In August 2026, Salesforce introduced Claudeforce, embedding Anthropic's Claude AI directly into its platform. This followed similar integrations in Slack and Microsoft 365, all claiming to inherit the host platform's security model. The rapid adoption of these agents posed a significant challenge: they bypassed traditional procurement and security reviews, creating an expanding attack surface without formal approval.
The problem lies in the nature of AI agents. They are embedded by third-party platforms, avoiding the usual governance processes. This leaves security teams struggling to answer critical questions: How many agents exist? What data can they access? Who is accountable if compromised? The rapid evolution of offensive AI, costs dropping tenfold annually, exacerbates the risk, particularly in the third-party application layer where these agents operate.
Workday's success with AI-driven contracts highlights the pressure to adopt these technologies quickly. However, security leaders face the daunting task of managing a continuously growing, third-party-driven ecosystem. Traditional security tools, designed for first-party problems, fail here. The solution requires real-time monitoring and continuous updates to track agents' access and capabilities.
Reco, a leader in agent security, offers a platform to address these challenges. By discovering and managing agents across applications, identities, and permissions, Reco aims to bring order to the proliferation of AI agents in enterprise environments.