Skip to content
Resource Library
Security 6 min read

Agents and agentless: why you want both

Connectors see your clouds and consoles; agents see the device itself — and a discovery agent sees the devices nobody enrolled. How the layers fit together.

A debate that dissolves under one question

"Agent vs. agentless" gets argued as a philosophy, but it dissolves the moment you ask a concrete question: what are you trying to see? Agentless connections — read-only API access to clouds, identity providers, and security consoles — see everything those systems know, instantly, with nothing to install. Agents — software running on a device — see the device itself from the inside. These are different vantage points on different truths, which is why mature security programs stopped choosing years ago.

What agentless sees — and where it stops

Read-only connectors are the fastest visibility you will ever get. Ten minutes of setup and your entire AWS footprint is inventoried: every instance, bucket, role, and security group, with misconfigurations checkable continuously. The same applies to your identity provider (every account, MFA state, privilege) and to consoles like Defender or Qualys, which happily export what they already know. No deployment project, no per-device maintenance, no performance cost.

The limit is built in: an API can only tell you what its system knows. Your cloud doesn't know whether a laptop's disk is encrypted. Your identity provider doesn't know what software is installed on a server. And no API anywhere knows about the machine that was never enrolled in anything. Agentless visibility is broad and shallow exactly where devices are concerned.

What agents add — and what discovery adds on top

A device agent answers the questions APIs can't: OS and patch level, installed software, disk encryption, firewall and antivirus state, end-of-life systems, and the CVEs present on this specific machine — reported hourly, from the inside. On mobile, the same idea takes a lighter form: per-device enrollment that reports posture without managing the phone, which is the difference between BYOD users accepting it and refusing it.

Then there's the layer both approaches miss: the devices nobody enrolled and no console tracks. Printers, cameras, IoT, the contractor's laptop, the forgotten NAS. A network discovery agent — one per segment, passively listening to what devices announce — surfaces that shadow inventory as discovered, unmanaged assets. It's the answer to the question that precedes all others: is our inventory even complete?

The layered answer

Layer them by what each does best: agentless connectors first for instant breadth across clouds, identities, and the consoles you already run; device and mobile agents where depth matters — laptops, servers, phones; a discovery agent per segment to catch what everything else missed. One inventory, three vantage points, no gaps between them by design.

That's the architecture Cybermatic ships: twenty read-only integrations for breadth, its own Device Agent, Device Trust mobile app, and Discovery Agent for depth and completeness — all included on every plan, all feeding one posture, one set of findings, and one set of reports.

Security Essentials, Weekly

A practical weekly briefing on real-world security misconfigurations, why they matter, and how to fix them.

One email a week, unsubscribe any time. We use your address only to send the briefing — see our Privacy Policy.