-risk AI system deployers took binding effect on August 2, 2026, requiring technical documentation and risk-management records that presuppose a complete AI agent inventory — something almost no startup has. Gartner reports that unmanaged agentic AI now puts $234 billion in enterprise SaaS spending at governance risk. Witness AI raised $58 million in early 2026 for enterprise shadow-AI monitoring off 500% ARR growth, confirming the demand signal — but their minimum deal size leaves the 50–300-employee segment unserved. The average enterprise logs 223 AI-related data-policy violations per month (Netskope, 2026); SMBs have no affordable, self-serve equivalent to detect or prevent them.
Risks & open questions
- OAuth permissions required for broad SaaS discovery may trigger trust objections from security-conscious prospects who are wary of granting another SaaS admin-level read access to their stack
- Enterprise players (Astrix, Witness AI, DoControl) could launch an SMB tier within 12 months and outspend on distribution
- SaaS platform API coverage is uneven — Zapier and Make.com expose scenario metadata but not full data-flow graphs, so risk scoring will be partially heuristic rather than definitive
- Demand-side risk: security budgets at sub-100-employee startups are thin, and compliance urgency may not drive conversion until after a breach or failed audit
- Build complexity: each SaaS integration requires its own OAuth app, scope negotiation, and rate-limit handling — 10+ integrations is three to four months of engineering
Next step
Validate EU AI Act compliance pain with 10 Head-of-Security interviews at Series A/B SaaS companies; build a proof-of-concept connecting GitHub, Slack, and Google Workspace to generate a sample risk report, then gate a waitlist on demand for a $49/month Starter plan.
Sources
- https://www.hklaw.com/en/insights/publications/2026/04/us-companies-face-eu-ai-acts-possible-august-2026-compliance-deadline — EU AI Act August 2026 deployer obligations and compliance requirements for U.S. companies
- https://shattered.io/agentic-ai-security-2026/ — $4.7M average cost of AI agent-related data breaches in 2026; 92% of security professionals alarmed by agentic AI risks
- https://www.cio.com/article/4192242/agentic-ai-puts-234b-in-enterprise-saas-spending-at-risk-gartner-says.html — Gartner projection: unmanaged agentic AI puts $234B in enterprise SaaS spending at governance and compliance risk
- https://techcrunch.com/2026/01/19/rogue-agents-and-shadow-ai-why-vcs-are-betting-big-on-ai-security/ — Witness AI $58M raise driven by 500% ARR growth; enterprise-only deal size leaves SMB market unserved
- https://netwrix.com/en/resources/blog/shadow-ai-security-risks/ — 223 AI-related data policy violations per month per average enterprise (Netskope, 2026); agentic shadow AI as the fastest-growing category