AgentLens is a governance and security platform for AI agents. Companies give agents access to their systems, yet few can say what an agent may do, what it actually does, or who owns it. AgentLens answers those three questions for every agent.
How it works: it ingests agent identities, roles, tools, guardrails and OpenTelemetry GenAI traces. Detectors compare granted permissions with the permissions actually used. This exposes least-privilege gaps and privilege hops. They also flag risky behaviour mapped to the OWASP LLM and Agentic Top 10. Each agent is classified into an EU AI Act tier, and missing controls such as oversight, logging and disclosure become findings linked to the relevant article. Every agent gets a 0–100 risk score, weighted by tier, with a per-issue breakdown. Each issue carries a proposed fix, an owner and an approval workflow with a full audit history.
A daily briefing is scripted by an LLM, voiced with text-to-speech.
Tech: ClickHouse stores traces and findings for fast aggregation. An API and dashboard sit on top, with a scheduled background worker for briefings and alerts. An open-weight, self-hostable model handles tiering, mitigation plans and scripts. Everything runs in containers, locally with one command or on Akash. A synthetic data engine plants known issues, and an eval harness measures recall and precision.