Map agents, tools, credentials, integrations and workflows, then see the impact before you remove, revoke or replace them.
Every agent sits on the same chain of dependencies. This is exactly what the deterministic detectors look for in your code — nothing more, nothing inferred.
It's knowing what depends on it six months later.
Select an operation and watch the blast radius light up, and what stays quiet.
A dependency map that quietly drops what it can't resolve looks complete when it isn't. An unresolved reference stays on the map on every scan, not just the demo above.
Not just a graph. A checklist ordered by what has to happen first.
This is what a platform engineer sees after connecting every repo their team owns: not one graph, but a portfolio of them.
| Repository | Credentials | MCP | Agents | Unknown | Status |
|---|---|---|---|---|---|
| payments-api | 3 | 1 | 2 | 0 | OK |
| support-agent-repo | 2 | 2 | 1 | 1 | Review |
| billing-worker | 4 | 0 | 1 | 0 | OK |
| internal-tools | 1 | 1 | 0 | 0 | OK |
| data-pipeline | 2 | 0 | 3 | 0 | OK |
| legacy-crm-sync | 5 | 1 | 0 | 2 | Stale credential |
| growth-experiments | 1 | 2 | 4 | 1 | Review |
| infra-scripts | 2 | 0 | 0 | 0 | OK |
| onboarding-flow | 2 | 1 | 1 | 0 | OK |
| analytics-worker | 3 | 0 | 2 | 0 | OK |
| sales-enablement-bot | 2 | 3 | 2 | 1 | Review |
| notification-service | 1 | 0 | 0 | 0 | OK |
Click into any credential and it's merged across every repository that references it by name, so “what breaks if I revoke this?” means the whole org, not just the repo you happened to be looking at.
Deterministic detection first. An LLM is only ever asked to summarize what was already found, never to invent a dependency.
scan: kev-er/support-agent-repoScanning repository...✓ 3 agents detected✓ 9 dependencies detected✓ 2 MCP servers detected✓ 4 credentials detected1 unknown relationshipScan complete.impact: CustomerSupportAgent --removePotential impact:6 systems affected1 workflow2 integrations1 credentialUnknown:customer-sync webhook
Built for the engineer who gets asked “can we safely revoke this token?”