Shelved Agents and the Case for Agentic Lifecycle Management
When enterprises iterate on their agent workflows, older agents rarely get decommissioned.
Across our customer base, the majority of how end users interact with agents right now is hands-on: agents helping people work faster, improving output, with the human moving from executor to reviewer. One enterprise restructured its development workflow around agentic pods, with individual engineers running teams of agents, and saw pull request volume jump from 50 a month per developer to 250. That is the productivity story everyone is aspiring to tell.
What tends to get missed underneath that iteration process is what happens to the preceding agents. Every time a team builds a newer agent or restructures a workflow, the previous agent persists: it keeps its API keys, its system access, its token consumption. Nobody decommissions it because nobody built a process for that. What we consistently find across customer environments is agents that are shelved without anyone knowing they are shelved, still credentialed, still consuming tokens, with no owner accountable for them.
Gartner projects that by 2028, the average Fortune 500 enterprise will have over 150,000 agents in use, up from fewer than 15 in 2025, and only 13% of organizations believe they have the right governance in place. The Wall Street Journal reported that DaVita’s employees alone created more than 10,000 agents, and the company struggled to maintain understanding of what many of them were doing. TLDR: if agent creation continues to scale at this pace while retirement processes remain absent, shelved agents will be a structural feature of every enterprise within the next two years.
The formal taxonomy for agent sprawl
The shelved agent problem has first been classified in a April 2026 paper on arXiv. The paper introduced the Agentic AI Governance Maturity Model (AAGMM), grounded in NIST AI RMF and ISO/IEC 42001 standards, and with it a five-pattern taxonomy of agent sprawl: functional duplication, shadow agents, orphaned agents, permission creep, and unmonitored delegation chains. Each pattern is linked to quantifiable business cost models.
The shelved agent maps most directly to the “orphaned agent” classification, defined as an agent whose owner has left or whose purpose has ended while the agent itself persists. In practice, though, shelving often sits at the intersection of orphaned agents and functional duplication, because the newer agent that replaced the old one is doing similar work, and both continue to consume resources. Where these patterns surface also differs by how agents are built. Orphaned agents tend to concentrate on low-code/no-code platforms like Copilot Studio, where the barrier to creation is low enough that agents proliferate without centralized oversight. Functional duplication, by contrast, is more common among agents created in code, particularly in environments where agentic coding tools allow engineering teams to iterate and rebuild faster than any manual inventory can track.

From a separate research direction, the OWASP Non-Human Identities Top 10, published in 2025, ranks Improper Offboarding as the number one non-human identity risk. OWASP defines this as the inadequate deactivation or removal of non-human identities when they are no longer needed, covering three scenarios: applications deprecated without decommissioning their associated identities, owners who depart while associated credentials remain active, and administrators who leave without revoking the credentials they provisioned. The shelved agent fits all three.
The governance gap
What we tend to find in customer environments is that shelved agents are more common than the rogue agents security teams spend their time worrying about. An agent that was working, that got iterated past, and that now sits idle with live credentials and no owner. In the context of an enterprise running thousands of agents, “forgotten” carries real risk.
Companies have decades of practice retiring human employees: payroll systems, org charts, offboarding workflows that revoke access and close accounts. They have ITAM for SaaS sprawl and FinOps for cloud sprawl. For their agentic workforce, they have almost nothing. There is no performance review that surfaces a dormant agent, no headcount reconciliation that flags redundancy, and no org chart that makes one visible. The CSA’s 2026 analysis found that 78% of organizations have no policy for creating or retiring AI-related identities at all.

Shelved agents and the financial dimension
For shelved agents, the cost profile is also particularly difficult to detect because it looks routine from the billing layer. A billing API or model router sees token counts from a dormant agent, but it cannot distinguish productive work from waste. An agent running loops on a deprecated workflow blends into overall token spend, indistinguishable from the agents producing value.
Surfacing that distinction requires connecting agent behavior to the spend it generates, so that cost data carries enough context to separate an agent that is working from one that should have been retired. Without that connection, cost optimization stays at the infrastructure level, where the only levers are rate limits and model downgrades, neither of which addresses the underlying question of whether an agent should still be running at all.
Where security, IT, and AI governance leaders should focus
The pattern here is familiar to anyone who has lived through SaaS sprawl or cloud sprawl. When a new technology class proliferates faster than the governance infrastructure around it, the corrective sequence is always the same: discover what you have, understand what it is doing, establish lifecycle management, and build the operational muscle to retire things that no longer serve a purpose.
For the agentic workforce, that sequence is still in its earliest stages at most organizations. From this perspective, there are three areas where security, IT, and AI governance teams can start building the infrastructure that shelved agents expose as missing.
- Agent discovery that goes beyond what teams self-report. The gap between what an organization thinks it has and what it actually has is consistently large. Our own customer data shows discovery gaps of 327% and higher, meaning the actual agent population is more than four times what the security team estimated. Manual inventories, employee surveys, and platform-specific registries each capture a slice; none of them captures the full picture across cloud, code, and endpoint.
- Behavioral understanding that connects identity, activity, and cost. Knowing that an agent exists is step one. Knowing what it is doing, whether it is still serving a productive purpose, whether its access permissions match its current function, and what it is costing the organization, that is the understanding layer that turns an inventory into a management system. The same behavioral data that surfaces a security risk can also explain whether an agent should have been retired.
- Lifecycle governance that extends through retirement. The Gartner and OWASP frameworks both emphasize that agent governance must extend through the full lifecycle, including decommissioning. An agent registry that catalogs deployments but has no mechanism for flagging dormancy, revoking credentials, or triggering reviews is an inventory, and inventories alone do not solve lifecycle problems.
The shelved agent is a useful diagnostic for enterprise resilience maturity. The organizations that can identify, measure, and retire agents that have outlived their purpose are the same ones that will confidently scale their agentic workforce, because the lifecycle infrastructure that catches a dormant agent also strengthens the agents that are still working. Discovery, behavioral understanding, and lifecycle governance are the foundation, but none of it holds without clear ownership that ties every agent back to an accountable team. Everything else builds on top of that!