AI platforms and agent frameworks
Where agent credentials and model access keys live. An agent acts through a credential someone has to own. The checker reads the system column to group the accounts; the findings come from the other columns, the same way for every system.
What the export usually carries
An AI platform or agent framework usually lists the agents or apps, the API keys or credentials they use, created and last used per key, and the scopes or connected data sources. The owner is often the person who created the agent, which may not be the person accountable for it now.
What the checker most often raises here
- 11. AI agent credential with no owner or no review: An AI agent credential with no owner, a team for an owner, an owner who has left, no review recorded, or a review older than the interval. Without a review column, the review half is a question.
- 3. No owner named, or a team named with no accountable person: The account is not a personal account and its owner cell is blank, "unknown", "TBC" or similar, or names a team, a department or a mailbox with no accountable person named beside it. When an accountable, approver or owner of record column names a person for the team, this finding does not fire; with a staff list, that person is checked like any owner (left is finding 2, not in the list is a question).
- 8. Credential stored in code, a config file or a script: The stored-in column reads code, a config file, a script, or a document (a spreadsheet, a wiki, an email or a chat).
- 10. Not reviewed within the interval: The list has a last reviewed column, and this account's cell is blank or older than the interval you set (default 12 months) before the as-at date. With PCI DSS ticked, user accounts also fire at more than 6 months (7.2.4); with CIS Controls ticked, every account at more than 12 months (6.8). Exactly the interval never fires. Without the column, the finding does not fire and every line says the column is missing.
Account types found here
- Built-in or vendor default accounta system account
- Break-glass or emergency accounta user account
- AI agent credentiala system account
- Automation or bot (scheduled jobs, RPA)a system account
- Service accounta system account
- API key or access keya system account
- OAuth client or app registrationa system account
- Device or workload identitya system account
- Mailbox or resource accounta user account
- Test accounta user account
- Shared or generic logina user account
- Administrator or privileged person accounta user account
- Contractor or guesta user account
- Person (employee)a user account
The system names in your export are matched to these classes by the browser dictionary; product names are never shown on these pages. A system the dictionary does not place reads as other, and every finding still works.