Skip to content

Guides

Find shadow agents with discovery

Connect OpenAI, Anthropic and OpenRouter with an admin credential and every key, project and workspace your people run outside Immiscible shows up, with its owner and its spend. Bring each one under control in one click, or propose revoking it.

The gateway governs what is pointed at it. Discovery finds what is not: the API key on a laptop, the side project with its own OpenRouter credit, the service account a contractor made. It asks each vendor’s admin API what exists, on a schedule, and lists it under Discovery in the console. Every key it finds is also a row in the agent inventory, beside agents found in Microsoft Entra, Google Workspace, n8n and Zapier.

#Connect a vendor

VendorCredentialWhere to make it
OpenAIan admin keyOpenAI platform, organisation settings, admin keys
Anthropican admin key (sk-ant-admin...)Claude Console, organisation settings, admin keys
OpenRoutera management keyOpenRouter, settings, management keys

An admin credential can see your organisation’s whole bill and, at Anthropic and OpenRouter, switch keys off. Immiscible checks it with the vendor before it keeps it, then seals it with AES-256-GCM under its own label; it is never shown again and never used for inference.

#What is found

VendorItemsSpend, last 30 days
OpenAIprojects, each project’s API keys (with the owner’s email), service accountsthe costs API grouped by key and by project
Anthropicworkspaces, API keys (with the creator’s email)the workspace’s cost report, shared out to its keys by their tokens in the usage report, and labelled as such
OpenRouterkeys, and the organisation’s creditseach key’s usage this month

Each item gets an id (dsc_...) and a first sighting that never change: a database trigger refuses any edit. Its owner is the vendor’s email for whoever made it, matched to a member of the workspace where the emails agree. The gateway’s own upstream key is recognised and listed as managed.

An item is unmanaged, managed, ignored, revoked, or gone (the vendor no longer lists it).

#Bring it under control

One click on an unmanaged key registers it as an agent acting for its owner and issues a governed agent key, shown once. Give that key to whatever used the original, point it at the gateway, and its traffic is now metered, routed, judged and recorded like everything else. A project or workspace becomes an application in the registry.

Tick revoke the original and a proposal to switch the old key off is filed at the same time.

#Policy for keys made outside Immiscible

PolicyOn each new key found
recordlisted, and a shadow_agent_discovered record on the ledger
alertas record, and an email to every owner
revokeas alert, and a revocation proposal for each key the vendor lets us revoke

Only an owner sets revoke.

#Revoking is always two owners

Nothing changes at a vendor on one person’s word, and never on the policy’s alone. An owner proposes; a different owner confirms within seven days; only then does Immiscible call the vendor:

VendorWhat happens
OpenAIthe project key is deleted. OpenAI does not let an admin key delete a key owned by a service account, so those are refused up front: delete the service account in OpenAI instead
Anthropicthe key is set to inactive, which an owner can reverse in the Claude Console
OpenRouterthe key is disabled

A person alone in their workspace confirms their own proposal as a separate, recorded step. A vendor refusal marks the proposal failed with the vendor’s reason.

#Schedule

Each connection syncs every syncHours (default 6) from the same sweeper that expires approvals. Sync now runs one at once.

#What discovery cannot see

Only what the vendor’s admin API reports: keys and spend in organisations you hold an admin credential for. A personal account on someone’s own card, a consumer chat subscription, or an agent product with no admin API at all (see agents without an API) will not appear. The card side of that is covered by Ramp reconciliation.