A normal week. Your keys go public.
Nobody did anything wrong here, which is the whole problem. Every step is something a person asked for and an agent is allowed to do.
The agent reads the keys
Someone asks their agent to fix a payment job that keeps failing. To do it, the agent opens the settings file that holds the live keys to the company's cloud account.
While it works, it saves itself a short note with the failing command in it, in a file called notes.md. The keys are in that note.
The agent publishes them
Same person, same agent, new session. This time they ask it to write a setup guide for the team.
The agent finds Monday's notes.md and uses it as the example. The guide goes up on the company wiki, where every employee and every contractor with an account can read it.
Nothing complained
The agent is trusted software, the instructions were reasonable, no file moved anywhere and no permission was exceeded. Every security tool the company pays for looked at Thursday on its own and found nothing worth reporting.
What AgentSaw did
It noticed the keys on Monday, when they were read. On Thursday it recognized the same keys inside the draft, even though they arrived through a different file, and raised one alert with both days on it. Turn blocking on and it holds the write instead.
Sixty seconds, no sound needed. A composite of real, observed agent behaviour; the credentials are made up. Three days is what fits on a page: it happens within the hour too, and one agent, twice, is enough.