An agent credentialed to read a system can repeat what it read anywhere, and no amount of prompt review bounds where.
An agent can repeat anything it can read. Record what every run touched, check scope as it happens, and hold an action that moves data outside the agent's job before the output leaves.
Exposure rarely announces itself. These are the shapes it takes in a fleet nobody watches for scope.
The same agent on the same task takes a different path each run. An agent that read a customer record on Monday can surface it in an unrelated answer on Thursday, and reading the prompt tells you nothing about which run will.
User uploads and customer records flow into prompts because that is how the agent does its job. From there they reach models, tools, and traces that nobody listed when access was granted.
Staff paste company data into AI tools nobody approved, and unregistered agents move the same data on a schedule. Neither shows up in any inventory you hold.
The security team holds veto power over each agent, and their first question is what data it can leak. Without a per-run answer, the honest reply is a shrug, so the launch waits.
Each is a reasonable trade under deadline. Together they make exposure unbounded and unwatched.
With deterministic software, a code review bounds what data can go where. An agent chooses its own path each run, so the only real boundary is a check on what each run actually did.
The agent gets read access to a whole system because one task needs it. Every run inherits everything, whether or not this run's task does.
De-identification pipelines cost engineering quarters, so teams ship without them and rely on the prompt asking the model to be careful. Nothing checks that it was.
Approved agents log to five different places and unapproved ones log nowhere. Data exposure across the fleet is not a number anyone can produce.
Prefactor records what every run accessed and evaluates it against the agent's job, so a repeat outside scope becomes a caught event, not a discovery.
Every agent into one record. Native SDKs for common frameworks, a TypeScript and Python core SDK for anything custom, and OpenTelemetry ingest for closed tools. Data reads and tool calls land as they happen.
What it accessed, and what it did with it. Each run records the data the agent read, the tools it called, and the output it produced, tagged to that run, queryable per agent.
A scope check on every run. Each run is checked against the agent's job: did it touch data outside its task, did restricted fields reach an output or a tool call. A repeat outside scope is a verdict, not a lucky catch.
Shadow agents show up. With telemetry centralised, anything emitting runs appears in the fleet view, so the unregistered agent moving customer data stops being unknowable.
Catching a repeat is the start. The loop is what turns exposure into a bounded, answerable record.
A breach is held before output leaves. A run that puts restricted data in an output or a tool call can be held or escalated to a person before the action completes, so the repeat stays inside the record instead of reaching a customer.
Narrow scope where it actually leaked. The record shows which prompt, tool, or credential let restricted data in, so the fix is a narrower grant or a redacted field, landed where the leak happened and verified on the next runs.
"What did it touch?" becomes a lookup. SOC 2, ISO 27001, and sector rules ask what data your agents accessed. The per-run record answers in minutes, with an artefact you can hand to an auditor or your own security team.
A support agent scoped to tickets was found reading billing records to answer refund questions. The scope check flagged the reads, held one output that contained card details before it sent, and escalated to the owning team. The fix was a narrower credential, and the following week's runs proved it held. Illustrative, but this is the standard shape of the catch.
Your veto question, what can this agent leak, answered with a per-run record and a hold on breaches instead of a promise.
See the solution →Heads of AIEvery agent's data scope in one view, including the agents nobody registered, so the exposure across the portfolio is a number, not a guess.
See the solution →Engineering leadershipGet agents past security review with a record of what each run touches, without building a redaction pipeline first.
See the solution →Book a demo and we will put one of your agents in the record: every run watched for scope, breaches held before output leaves, and the audit question answered as a lookup.
Prefactor helps teams observe, evaluate, and improve their AI agents in production, across every framework and provider.