Shadow-agent inventory

A bounded inventory of agent-like activity LumenFlow can observe — its own governed runtimes, agents that describe themselves, and telemetry you send it. Confirm-only: acknowledge or set aside what you see; it never acts on its own.

What we see, and what we govern#

Shadow-agent inventory is a bounded inventory over the signals LumenFlow can observe: its own governed runtimes, agents that describe themselves, and telemetry you send it. It is not a tenant-wide scan, so an empty list means nothing has been observed here, not that nothing exists — and it never acts on its own.

Open it at /dashboard/<workspaceId>/observe/agents/shadow. Only workspace owners and admins can see this page.

The three groups#

  • Governed — activity running under LumenFlow's own governance
  • Observed, not governed — activity LumenFlow can see but doesn't control
  • Reviewed and set aside — entries an admin has already actioned

Each entry shows a state (Registered, Discovered, Suspected, Ignored, or Remediated), a confidence level where applicable, its source, when it was first and last seen, and a retention expiry.

What you can do#

This is a confirm-only inventory, not a control surface — there's no start, stop, or pause action for the underlying activity. An admin can only record a judgement about an entry:

  • Ignore — set an entry aside
  • Restore — undo an ignore
  • Mark remediated — record that the activity has been addressed
  • Not an agent — mark a false positive so it stops resurfacing

info This inventory complements the Audit & Compliance trail — it's about visibility into agent-like activity, not a replacement for approvals or policy.