The first step in securing AI agents is not counting them but tracing their data paths, according to Kelly Herrell, CEO of Nol8. An agent inventory shows what an organization believes it deployed, while the data path reveals what is actually exposed—and the gap between the two is the real risk. Most teams can confirm whether an agent is legitimate and what it is authorized to reach, but few can say what it should see or disclose in a specific interaction.

Surprising exposure points are not necessarily databases but the systems enterprises have accumulated for years: ticketing systems, CRM platforms, shared drives, and chat histories. A single ticket can hold a pasted production log with a live credential, customer account details, and a step-by-step incident narrative. Historically, assembling that picture required a human to know where to look and connect pieces by hand—friction that quietly acted as a security control. Agents remove that friction, making sensitive data discoverable, combinable, and movable in seconds.

For a 90-day plan, Herrell advises starting with visibility, not redesign. Map the paths between agents, data sources, models, and tools; measure what sensitive data crosses those boundaries; and establish where policy can be enforced at runtime. Postpone large builds like identity overhauls, perfect data classification, or per-role masked replicas—they scale with the number of agents and roles, not with risk. The objective is to establish control at the points where data moves, then widen coverage.

The tension between business and security teams—context versus restriction—is not a binary choice. An agent may need access to Salesforce or Jira without needing every field those systems return. The better model is to enforce policy on the data itself, redacting or blocking sensitive fields in flight per agent and role. This avoids maintaining masked copies that grow with every role and agent. A deterministic enforcement point in the data path, one that reads every payload and decides by content rather than labels, is what lets security teams sign off on a mechanism. That is the third option beyond "allow everything" and "block the agent."