Agent Discovery
Your teams are already building and running AI agents — in Microsoft Copilot Studio, in Google's Vertex AI and Gemini Enterprise, in Amazon Bedrock AgentCore. Most of them are invisible to security and platform teams: no inventory, no activity trail, no policy.
Agent Discovery gives you that inventory in minutes. Connect a cloud once — with a single admin action, read-only — and Waxell:
- Discovers every agent on that platform, across all of your users and environments, into one cross-cloud fleet inventory.
- Observes their activity — who ran what, when — pulled from each platform's own audit and telemetry, with zero changes to the agents themselves.
- Governs them under one policy regime, the same policies you already author for Waxell-hosted agents.
It is read-only by default and credential-less: Waxell authenticates through a short-lived, scoped grant you control, and no long-lived key ever leaves your cloud. Remove the grant and access ends immediately.
What you connect
| Cloud | Agents discovered | How you connect | Guide |
|---|---|---|---|
| Microsoft | M365 Copilot & Copilot Studio agents, Azure AI Foundry agents | One Global-Admin consent click | Connect Microsoft |
| Google Cloud | Vertex AI Agent Engine, Conversational Agents, Gemini Enterprise | Grant a role to Waxell's service account (keyless) | Connect Google Cloud |
| AWS | Bedrock AgentCore runtimes & gateways | Launch a CloudFormation stack (one account or a whole Organization) | Connect AWS |
Each connection lands in the same place — Governance → Agent Discovery — so a Copilot agent, a Vertex agent, and an AgentCore runtime sit side by side in one fleet view.
What you get
A live fleet inventory. Every discovered agent, tagged with its platform, owner, environment, and type. Agents that stop appearing are kept as history, marked inactive — your inventory never silently loses an agent.
Zero-touch observability. Waxell pulls each platform's native audit and telemetry — Copilot conversation transcripts, Vertex Cloud Logging, AgentCore CloudTrail — and turns them into governed runs on your Executions screen, attributed to the right agent. Your teams don't change a line of code or redeploy anything.
One governance policy across clouds. The policies you write once apply everywhere: an agent on Copilot, Vertex, and AgentCore is held to the same rules, with one audit log and one place to answer "which agents touched customer data this week?"
Precise, least-privilege access. Every connection uses the narrowest read scope each cloud allows, gated so only your Waxell tenant can use it. You can see exactly what each grant permits in each guide, and revoke it at any time.
How onboarding works
Every cloud follows the same three steps:
- Add the connection in Waxell (Governance → Agent Discovery → Connect), pick the platform.
- Authorize with the one admin action that platform uses — an admin-consent click (Microsoft), a service-account role grant (Google), or a CloudFormation launch (AWS). Waxell shows you the exact value to use.
- Sync — Waxell discovers the fleet and begins pulling activity. Discovery re-runs automatically thereafter.
Pick your cloud to get started:
- Connect Microsoft (Copilot & Foundry)
- Connect Google Cloud (Vertex & Gemini Enterprise)
- Connect AWS (Bedrock AgentCore)
For MSPs and multi-account estates
Managing many customers or a large cloud estate? Every connection is scoped to a single tenant, and the onboarding actions above scale to a whole org in one step — a Microsoft tenant-wide consent, a Google org-level role grant, or an AWS Organizations StackSet that reaches every member account. See the org-wide sections in each cloud's guide.