Black
AI Discovery & Inventory

Build a Complete AI Asset Inventory

Create a continuously updated inventory of models, agents, MCP servers, and AI assets.

Use Case

Create a centralized, continuously updated inventory of models, datasets, notebooks, applications, agents, endpoints, MCP servers, tools, and connected services. Correlate each resource with ownership, provenance, lineage, approval status, risk, and application context.

Challenges

Enterprise AI is distributed across development, cloud, endpoint, and runtime environments. Conventional asset inventories leave critical gaps:

  • AI-specific resources remain fragmented across multiple platforms
  • Shadow AI and unmanaged agents avoid traditional discovery
  • Ownership, lineage, provenance, and approval status remain unclear
  • Static inventories quickly fall behind changing AI environments

Solution

PointGuard AI provides a comprehensive solution for building and maintaining a complete AI asset inventory:

1. Discover AI resources. Use AI Discovery & Inventory to identify models, agents, MCP servers, datasets, notebooks, applications, endpoints, and connected services.

2. Centralize asset context. Consolidate ownership, business purpose, provenance, approval, lifecycle, and risk into a dynamic system of record.

3. Map relationships. Connect models, agents, MCP infrastructure, applications, data, tools, and supply-chain dependencies.

4. Keep records current. Use ongoing discovery and runtime telemetry from Agent Mission Control and MCP Security Gateway to detect new or changed resources.

A complete inventory gives security and governance teams the foundation to prioritize risk and apply controls consistently.

Risks Addressed

Applicable framework risks and controls include:

OWASP Top 10 for LLMs
  • LLM03:2026 Excessive Agency
  • LLM04:2026 Supply Chain
  • LLM05:2026 Data and Model Poisoning
OWASP Top 10 for Agentic Applications
  • ASI02: Tool Misuse and Exploitation
  • ASI03: Identity and Privilege Abuse
  • ASI04: Agentic Supply Chain Vulnerabilities
  • ASI07: Insecure Inter-Agent Communication
  • ASI10: Rogue Agents
NIST AI Risk Management Framework
  • GOVERN 1.4: Transparent risk policies, procedures, and controls are established
  • GOVERN 2.1: Roles, responsibilities, and communication are documented and clear
  • MAP 1.1: Intended use, context, users, and lifecycle risks are documented
  • MANAGE 4.1: Post-deployment monitoring and change management are implemented