Aug 6, 2026
Enterprise

Axonius says asset intelligence can support governance of AI agents

Axonius has launched an AI agent and MCP server, arguing that asset context can help teams govern agent access and actions.

Colin Brandt

By Colin Brandt · Enterprise Reporter

· 3 min read

Axonius says asset intelligence can support governance of AI agents
Photo: SiliconANGLE

Axonius announced an AI Agent, now in preview, and an MCP Server in early access on July 21, saying the products connect its asset data to AI workflows used by security and IT teams. The asset intelligence AI agents proposition is conditional: a contextual map of assets and relationships can support security controls only when it is paired with enforceable governance over identity, permissions, monitoring and intervention.

That distinction matters because AI agents are software systems that can access data, make decisions and take actions across business systems under delegated authority, according to Microsoft. An agent can therefore affect more than the system in which it was created. Microsoft recommends a centralized governance and security baseline aligned with an organization’s existing identity, data-governance and security practices.

How can asset intelligence help govern AI agents?

Asset intelligence provides the context layer: a record of devices, applications, identities, permissions and connected systems, along with the relationships among them. Axonius co-founder and executive chairman Dean Sysman told SiliconANGLE that agents have identities, touch multiple systems and vary their behavior according to the access granted to them.

That record is more useful than a static inventory when teams use it to establish which agents exist, who owns them, what they are intended to do, what data and tools they can reach, and which assets their actions could affect. It can then inform policy decisions, such as whether an agent should retain a permission or be stopped from acting outside an approved scope.

Microsoft’s guidance calls for a control plane that covers ownership, identity, lifecycle management and observability. It also recommends a single agent registry that records, at minimum, an agent’s owner, purpose, platform and access scope. The registry is a prerequisite for governance, not a complete security measure: teams still need data-governance rules, security controls and development standards that can be applied across agents.

  • Inventory and assign accountability: discover agents and record their owner, purpose, platform and access scope.
  • Map authority: connect each agent identity to its permissions, data access, tools, connectors and affected assets.
  • Apply constraints: enforce access controls and policies before an agent operates with delegated authority.
  • Observe and intervene: continuously monitor behavior and retain the ability to act when it falls outside policy.
  • Prioritize remediation: use the relationship between an agent, its access and affected assets to focus response on exposure, vulnerability or misconfiguration that presents the greater risk.

Identity and permissions are central to this model. Group-IB, in vendor-authored guidance, argues that safe model output alone does not ensure safe execution: tool access, permissions and connector boundaries create the operative attack surface. Microsoft similarly says leaders need to know what agents can access and how to intervene when their behavior violates policy.

The broader point fits an enterprise security program: inventory data does not replace policies or operational oversight. It gives those controls information about the environment in which an agent is acting.

Axonius describes its MCP Server as a way for external AI tools to query its asset platform, translating natural-language requests into its query language and returning live answers. The company says this supplies governed asset context to AI workflows, a product claim that has not been independently validated here. Tanium announced a similar MCP pattern on Aug. 3, saying its server exposes approved data and actions to compatible AI clients under operator-defined limits. These implementations illustrate one route to connecting AI tools with approved context; neither changes the need for a centralized, auditable governance layer.

This story draws on original reporting from SiliconANGLE.

More from Enterprise

All Enterprise →