This matters to Microsoft shops because Entra is one of only two identity sources the tool supports at launch. The tool also reads Microsoft Entra Agent ID, where an organization has enabled it.
What happened
HYCU announced aiR Graph is generally available at no cost, directly from HYCU and through its global partner network. Blocks & Files reported on the launch on October 9. The tool connects read-only to Entra ID and Okta, and any organization can use it whether or not it is a HYCU customer.
The product sits inside HYCU's wider aiR family. aiR lets organizations search, query and run purpose-built agents across their backup data. aiR Graph is a narrower, identity-driven offshoot of that.
What it reports
Per Blocks & Files, the first scan maps the applications in the organization and flags the copilots and agents among them. For each agent it reports:
- the OAuth scopes the agent holds
- the data sources it can read or write
- whether it has organization-wide access
- whether it can act unattended
- how many users can invoke it
- whether anyone is recorded as its owner or sponsor
Severity is ranked by capability, not just by whether an owner exists. HYCU's examples of high-risk findings are:
- unattended access to every user's data
- broad access combined with write or delete rights
- an account that is still enabled after its agent identity was deleted
Next, the tool shows which applications agents reach most, and which of those HYCU R-Cloud can protect. A one-click assessment report follows, with an executive summary, recommended triage actions and a full inventory. HYCU's datasheet says findings are graded by severity with a clear action: review, confirm, or revoke.
HYCU's product page lists the kinds of agents it expects to find, including those from Copilot Studio, Agentforce, Rovo, Glean, Now Assist, and home-built agents. The tool only finds agents registered in the connected identity provider. aiR Graph finds AI agents registered in your identity provider. The same page says it is free, with no limits on seats, agents, or time.
Why the Entra angle matters
Microsoft's documentation explains why identity data is a sensible place to start. DCIG's coverage notes the tool connects through read-only access to platforms such as Microsoft Entra Agent ID and Okta. That fits how Microsoft models agents. Per Microsoft Learn, an agent identity is a special service principal in Microsoft Entra ID.
Microsoft's agent identity documentation adds several details that map onto aiR Graph's fields:
- Agent identities can have a sponsor, which records the human user or group accountable for the agent. That corresponds to HYCU's owner/sponsor check.
- Microsoft distinguishes autonomous agents, which acquire app tokens, from interactive agents called with a user token. That is the same distinction as HYCU's "unattended" flag. Microsoft does not say how HYCU classifies agents, so I can't confirm the exact mapping.
- Agent identities don't hold credentials of their own. They rely on an agent identity blueprint to acquire tokens on their behalf.
- Agent identities can only be issued tokens in the tenant where they were created.
- Blueprints let an administrator apply a Conditional Access policy to, disable, or revoke permission grants for every agent of one kind.
The blueprint point is useful for triage. If an inventory flags a worrying agent type, the blueprint is the lever Microsoft provides to act on all agents of that type at once. aiR Graph itself is read-only, so it reports and does not remediate.
The "no language model" design
HYCU's chief product officer, Anant Chintamaneni, said the company deliberately kept language models out of the risk assessment. He said every finding comes from an explicit rule applied to data read from the identity provider. He also said that running the assessment twice on the same tenant gives the same answer, and that each finding traces back to the field that produced it.
That is a sensible choice for a report an auditor or board will read. It is also a vendor claim. The source offers no independent testing or published methodology, so treat repeatability as asserted rather than verified. Reviewing a sample of findings against your own Entra data is a reasonable sanity check.
Limits and open questions
- Scope is identity-driven. The tool maps agents that appear in Entra or Okta. It does not claim to find agents with no identity record in those systems. Shadow agents that bypass identity registration may be invisible to it.
- It is an assessment, not protection. It does not block agent activity or restore data. HYCU's proposed fix is an independent, immutable R-Cloud backup of exposed applications. R-Cloud covers more than 100 workloads, but the source does not list them, so don't assume every flagged app is supported.
- The backup recommendation comes from the vendor. The free assessment ends with a sales path to HYCU's paid product. That is not unusual, and the inventory still has value on its own, but readers should weigh it accordingly.
- Details not supplied. The reporting doesn't give the exact Entra roles or consent permissions needed to connect, data-retention terms, or scan duration. Check those with HYCU before connecting a production tenant.
- A backup must be tested. An inventory doesn't show that any backup is recoverable. That has to be configured and tested separately.
Jason Buffington of Data Protection Matters called permissions-versus-backup-coverage mapping a gap assessment many teams didn't realize they needed. That is attributed commentary, not a technical evaluation.
A practical way to use it
Based on the tool's described outputs, a sensible workflow for an Entra administrator would be:
- Confirm whether Entra Agent ID is enabled, since the tool reads it only where it is.
- Run the free assessment and review the highest-severity agents first, especially unattended agents with write or delete scopes.
- Assign owners or sponsors to any agent without one.
- Check whether the applications those agents write to have an independent recovery copy, from HYCU or any other tool you already use.
- Use Microsoft's own controls, such as Conditional Access and permission revocation, on agent types you can't justify.
Bottom line
aiR Graph doesn't fix the agent-sprawl problem. It makes the problem visible and ties it to recoverability. For Microsoft 365 and Entra environments filling up with Copilot Studio and third-party agents, a no-cost, read-only inventory is a low-friction first look. Just remember that its view is limited to what your identity provider knows, and its recommended remedy happens to be HYCU's own product.
References
- HYCU's aiR Graph maps AI agents - Blocks & Files Blocks & Files · 2026-10-09T14:18:00+00:00
- aiR Graph Datasheet: Free AI Agent & SaaS Discovery hycu.com
- HYCU aiR Graph: Find AI Agents and SaaS App Risks hycu.com