HYCU Makes aiR Graph Generally Available: A Free Map of Every AI Agent in the Enterprise, What It Can Reach, and What Isn’t Protected
aiR Graph gives IT and security teams a fast way to triage which applications are most at risk of agentic data loss and disruption, starting with the ones that have no independent backup
This is a Press Release edited by StorageNewsletter.com on October 9, 2026 at 2:01 pmHYCU, Inc., an AI Resilience company, announced the availability of HYCU aiR Graph, a free solution that discovers the AI agents operating across an organization’s applications, shows which workloads each agent can reach and who can invoke it, and identifies which of those applications lack independent backup.
Agents increasingly run with broad permissions and write access to systems of record. A misconfigured instruction, a compromised credential, or an agent acting outside its intended scope can change or delete data across multiple applications at machine speed. Where those applications have no independent backup, that data cannot be recovered. aiR Graph connects read-only to Microsoft Entra ID and Okta and is available to any organization, whether or not it is a HYCU customer.
The first question IT and security teams may face is: how many agents are running, and what can they touch? This is often hard to answer. Business units connect copilots and create agents faster than IT can track them, and a periodic inventory is out of date before it is finished. aiR Graph answers that question from the first scan. It then answers the one that matters when an agent gets it wrong: can the organization recover the data?
“Every organization we talk to is adding AI agents faster than it can count them, and most of those agents hold permissions nobody regularly inspects,” said Simon Taylor, founder and CEO, HYCU. “If you can’t see it, you can’t protect it. aiR Graph gives any organization that first look for free. It shows which agents can change or delete data, and which of the applications they reach have no independent copy to recover from. That second answer is where resilience starts.”
How HYCU aiR Graph works
aiR Graph follows the order a security or IT team would work through the problem: find the agents, judge what they can do, then protect what they can reach.
- First Supported Discovery Sources for Read-only Connection to Identity: aiR Graph connects read-only to Microsoft Entra ID, including Microsoft Entra Agent ID where it is enabled, and to Okta, including Okta AI Agents where the organization subscribes. Entra ID and Okta are the first supported discovery sources, and HYCU will be adding more
- Discovery of Applications and Agents. The first scan maps the total applications in the organization and flags all copilots and agents in the organization
- What Each Agent Can Reach, and Who Can Invoke It. For every agent, aiR Graph shows its OAuth scopes, the data sources it can read or write, whether it has organization-wide access, whether it can act unattended, how many users can invoke it, and whether anyone is recorded as its owner or sponsor
- Findings to Act On. Severity reflects capability, not just ownership. The more an agent can reach and change, the higher it ranks: unattended access to every user’s data, broad access combined with write or delete permissions, or an account still enabled after its agent identity was deleted
- From Exposure to Protection. aiR Graph shows which applications agents reach most and which of those HYCU R-Cloud can protect, so teams can backup the systems of record most exposed to agent activity first
- Assessment Report. One click produces a point-in-time report with an executive summary, recommended triage actions, and a full inventory for management, audit, or board review
Once aiR Graph shows that an agent can write to a Git repository, a Salesforce org, or a Confluence space, the next step is an independent, immutable backup of that application in HYCU R-Cloud, which protects more than 100 workloads. That copy is what lets an organization roll back to the moment before an agent went wrong.
From Preview to General Availability
HYCU gave the first public look of aiR Graph at the 69th IT Press Tour in Ljubljana, Slovenia, home to one of HYCU’s main engineering centers. Since then, a select number of customers have run aiR Graph in preview.
“We made a deliberate choice to keep language models out of the risk assessment,” said Anant Chintamaneni, CPO, HYCU. “Every finding in aiR Graph comes from an explicit rule applied to data read from your identity provider. Run it twice on the same tenant, and you get the same answer, and every finding traces back to the field that produced it. When a security team takes that report to an auditor or a board, it has to hold up.”
Availability
HYCU aiR Graph is available today at no cost, directly from HYCU and through HYCU’s global partner network. Organizations can connect Microsoft Entra ID or Okta and run their first assessment at aiR Graph. aiR Graph is part of HYCU aiR, which lets organizations search, query, and run purpose-built agents across their backup data. To join the aiR early adopter program, click here.
What The Industry is Saying About HYCU aiR Graph
“SaaS vendors have always been clear that protecting your data is your job,” said Johnny Yu, research manager, storage and data management, enterprise infrastructure, IDC. “What’s changed is who’s touching it. When an AI agent with write access makes a mistake, the platform will do exactly what it was told, and if there’s no independent backup, that’s the end of the story. Mapping agent permissions against backup coverage is the gap assessment most IT and security teams don’t yet know they need.”
“Agentic AI changes the risk model for data protection. The question is no longer only whether an application is backed up, but which non-human identities can modify it and how fast,” said Philippe Nicolas, analyst and market watcher, Coldago Research. “aiR Graph addresses this by correlating identity data from Entra ID and Okta with protection coverage, and its extensible design for additional discovery sources is a correct architecture for a market that will not standardize on a single identity provider.”













