AI agents

Your data has new readers. They are not human.

AI agents, MCP clients, and external crawlers now reach production storage at machine speed, with permissions nobody reviewed and patterns nobody baselined. Every one of them is attributable from the access log.

Observed identities and clients

The user agent tells the truth

Agent tooling encodes its own configuration into every request. reCost parses it: which client, which MCP server, and whether read-only and consent guardrails were actually enabled.

ua="claude-code/1.2 aws-mcp cfg/ro#1 cfg/consent#1"
read-only on, consent on, expected posture
ua="claude-code/1.2 aws-mcp cfg/ro#0 cfg/consent#0"
write-capable, no consent gate, flagged

What we surface

01

A census of every AI agent, MCP client, and external crawler touching storage.

02

Guardrail posture per client, and the moment it flips.

03

Agents performing writes where they were assumed read-only.

04

Multi-account sweeps under admin or SSO roles.

05

Knowledge-base and RAG ingestion pulling documents out of buckets, where the audience widens from who can read the bucket to everyone who can query the agent.

06

First-seen AI clients anywhere in the estate.

07

Agent share of total access, trended over time.

The presigned URL problem

When an application signs a URL and hands it to an agent, the log records the signing role, not the reader. Every request looks like the application. Only the user agent reveals the actual consumer.

This is the single most common way agent access hides in plain sight.

Free Agent Report
30-day lookback, 48 hours.

Every agent, MCP client, and crawler that touched your storage, with the log lines as evidence.