Avanoo Agent and licence data
How Avanoo Agent reads seats, usage, cost, and renewal from vendor admin consoles, where AI is used, and which controls keep it read-only.
Avanoo Agent connects to the admin consoles of your software vendors (for example OpenAI Platform, Cursor, Notion, or any console with a login page) and reads licence data on a schedule: seats bought and assigned, members and their activity, usage and quota, billing, and renewal. It never changes anything in the console.
Avanoo Agent is being rolled out progressively. This page describes how it works so security and procurement teams can review it before it is enabled.
Where AI is used, and where it is not
Avanoo Agent works in two separate phases.
- Writing the script. For each console, large language models write a browser automation script, similar to a Playwright test, that describes which pages to open and which fields to read. An Avanoo engineer reviews the script before it goes live.
- Running the script. Every collection runs that fixed script. It performs the same navigation and reads the same fields each time. No language model interprets the console or decides what to do during a collection.
Because values are read by a deterministic script and not generated by a model, the agent cannot hallucinate a seat count, a price, or a member list. A value is either read from the page, with evidence, or the collection fails visibly.
API first, console when needed
When a vendor offers an admin API, Avanoo reads through it. When the data is only available in the web console, Avanoo Agent reads it in a browser. Every value shows how it was obtained:
- API-verified: read through the vendor API.
- Browser-read: read in the vendor console by Avanoo Agent, with evidence.
The Allow console reading when no API exists setting controls the second path. When it is off, only vendors with an API can be connected.
What the agent reads
When you connect a console, you choose what Avanoo Agent may collect:
- Seats and plan
- Members and roles (e-mail, role, status, last active)
- Usage and quota
- Billing and renewal
- Storage, where the console exposes it
The agent never reads message bodies, documents, prompts, or API keys. It stores the collected values and their evidence, never your password.
How the agent signs in
You choose one of three access paths for each console.
| Access path | How it works |
|---|---|
| Hand over my session | You sign in yourself inside a secure browser, including SSO and MFA. The agent keeps only the resulting session, never the password. |
| Ask through the Avanoo extension | The console administrator receives a request in the Avanoo browser extension and signs in to the secure browser from there. |
| Dedicated Avanoo account | You invite an Avanoo e-mail address dedicated to your organization (<organization>@integrations.avanoo.ai) with a read-only role. Avanoo handles SMS codes with its own phone number. |
For a dedicated account, Avanoo recommends the least privileged role that still shows seats and billing: for example Reader in OpenAI Platform, Membership admin in Notion, or a read-only administrator or billing viewer role elsewhere. The first collection starts once the invitation is accepted.
Isolated browser sessions
Each connector runs in its own isolated browser profile, dedicated to one console and one organization. The profile holds the console session and nothing else.
- When you sign in, your password stays on the vendor's page. Avanoo does not see or store it.
- A profile is never shared between consoles or between customers.
- Disconnecting a connector destroys its profile and session. Values already collected stay in Avanoo until the next collection would have replaced them.
How a collection runs
Each step below is performed by the script, not by a model:
- Open the console with the saved session.
- If the console asks for a second verification step, pause and ask an administrator to approve.
- Read members and seats.
- Read plan and billing.
- Capture evidence for each value.
- Compare with the previous collection and record what changed.
Collections run every 6 hours, daily at 06:00, or weekly, and can also be started manually. If the console does not respond in time, the collection is retried at the next schedule. If the saved session has expired, collections stop until an administrator reconnects.
Read-only by design
Avanoo Agent only reads. It does not remove users, change plans, or edit settings in a vendor console. When a collection reveals something to act on, such as unused seats, the finding becomes a proposal in Actions for an administrator to approve.
Transparency and evidence
For every connector, Avanoo keeps:
- a collection history: when each run happened, what triggered it (schedule, manual, or first run), which pages were read, how many rows were read, and what changed since the previous run;
- an evidence record for every value, with the console page it came from and the capture time; and
- optionally, a snapshot of the console page for each value read in the browser. E-mail addresses and names can be masked in snapshots.
Admin controls
Administrators control Avanoo Agent under Settings > Sources:
- Enable Avanoo Agent: turning it off pauses every connector and hides agent data.
- Allow console reading when no API exists: when off, only vendors with an API can be connected.
- Keep evidence snapshots: keep a rendering of the console page for each value. The structured evidence record is always kept.
- Mask personal data in snapshots: replace e-mail addresses and names in snapshots.
- Allow a dedicated Avanoo account: let administrators use the dedicated account access path.
Each connector can also be paused, resumed, reconnected, or disconnected at any time.
Hosting
Avanoo Agent runs on Amazon Web Services in AWS Europe (Paris), eu-west-3, like the
rest of the Avanoo platform. Browser sessions, collected values, and evidence stay in the
same EU hosting. See Hosting, security, and compliance
for residency, subprocessors, and certifications.
FAQ
Can the agent see sensitive data?
Only what the account it signs in with can see, and only within the scopes you selected. A read-only role limits what is visible in the console. The agent reads seat, member, usage, and billing information. It never reads message bodies, documents, prompts, or API keys.
Does Avanoo store our credentials?
No. With session handover or the extension, you sign in on the vendor's page and Avanoo keeps only the session in an isolated profile. With a dedicated account, the account belongs to Avanoo and holds only the read-only role you grant it.
Can the AI hallucinate values?
No. Collections run a fixed, reviewed script that reads values from the page. No language model produces the numbers, and each value has an evidence record you can check against the console.
Does a language model see our console data during collections?
No. Language models are only used to write and update the collection scripts. Scheduled and manual collections run the script without a model.
What happens if a vendor changes its console layout?
The script does not guess. If an expected page or field is missing, the collection fails visibly and the previous values are kept. The AI drafts an updated script, and an Avanoo engineer reviews it before it goes live.
How do SSO and two-factor authentication work?
With session handover or the extension, you complete SSO and MFA yourself in the secure browser. With a dedicated account, Avanoo handles SMS codes with its own phone number. If a console asks for an extra verification step during a collection, the run pauses until an administrator approves.
What happens when a session expires?
Collections for that connector stop and the connector is marked for reconnection. An administrator signs in again to resume.
Which language models are used, and for what?
Avanoo uses several large language models, only to write and maintain the collection scripts. They are not used to read, interpret, or store your console data during collections.
Can the agent run on-premises?
No. Avanoo Agent runs in Avanoo's AWS hosting in eu-west-3.