Methodology

    Methodology: How Andeavour Measures Agents, Principals & Risk

    This page defines the terms, counting rules, testing procedure and limitations behind every number Andeavour publishes, so any claim we make can be checked, reproduced or challenged.

    Definitions used when counting

    AI agent: a software entity that uses a model to decide and then acts through tools or APIs, with its own identity or credential. Chat interfaces without tool access are counted separately and are not included in agent counts.

    AI Principal: code with creation authority — a program, orchestrator, template or pipeline that spawns agents, trains their models or issues their standing instructions. Principals are counted independently of the agents they produce.

    Shadow agent: an agent found by discovery that does not appear in the organization's documented inventory at the time of the scan.

    Over-privileged agent: an agent holding at least one entitlement that was not exercised during the observation window and is not required by its declared task.

    Discovery procedure

    Discovery runs read-only against identity providers, cloud platforms, SaaS administrative APIs, code repositories and agent runtimes that the customer connects. Each candidate is deduplicated by credential and by creating Principal so that one agent appearing in three systems is counted once. Results are compared against the customer's own inventory to derive shadow-agent figures.

    Observation window

    Unless a figure states otherwise, privilege-use measurements use a rolling 30-day observation window, and population counts are point-in-time snapshots taken at the end of that window. Environments with fewer than 30 days of telemetry are excluded from privilege statistics.

    Attack-class testing

    Lab tests are performed against purpose-built agentic systems using common orchestration frameworks and tool protocols, not against customer environments. Each test records the threat class, the preconditions required, whether the attack achieved an unauthorized action, and which control stopped it. Classes are mapped to OWASP GenAI agentic threats and MITRE ATLAS techniques.

    Sample size and aggregation

    Statistics are published only when derived from at least five distinct environments, and percentages are reported with the environment count alongside them. Single-customer observations are described as case studies, never as rates.

    Known limitations

    Coverage is bounded by the systems a customer connects; agents created entirely inside unconnected third-party platforms may be missed. Privilege analysis infers necessity from observed use, which can overstate over-privilege for agents with rare but legitimate high-impact tasks. Lab feasibility results say nothing about how often an attack occurs in production.

    Citation policy

    Third-party figures are attributed to their original publisher with a link at the point of use. Where a widely repeated statistic cannot be traced to a primary source, we omit it. Corrections can be requested at info@andeavour.io and are applied in place with a dated note.