Agent Inventory
An inventory that stops at models and chatbots is already incomplete. The fastest-growing exposure is AI that acts — and most of it is running as an anonymous service account.
A model generates an answer. An agent takes an action.
A chatbot drafts a reply and a human sends it. An agent creates the transaction, moves the data, calls the API, and starts the next process — on its own, with delegated authority.
That is a different class of risk, and today it is almost always deployed the same way: as a generic service credential, with no dedicated identity, no bounded authority, and no record of which agent acted on whose behalf.
When something goes wrong, the first question is the one nobody can answer: which agent did this, under whose authority, and what was it allowed to touch?
| Agent | Owner | Acts on | Reaches | Authority | Gap |
|---|---|---|---|---|---|
| Finance agent | CFO | Creates payments | ERP, banking API | Under $10k | No spend log |
| Support agent | VP Support | Issues refunds | CRM, payments | Under $500 | Shared credential |
| Ops agent | COO | Changes records | Data lake, SaaS | Unbounded | No human check |
Every agent, and the five controls each one needs.
The agent register
For every AI agent in scope:
- What it does, and what it can act on — not just what it reads
- A named business owner
- The identity it runs under — dedicated or shared
- What it is authorized to do, and the limits on it
- Which systems, data, and other agents it can reach
- Whether a human is required before consequential actions
- What record it leaves — and whether that record is enough
The control gaps
Where each agent is missing identity, scoped authority, a human checkpoint, or a usable log — who owns closing each gap, and by when. Recorded, not omitted.
The exposure profile
Which agents can move money, change records, or reach regulated data — and which of those can do it without a human in the loop. This is what scopes the remediation that follows.
Governing an agent is an identity problem before it is a policy one.
There is no single agent-governance standard yet, but the control set is converging — and it maps onto disciplines a regulated enterprise already runs.
Identity
Every agent uniquely identified — not sharing a person's or a service account's credential.
Authorization
Least privilege, scoped to a task, with hard limits — spend caps, approval thresholds.
Oversight
A required human checkpoint before consequential actions — the AI Act's human-oversight duty, in practice.
Logging
An immutable, reconstructable record of what each agent did, when, and under whose authority.
Monitoring
Behavioral monitoring and control over the tools and data an agent can reach.
It extends the inventory. It also feeds the governance.
The Agent Inventory is the action-layer companion to the AI Use Inventory — run together, or added once agents are in production. Its output feeds directly into AI Governance and the impact assessment underneath it.
Led directly by Ramon J. Matos — CISSP, ISO/IEC 42001 Lead Implementer, three decades in the identity, access, and infrastructure an agent actually runs on.
Discuss an Agent Inventory.
We'll tell you whether your agents need remediation now, governance around them, or executive ownership — and we'll say so if they're fine.