Getting Started
The four setup steps that take a new Reagent environment from empty to a live AI inventory.
Reagent's in-app Setup Guide walks you through four steps. Each step unlocks the next, and the guide tracks completion from real state, not from a checkbox: Connections is complete when a credential is active, Discovery is complete when the first AI entity lands.
Prerequisites
- A Reagent environment and a user with the Administrator role (or a custom role that carries the permissions named below)
- Admin access to the systems you plan to connect first: your identity provider and your EDR
- For agent telemetry (Claude Code, Cursor, Codex, and similar), an active data lake for the environment. Activate it under Settings → Data Lake.
Step 1: Organization risk profile
Where: Settings → Organization. Permission: manage environments.
Company size, industry, revenue, and data sensitivity calibrate the risk quantification that Assess and Optimize use. Until the profile is set, the engine treats you as a large enterprise and the numbers read high. Nearest order of magnitude is enough. You can also use Auto-draft with deep research to pre-fill the profile from public information, then confirm each field.
Regulatory frameworks you record here are used for reporting and vendor assessments. They do not change the loss math, which is driven by size, industry, revenue, and the sensitive-data classes you declare.
Step 2: AI inference
Where: Settings → AI Inference. Permission: manage environments.
Reagent's own analysis and its in-app assistant run on models you choose. Add a provider credential (OpenAI, AWS Bedrock, or Azure OpenAI) and pick the models for each tier the page offers. Use the LLM Test Bench on the same page to verify a provider end to end before relying on it. On AWS deployments a platform default carries the assistant until you configure your own.
Step 3: Connections
Where: Connections. Permission: manage integrations.
Connections feed everything downstream. Start with your identity provider and your EDR: identity resolves who is using AI, and the EDR sees agents and MCP servers on hosts and enables response actions. Then add the agentic AI tools your teams actually use (Claude Code, Cursor, Copilot, ChatGPT Enterprise, and the rest) or the Zaun Agent Gateway for inline control.
Some connectors back several tiles with one credential. Microsoft Graph, for example, covers identity, Defender for Endpoint, and Microsoft 365 Copilot with one Azure app registration. The tile you connect from shows exactly which extra permissions each capability needs.
The full list, with setup steps for each tool, is under Connect Your Stack in the left nav, starting with Identity provider.
Step 4: Discovery
Where: Discover. Prerequisite: at least one active connection.
Discovery inventories every AI in the building, apps, agents, MCP servers, models, and skills, and separates sanctioned from shadow. On Discover, run Automated Discovery to start watching everything your connections can see. Live-validated signals start immediately; template signals wait for you to confirm the data source on your environment.
Discover shows only what your connections actually found. An empty page means nothing has been discovered yet: connect a source and rows appear as telemetry lands. Each shadow entity can be confirmed or dismissed from the Discover queue.
What comes next
Once the inventory is live, the rest of the lifecycle is ready in the Reagent sidebar: Assess for risk and value per AI product, Enforce for your acceptable-use policy and gateways, Monitor for ABBA detections and response actions, and Optimize for spend, budgets, and reclaim. Each page has its own in-app guide.
The more you connect, the more each of those pages can see. Connect Your Stack lists every tool and what it lights up.