Skip to content
Rush Commerce
AI & Automation4 min read

Reco raises $55M. One customer had 21,000 unknown agents

Reco raised $55M for agent security after a Fortune 100 customer found 21,000 agents nobody had approved. Agent inventory is the control you can build free.

A Fortune 100 company turned on agent discovery and found 21,000 agents nobody had approved. That number, reported by TechCrunch on September 29, is the clearest argument yet for doing AI agent inventory before you do anything else. Reco raised $55 million on the strength of that problem. You can address the small-business version of it this afternoon with a spreadsheet.

What actually happened

Reco announced $55 million in additional funding — a strategic investment from AT&T Ventures with new investors Forestay and Quadrille Capital — bringing total capital to $140 million. It extends the $30 million round the company closed in February. TechCrunch labels it a Series C and reports annual recurring revenue in the double-digit millions, expected to triple this year, with more than 100 customers and roughly 40% of revenue from financial services.

The product maps the relationships among agents, identities, applications, permissions, data and workflows — 280-plus app integrations and about 1,000 detection controls. The pitch is discovery first: find the agents running in your environment, then see which identity each one borrows and what it can reach. One large financial services customer used it to find a rogue agent with unauthorized Salesforce access.

Reco's release cites a Gartner projection that the average global Fortune 500 enterprise will run more than 150,000 agents by 2028, up from fewer than 15 in 2025. CEO Ofer Klein's framing: "AT&T's participation reflects the need for security that follows agents across enterprise ecosystems."

The category is crowded. TechCrunch names AIR, Cymphony, CrowdStrike's Falcon Guardian, HiddenLayer and Zenity as competitors. That matters for pricing.

Why agent inventory matters for your business

You do not have 21,000 agents. You probably have somewhere between eight and forty, and you cannot name them. Every Zapier zap with an AI step, every GPT you built into a Slack workflow, every Make automation a contractor set up in 2024, every MCP server your dev tool connects to, every "AI assistant" toggle someone flipped on in your CRM. Each one holds a token. Some of those tokens belong to people who left.

The expensive part of the enterprise problem is discovery at scale. The cheap part — the part that delivers most of the risk reduction — is a list. Build it:

Pull the connected-apps page for every SaaS tool you pay for. Google Workspace, Microsoft 365, Shopify, Stripe, HubSpot, Slack. Each one has a screen showing every OAuth grant. Read it. Revoke what you do not recognize.

Write down, for each agent, whose identity it runs as. The single worst pattern in small-business automation is an agent authenticated as the founder's personal account, because that account has everything. Move each one to a dedicated service account with the narrowest scope that works.

Check your offboarding list against your automation list. When someone leaves, you kill their email. You almost certainly do not kill the three automations running on their token. Those keep working until they silently stop, which is the good outcome.

Then shop, if you still need to. Five funded vendors chasing the same buyer means list prices are negotiable and the feature sets are converging. If your inventory turns out to be forty agents on a spreadsheet, a platform is not your next purchase — least-privilege is.

The discipline scales down cleanly. Know what runs, know whose keys it holds, and know how to turn it off. Tooling makes that faster at 21,000. It does not replace it at 21.

Key takeaways

  • Reco raised $55M in additional funding (AT&T Ventures, Forestay, Quadrille Capital); total capital now $140M
  • A Fortune 100 customer discovered 21,000 agents nobody had approved, per TechCrunch
  • Reco's release cites Gartner projecting 150,000+ agents per Fortune 500 enterprise by 2028, from fewer than 15 in 2025
  • At least five funded vendors now compete in agent security — list prices are negotiable
  • Build your own inventory free: read every SaaS connected-apps page and revoke what you cannot name
  • Move every automation off personal accounts onto scoped service accounts, and add automations to your offboarding checklist

Most small businesses cannot name the automations running in their own stack. We audit what is connected, whose credentials it holds, and what it can reach — then rebuild the ones worth keeping on scoped service accounts you control. Send us your tool list and we will map it, or see how we build automation with least-privilege by default.

Sources: GlobeNewswire, TechCrunch, SecurityWeek.

  • #agent-security
  • #ai-agents
  • #shadow-it
  • #governance
  • #funding
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.