Signals
You already have unknown agents in the building
TechCrunch's Ram Iyer covered Reco's $55M raise and a claim of 21,000 unknown agents at one F100. GTM has the same shadow stack. Inventory before you scale.
September 29, 2026

You already have unknown agents in the building
You do not have an agent strategy problem. You have an inventory problem.
On Sep 29, TechCrunch's Ram Iyer reported that Reco raised $55M as AI agent security startups crowd the market. In that coverage, Reco claims 21,000 unknown agents at one Fortune 100 customer. Read that number again. Twenty-one thousand agents the company did not have on a roster. GTM is smaller, but the pattern rhymes: Clay workspaces nobody owns, browser extensions with CRM scopes, unofficial MCP servers, intern-built Zapier that still fires at 2 a.m.
Inventory agents before you scale them.
What does "unknown agent" mean in GTM?
It means something that can change buyer-facing state and is not on your roster.
Not every Chrome plugin. The ones that read Salesforce, push to Outreach, scrape LinkedIn at volume, or call an LLM with your ICP list in the prompt. If it can enrich, write, or send, and you cannot name an owner, a purpose, and a kill path, it is unknown. Reco's Fortune 100 number is the extreme case. Your version might be 12 tools and three "temporary" notebooks that never got retired.
Staff AI agents like a GTM roster exists for this reason. A roster without discovery is fiction.
Why does shadow GTM show up so fast?
Because the tools are cheap and the pain is loud.
An AE pastes a list into a personal GPT. An SDR installs a helper that auto-drafts replies. A marketer connects an unofficial MCP server to HubSpot because the official path was slow. None of that shows up in the QBR as "agents." It shows up as weird CRM fields, duplicate sequences, and a domain that starts warming the wrong way.
This is not AI as operator. Operator means owned jobs, owned tools, owned outcomes. Shadow means nobody can answer "what is allowed to touch the buyer this week."
How do you inventory without a six-month security program?
Four lists. One afternoon. Then a weekly refresh.
- Send path. Every tool that can put email or LinkedIn in front of a human. Include personal seats used for work.
- CRM write path. Every integration, script, and agent with create/update on accounts, contacts, or activities.
- Data egress. Every place ICP lists, call notes, or pricing leave the building into an LLM or a vendor.
- Orphans. Anything with an API key in a shared vault and no named owner in the last 30 days.
For each row: owner, purpose, data in, actions out, last reviewed. If a row cannot fill those five cells, revoke first, argue second. That is rails before scale, not paranoia.
How does this fit Signals?
Signals only work if you know which systems are listening and writing.
Ehrenberg-Bass / LinkedIn B2B Institute: roughly 95% of B2B buyers are not in-market. Unknown agents thrashing that 95% burn trust and domain before the 5% ever raise a hand. Inventory is how you stop paying for noise you did not approve.
GTM engineering is systems that change state under constraints. You cannot constrain what you refuse to list.
What should I do Monday?
Open a spreadsheet. Title it "GTM agents and automations." Pull OAuth apps from Salesforce and HubSpot. Export Clay workspaces and shared tables. Ask every AE and SDR for browser extensions that touch CRM or email. Cap the hunt at three hours. Anything without an owner gets credentials rotated that day. Then freeze new agent seats until the roster has a review date.
Adapt or fail. Scaling unknown agents is how you buy a security vendor after the apology, not before.
FAQ
Is every automation an "agent"?
For inventory, treat anything that can act without a human click on each record as in scope. Workflows, agents, and brittle scripts all change state. Label them later. List them first.
What if Reco's 21k number is vendor marketing?
Treat it as a directional signal from Ram Iyer's TechCrunch coverage of the raise, not as your KPI. Your job is your own count. If your count is zero and you have Clay plus three unofficial MCP servers, your count is wrong.
Who should own the roster?
One GTM engineering owner with security and RevOps on the review. Shared ownership with no name on the cell is how unknowns return.
When can we buy more agent seats?
After the roster exists, after orphans are revoked or owned, and after each new seat gets a job, tools, and a kill path on day one.
Frequently asked questions
- Is every automation an "agent"?
- For inventory, treat anything that can act without a human click on each record as in scope. Workflows, agents, and brittle scripts all change state. Label them later. List them first.
- What if Reco's 21k number is vendor marketing?
- Treat it as a directional signal from Ram Iyer's TechCrunch coverage of the raise, not as your KPI. Your job is your own count. If your count is zero and you have Clay plus three unofficial MCP servers, your count is wrong.
- Who should own the roster?
- One GTM engineering owner with security and RevOps on the review. Shared ownership with no name on the cell is how unknowns return.
- When can we buy more agent seats?
- After the roster exists, after orphans are revoked or owned, and after each new seat gets a job, tools, and a kill path on day one.