# HYCU's aiR Graph maps AI agents

> Source: <https://www.blocksandfiles.com/data-protection/2026/10/09/hycus-air-graph-maps-ai-agents/5302225>
> Published: 2026-10-09 14:18:00+00:00

data protection

# HYCU's aiR Graph maps AI agents

Cyber-resilience data protector [HYCU’s](https://www.blocksandfiles.com/public-cloud/2026/09/08/hycu-extends-microsoft-saas-protection-to-azure-dev/ops/5295010) aiR Graph product connects to Entra ID and Okta to map every AI copilot and agent listed there.

It’s free, read-only, and discovers the AI agents operating across an organization's applications to find out what each one can read or write, whether it acts unattended, how many people can invoke it, is anyone listed as its owner, and and then identifies which of those AI agent-interacting applications lack independent backup. HYCU says agents increasingly run with broad permissions and write access to systems of record. A misconfigured instruction, a compromised credential, or an agent acting outside its intended scope can change or delete data across multiple applications at machine speed. Where those applications have no independent backup, that data cannot be recovered.

HYCU founder and CEO Simon Taylor said: "Every organization we talk to is adding AI agents faster than it can count them, and most of those agents hold permissions nobody regularly inspects. If you can't see it, you can't protect it. aiR Graph gives any organization that first look for free. It shows which agents can change or delete data, and which of the applications they reach have no independent copy to recover from. That second answer is where resilience starts.”

Jason Buffington, Principal Analyst, Data Protection Matters, points out: “Mapping agent permissions against backup coverage is the gap assessment that most IT and security teams didn't realize they needed and will appreciate immediately."

The [aiR software](https://www.blocksandfiles.com/data-protection/2026/05/14/hycu-adds-agentic-backup-data-intelligence-layer-to-find-and-fill-risk-gaps/5240353) was announced in May to query multiply-sourced backup data to find cyber-resilience risks no single-source risk visibility app can discover. The aiR Graph offering identifies agentic risk to applications. In  detail, aiR Graph does this:

- Connects read-only to Microsoft Entra ID, including Microsoft Entra Agent ID where it is enabled, and to Okta, including Okta AI Agents where the organization subscribes. Entra ID and Okta are the first supported discovery sources, and HYCU will be adding more.
- The first scan maps the total applications in the organization and flags all copilots and agents in the organization.
- For every agent, aiR Graph shows its OAuth scopes, the data sources it can read or write, whether it has organization-wide access, whether it can act unattended, how many users can invoke it, and whether anyone is recorded as its owner or sponsor.
- Risk assessment with severity reflecting capability, not just ownership. The more an agent can reach and change, the higher it ranks: unattended access to every user's data, broad access combined with write or delete permissions, or an account still enabled after its agent identity was deleted.
- It shows which applications agents reach most and which of those HYCU [R-Cloud](https://www.blocksandfiles.com/data-protection/2025/04/25/hycu-puts-up-r-shield-extra-protection-in-its-r-cloud/1590517) can protect, so teams can back up the systems of record most exposed to agent activity first.
- Assessment Report - one click produces a point-in-time report with an executive summary, recommended triage actions, and a full inventory for management, audit, or board review.

Once aiR Graph shows that an agent can write to a Git repository, a Salesforce org, or a Confluence space, the next step is an independent, immutable backup of that application in HYCU R-Cloud, which protects more than 100 workloads. That copy is what lets an organization roll back to the moment before an agent went wrong.

HYCU Chief Product Officer Anant Chintamaneni said: "We made a deliberate choice to keep language models out of the risk assessment. Every finding in aiR Graph comes from an explicit rule applied to data read from your identity provider. Run it twice on the same tenant, and you get the same answer, and every finding traces back to the field that produced it. When a security team takes that report to an auditor or a board, it has to hold up.”

HYCU aiR Graph has extensible design for additional discovery sources, and is available to any organization, whether or not it is a HYCU customer, directly from HYCU and through its partner network. It’s is part of HYCU aiR, which lets organizations search, query, and run purpose-built agents across their backup data.

To join the aiR early adopter program, visit [https://www.hycu.com/air](https://www.hycu.com/air).
