Home Case Studies

Ditto Finds and Secures Every AI Agent, Owner, and Permission in One View with CloudEagle.ai

Ditto Finds and Secures Every AI Agent, Owner, and Permission in One View with CloudEagle.ai

"Agents were spreading across tools faster than any one console could show us, including a few still running on admin-level access from people who'd already left. CloudEagle gave us the full picture, every agent, its owner, its permissions, its activity, in one place. Now if one's a problem, the kill switch shuts it down from that same screen."

- Yaniv Erel, CTO, Ditto

340
Agents found across every console
28
risky agents killed with one click switch
19
agents created by ex-employees were active

340

Agents found across every console

28

risky agents killed with one click switch

19

agents created by ex-employees were active
Problems
Challenge
  • Agents got created across whatever tool or console someone happened to be using, with no sign-off and no shared list of what existed.
  • Credentials, roles, and permissions were inherited as an agent was built, with no record of what came from where.
  • Nobody could say what an agent had actually done until something went wrong and someone had to dig for it after the fact.

‍

Solutions
Solution
  • Every agent across every console and workflow was surfaced in one view: status, last activity, owner, credentials.
  • Each agent appeared in its actual context, which application or environment it belonged to, and what was known about it individually.
  • A single kill switch shut an agent down the moment it became a problem, with no hunting across consoles first.

‍

Profit
Result
  • The first scan surfaced of 340 agents across every console, a number nobody could have named beforehand.
  • 19 of those were created by ex-employees and had admin access to critical data and were closed out immediately.
  • 28 agents flagged as risky were shut down with a kill-switch no ticket, no queue.

‍

Challenge

At Ditto, agents had been created across whatever console or tool a team happened to be using at the time.

Each one inherited credentials, roles, and permissions as it was built, but no record traveled with it explaining what it had been given access to or why.

Security could open any single console and see the agents living there, but no view existed that pulled all of them together, so the real number was a guess. 

Somewhere in that unknown count sat agents built by people who'd since left the company, quietly holding onto whatever access they'd been given, with nobody positioned to know that or check for it. 

Finding out these unmonitored agents with admin-level permissions meant checking console after console and hoping the trail hadn't gone cold.

‍

Solution
  • Every agent across every console and workflow gets surfaced in a single view, showing status, last activity, owner, and credentials for each one.
  • Each agent appears in its actual context: which application or environment it belongs to, and what's specifically known about it, including its permission level.
  • Activity logs for any agent are pulled up on demand, showing what it did, what it changed, and which resources it touched, so an investigation starts with answers instead of guesswork.
  • A single kill switch shuts an agent down the moment it's flagged as a problem, without hunting across consoles first to find where it lives.
  • Ownership gets established for every agent found, closing the gap where something runs simply because nobody remembers building it.
Why CloudEagle.ai?

Ditto evaluated several options and chose CloudEagle.ai because it already governed SaaS and AI, and agents were a natural extension.

  • A natural extension of the platform already in place. CloudEagle.ai was already a leader in governing SaaS and AI apps, so agent governance mostly meant adding integrations and went live from day one.
  • One view across every console, instead of checking five places and still guessing at the total.
  • Nothing hidden. EagleIQ's seven telemetries find agents even when they were built outside any approved tool, including ones left behind by former employees.
  • Every agent's owner and permissions in plain sight, admin-level access included, so "who owns this agent" gets answered on the spot.
  • Control the moment something goes wrong. Activity logs are there on demand, and a kill switch shuts the agent down from the same screen it was found on.

‍

Impact

Every Agent Has a Known Owner, Right Now

  • 340 agents are accounted for in one view, a count that didn't exist anywhere before the first scan.
  • The 19 agents holding admin access under former employees' names are closed, with no standing credentials left over from someone who no longer works there.
  • Security answers "who owns this agent" on the spot, for any agent, without a follow-up email.

‍

Investigations Start With Answers

  • The activity log is already sitting there the moment someone needs it, no reconstruction required.
  • What an agent touched and changed is visible immediately, not after hours of tracing.
  • Security's time goes into acting on what happened, not searching for what happened.

‍

Risk Gets Shut Down on the Spot

  • 28 agents flagged as risky in the first month were shut down the same day they were found.
  • Nothing stays live waiting for a queue to clear.
  • A single click kill-switch ensures risky agents are remediated without much manual effort 

‍

The Transformation

Before CloudEagle
Agents created across different tools and consoles, with no sign-off and no shared list of what existed.
Security could see agents in any one console, but never the full picture across all of them.
Credentials and permissions inherited with no record of where they came from.
An agent's activity was a mystery until something went wrong and someone had to dig for it.
Shutting down a risky agent meant hunting across consoles first.
After CloudEagle
Check box
Every agent across every console surfaced in one view, with status, owner, and credentials.
Check box
Each agent shown in its actual context, with known permissions and history.
Check box
Activity logs available on demand for any agent, at any time.
Check box
A single kill switch shuts down a risky agent in one click, from the same screen it was found in.
Check box
Every agent mapped to a real, known owner.

Achieve similar success with CloudEagle!