Priced per governed agent.
Not per surprise.
Start with discovery to see what is running. Pay for governance only on the agents you govern. No per-seat games, no data-volume traps.
Three ways in.
See what is running
The full inventory: every agent, risk-scored and owner-mapped, across IdP, cloud, and endpoints.
- ✓ Continuous agent discovery
- ✓ Shadow AI detection
- ✓ Agent registry with ownership
- ✓ Risk and blast-radius scoring
Govern every action
Everything in Discover, plus runtime governance. Priced per governed agent, so cost scales with what you actually govern.
- ✓ Per-action verdicts, under 30ms
- ✓ Step-up and human-in-the-loop approvals
- ✓ 150+ governed connectors
- ✓ Audit-ready evidence, at action time
Your environment, your terms
Everything in Platform, plus the deployment and control options large environments need.
- ✓ Hybrid or on-prem data plane
- ✓ AgenShield + BrowserShield (EA) rollout
- ✓ External MCP for customer agents
- ✓ Dedicated support and onboarding
You pay for governed agents. Not for everything we can see.
Discovery watches everything, free of drama. The meter runs only on agents you place under runtime governance. Govern ten agents in a two-thousand-agent inventory and you pay for ten. A governed agent is one price whether it acts a hundred times a day or a hundred thousand.

Everything, tier by tier.
SWIPE TO COMPARE TIERS →| Capability | Discover | Platform | Enterprise |
|---|---|---|---|
| Discovery & inventory | |||
| Continuous discovery: IdP, cloud, endpoints | ✓ | ✓ | ✓ |
| Shadow AI detection | ✓ | ✓ | ✓ |
| Agent registry with named ownership | ✓ | ✓ | ✓ |
| Risk & blast-radius scoring | ✓ | ✓ | ✓ |
| Runtime governance | |||
| Per-action verdicts (<30ms) | — | ✓ | ✓ |
| Step-up & human-in-the-loop approvals | — | ✓ | ✓ |
| Policy plane (one rule, every surface) | — | ✓ | ✓ |
| 150+ governed connectors · 1,000+ tools | — | ✓ | ✓ |
| Custom API connectors (3-day SLA) | — | ✓ | ✓ |
| Evidence & audit | |||
| Per-action audit chains | — | ✓ | ✓ |
| SOC 2 · ISO 27001 · GDPR mapping | — | ✓ | ✓ |
| SIEM export | — | ✓ | ✓ |
| Autonomous operations | |||
| Policy Builder (drafts from real traffic) | — | ✓ | ✓ |
| Compliance Mapper (continuous) | — | ✓ | ✓ |
| Agent in the Loop (step-up triage) | — | ✓ | ✓ |
| Enforcement surfaces | |||
| Gateway enforcement | — | ✓ | ✓ |
| AgenShield · on-device | — | — | ✓ |
| BrowserShield · in-browser | — | — | EA |
| External MCP (customer & partner agents) | — | — | ✓ |
| Deployment & support | |||
| SaaS deployment | ✓ | ✓ | ✓ |
| Hybrid data plane | — | — | ✓ |
| On-prem / air-gapped data plane | — | — | ✓ |
| Dedicated onboarding & support | — | — | ✓ |
Questions, answered.
How is Agen.co priced?
Is there a free way to start?
Does price change with action volume?
What does Enterprise add?
Can we mix tiers?
Get a number for your environment.
Tell us your agent count and stack; you will have a quote this week.