You cannot control what you cannot see. Sentry reads the systems Infosys already pays for, licences, sign-ins, invoices and MCP servers, and reports every AI it finds. Registered or not.
No agent has to cooperate. Each connector reads the paper trail an AI inevitably leaves.
Reads: Copilot licence assignments, Entra app registrations, OAuth grants
Reads: Every app users sign into, and which of them are AI vendors
Reads: Card and invoice lines matched against a catalogue of AI vendors
Reads: MCP servers answering inside the network, and who calls them
Reads: Bedrock/AgentCore and Azure AI Foundry agents running in your accounts
Every AI found in the estate, with the evidence that found it.
214 assigned licences · 168 active users in the last 30 days
Aggregate. Microsoft exposes usage and audit through the Graph API, but the agent runs inside their estate. Admin-API depth is the ceiling.
Enabled on the Service Cloud org · 4,180 agent conversations last month
Aggregate. Every turn lands in queryable Data Cloud objects, so transcripts and spans can be pulled. It cannot be routed through the gateway.
Team plan on the engineering card · 31 seats · $1,240/mo
High fidelity. Coding agents emit OTel traces and can be pointed at Sentry's collector without changing how engineers work.
Answering on the internal network · called by 2 registered agents and 1 unknown client
Full fidelity. MCP traffic can be fronted by the Sentry gateway, which makes every tool call visible and policy-enforceable.
Registered via the org usage API after discovery
Aggregate. Org usage and compliance APIs give cost and audit at the vendor's depth.
Enabled workspace-wide · 88 users signed in via SSO
Governance only. Notion exports no per-action audit for AI. It can be registered, owned and bounded, but not observed.