A vendor who cannot enumerate what they miss does not know what they miss — and you are the one holding the unmeasured exposure.
Why Coverage Honesty Matters Now
Every AI discovery pitch now ends the same way: “we see everything.” Total visibility across the estate, every agent, every endpoint, every connector. It demos beautifully. It is also, for any agentless approach, structurally impossible — unmanaged devices, remote Macs, the contractor laptop that never enrolled in MDM, and the local MCP server that produces zero network traffic all sit outside the collection surface. The question is not whether a vendor has blind spots. The question is whether they can hand you the list.
The exposure math makes this urgent rather than academic. Ospiri’s fleet research finds AI agents already active on endpoints in 88% of enterprise environments, and our published research puts the incremental cost of an ungoverned agent incident at +$670K over a comparable conventional breach. IBM’s Cost of a Data Breach work has repeatedly found that breaches involving “shadow data” — assets the organization didn’t know it held — take longer to find and cost more to resolve. An unenumerated blind spot in your agent inventory is exactly that asset class, compounding quietly.
| Signal | Number | Source |
|---|---|---|
| Enterprises with AI agents already active on endpoints | 88% | Ospiri fleet research |
| Incremental cost of an ungoverned agent incident | +$670K | Ospiri published research |
| Breaches involving unknown (“shadow”) data assets | Roughly one in three | IBM Cost of a Data Breach |
| Window before agent governance consolidates into platforms | 12–18 months | Ospiri published research |
Think of it the way a risk desk thinks about a portfolio. A book that is 84% marked to market with the remaining 16% enumerated, characterized, and priced is a manageable book. A book that claims to be 100% marked — with no methodology attached — is a book whose true exposure nobody has measured. You would never accept the second from a trading desk. Security teams accept it from discovery vendors every quarter.
Two Claims, Two Very Different Books
“We cover 84% of your fleet, and here is the gap report” and “we cover 100%” sound like the second vendor is winning. Decompose the claims and the ranking inverts.
| Dimension | “100% coverage” | “84%, here are the gaps” |
|---|---|---|
| Measurement | Asserted — no denominator offered | Measured against an explicit device denominator |
| Blind spots | Unenumerated, therefore unpriced | Listed by category, owner, and data exposure |
| Audit posture | Assertion an auditor will discount | Evidence an auditor can test |
| Roadmap value | None — nothing left to fix, allegedly | The gap list is the deployment plan |
| Incentive structure | Rewards hiding misses | Rewards finding misses |
| Failure mode | Silent — you learn about gaps from an incident | Explicit — you learn about gaps from a report |
The deeper point is about the denominator. A coverage percentage is only meaningful against a count of what should be covered — and building that denominator (every device, every identity, every egress path) is most of the actual work of agent observability. A vendor who claims 100% has usually defined the denominator as “the things we can see,” which makes the claim circular: perfect coverage of the covered.
Anatomy of a Blind Spot
Where do the misses actually live? Across deployments, the gap list is remarkably consistent:
- Unmanaged and BYOD devices. No MDM enrollment, no agent, no telemetry. Frequently the machines running the most aggressive AI tooling, because nobody is watching.
- Remote Macs. Fleet tooling built Windows-first ships macOS coverage months later; developer Macs are precisely where Cursor, Claude Desktop, and local agents concentrate.
- The contractor laptop. On the VPN, touching the repo, owned by another company’s IT department. Present in the work, absent from the inventory.
- Local stdio MCP servers. Spawned processes wiring agents into source trees over local pipes — zero proxy traffic, zero SaaS log entries, invisible to any network-edge collection method.
- Ephemeral compute. Short-lived VMs and containers that spin up, run an agent job, and vanish before a periodic scan ever fires.
Notice the pattern: each category is invisible to a specific collection method — MDM, network edge, SaaS logs, periodic scan. That is why the blind-spot taxonomy matters more than the headline percentage. It tells you which collection method the vendor actually built, and therefore which residual risk you are retaining.
The Coverage Confidence Framework
Turn the honesty question into a number. For any discovery vendor — or your own program — score:
Coverage Confidence = (Measured Coverage × Measurement Independence) − (Unenumerated Surface × Estate Churn)
| Factor | What it captures | How to score it |
|---|---|---|
| Measured Coverage | Devices observed ÷ an independently built denominator | 0–1, from your CMDB/identity graph, not the vendor’s console |
| Measurement Independence | Was the denominator built outside the tool being scored? | 1.0 independent, 0.5 vendor-assisted, 0.1 vendor-defined |
| Unenumerated Surface | Estimated share of estate in unlisted blind-spot categories | 0 if the taxonomy is complete; grows with every “we hadn’t thought of that” |
| Estate Churn | Rate of new devices, agents, and connectors per quarter | High churn decays yesterday’s coverage number fast |
A vendor quoting 84% with an independent denominator and a complete taxonomy can score higher than one quoting 100% against a denominator they defined themselves. That is the whole argument in one line of arithmetic — and it slots directly into the posture reviews your agent governance program already runs.
What CISOs Should Do This Quarter
Demanding the gap report is the cheapest diligence you will ever run. Operationally:
| Step | Action | Output | Effort |
|---|---|---|---|
| 1 | Build your own denominator from identity, MDM, and network sources | Device and agent count the vendor didn’t produce | 1–2 weeks |
| 2 | Ask each shortlisted vendor for measured coverage, method, and blind-spot taxonomy | Comparable coverage claims with methodology attached | One email per vendor |
| 3 | Score each vendor with the Coverage Confidence formula | A ranked shortlist defensible in front of the audit committee | 1 day |
| 4 | Treat the winning vendor’s gap list as the phased rollout plan for deeper, kernel-level control | Deployment sequence ordered by exposure, not convenience | Ongoing |
A vendor who responds to step 2 with a taxonomy and a measured number is a vendor who has done the work. A vendor who responds with “we see everything” has just answered a different, more important question.
The Bottom Line
In agent discovery, an honest 84% with an enumerated gap list is worth more than an asserted 100%, because the gap list is the only part of the claim you can act on. The unmeasured book is always the one that blows up; the enumerated gap is a known position you can hedge, monitor, or close, while the hidden one compounds at estate-churn speed. So make coverage honesty a scored procurement criterion, not a vibe. If your team is sizing agent discovery for this budget cycle, request a working session — we will walk through your environment, build the independent denominator and blind-spot taxonomy with you, and scope a deployment. It takes 90 minutes.