Skip to main content
The Agents page is your inventory of agents. Everything Switch Trust finds in your code, plus every agent you connect through the SDK, lands here as one row you can open, sort, and search.

The Agents list

Select Agents in the left navigation to open the list. Two cards sit above the table:
  • Total AI spend - What all your agents together have cost this month against your overall cap, with the amount left
  • Spending cap summary - How many agents are healthy, near cap, or over on spend
The top bar also shows how many of your agents are managed (see Managed agents). Each row in the table is one agent. By default the table shows: Select the column control to show more, including Description, Type, Library, Manufacturer, Supplier, Last seen, and Created at. An agent with nothing outstanding shows a dash under Highest severity and Issues.
Search the list by name to jump straight to a specific agent, and sort any column to line agents up by cost, severity, or when they were last seen.
Highest severity and Issues show which agents need attention first. To triage the findings from there, see Discovery results.

Add agents

Select Add agents to choose how a new agent gets into your workspace:
  • Discover agents - Connect a repository or cloud account and let a scan find the agents in your code. See Discover your agents.
  • Monitor & protect agents - Install the SDK so the agent reports live sessions and runs behind guardrails. See Monitor and protect.
  • Evaluate agents - Add an agent for evaluation the same way you add one for monitoring, then configure the endpoint where Switch Trust reaches it. Switch Trust runs continuous red-team and quality assessment against it from there. See Evaluations. You can also evaluate an agent from the command line with the open-source Switch Trust CLI.

The agent record

Select any agent to open its record. The record opens on its Overview tab, with Sessions, Issues, Assets, and Evaluations beside it.

Overview

The Overview tab gathers the agent’s cost, its connections, and its profile in one place. The agent’s name and description appear at the top, and a check icon beside the name marks a managed agent (see Managed agents). Cost cards report what the agent is spending:
  • Cost by month, across a Month, Quarter, or YTD window
  • $ per session
  • Burn rate, the current run rate
  • Monthly cap, the spend limit, with Set a cap when none is set
Until the agent reports through the SDK, the cost cards prompt you to install it. A connections graph shows the models, tools, MCP servers, and sub-agents the agent calls. Beside it, a Connections & data sources card lists how the agent is connected:
  • Code scanning - The scan that discovered it
  • Evaluations - Select Set up evaluations to connect it for evaluation (see Evaluations)
  • Monitor & protect - Select Install SDK to capture sessions and enforce guardrails
An Issues card reports what discovery found: the total, with Critical and High called out above a severity bar, so one Critical issue is easy to tell apart from a long tail of low-severity ones. See Discovery results. The Details card is the agent’s full profile. Fields that don’t apply show a dash:
  • Name and Agent ID
  • Library, Supplier, and Manufacturer, for where it comes from
  • Locations, the files it was found in
  • Description, Instructions, and Context, for how it was briefed
  • Type
  • Models, Tools, MCP servers, and Sub-agents, for what it calls
  • Input guardrails and Output guardrails, the protection attached to it
  • Last seen and Created

Sessions

Until the agent reports through the SDK, the Sessions tab shows Set up agent monitoring: install the SDK, generate an API token, select a guardrail policy, and add the environment variables and code. Sessions appear here once the agent starts processing requests. See Monitor and protect.

Issues

The Issues tab lists the findings open against this one agent, with Assets analyzed, Severity, and Occurrences. Select a finding to open its panel, then read the full record down to the line of code that triggered it. See Discovery results.

Assets

The Assets tab shows the dependencies this agent uses, grouped into Models, MCP Servers, and Tools, each a searchable table, next to a connections graph. Select any asset to open its detail panel. See Assets.

Evaluations

The Evaluations tab runs continuous red-team and quality assessment against the agent: Switch Trust attacks it and scores how well it holds up. Before the agent is connected, the tab shows Connect this agent. Set the Agent type, which is Generic HTTP by default, enter the Endpoint where the agent accepts requests, choose an Authentication method, and add any Headers it needs. Switch Trust supplies the attacker and judge models, so no provider key is needed. Select Test connection to confirm Switch Trust can reach the agent, then select Save changes. Once connected, select Assign evaluations to choose which evaluations run against the agent and how often, such as weekly. The tab then fills in with:
  • Overall evaluation health - The agent’s current score, with the change since the last run
  • Frameworks & coverage - The frameworks the assigned evaluations map to, such as OWASP LLM Top 10, and the specific risks each one covers
  • Overall health trend - How the score has moved across runs
Below the cards, a table lists each assigned evaluation with its Score, Trend, Status, and Last run. An evaluation that hasn’t run yet shows a dash until its first run completes. Open the options menu on any row to Run now, rather than waiting for the schedule, or to Remove the evaluation from the agent. To change how Switch Trust reaches the agent, or to stop evaluating it, use Connection settings.

Managed agents

An agent is managed once it has evaluations, session monitoring, or both. A managed agent reports live activity and runs behind the guardrails you set for it, so its record fills in with runtime data that a discovered-only agent doesn’t have.

Next steps

Assets

Browse the models, MCP servers, and tools your agents depend on

Discovery results

Triage findings, confirm they’re real, and know when they’re resolved