Discover · the action layer

Agent Inventory

An inventory that stops at models and chatbots is already incomplete. The fastest-growing exposure is AI that acts — and most of it is running as an anonymous service account.

Why agents are different

A model generates an answer. An agent takes an action.

A chatbot drafts a reply and a human sends it. An agent creates the transaction, moves the data, calls the API, and starts the next process — on its own, with delegated authority.

That is a different class of risk, and today it is almost always deployed the same way: as a generic service credential, with no dedicated identity, no bounded authority, and no record of which agent acted on whose behalf.

When something goes wrong, the first question is the one nobody can answer: which agent did this, under whose authority, and what was it allowed to touch?

Illustrative example of the agent register — not client data.
AgentOwnerActs onReachesAuthorityGap
Finance agentCFOCreates paymentsERP, banking APIUnder $10kNo spend log
Support agentVP SupportIssues refundsCRM, paymentsUnder $500Shared credential
Ops agentCOOChanges recordsData lake, SaaSUnboundedNo human check
What you get

Every agent, and the five controls each one needs.

The agent register

For every AI agent in scope:

  • What it does, and what it can act on — not just what it reads
  • A named business owner
  • The identity it runs under — dedicated or shared
  • What it is authorized to do, and the limits on it
  • Which systems, data, and other agents it can reach
  • Whether a human is required before consequential actions
  • What record it leaves — and whether that record is enough

The control gaps

Where each agent is missing identity, scoped authority, a human checkpoint, or a usable log — who owns closing each gap, and by when. Recorded, not omitted.

The exposure profile

Which agents can move money, change records, or reach regulated data — and which of those can do it without a human in the loop. This is what scopes the remediation that follows.

The control canon

Governing an agent is an identity problem before it is a policy one.

There is no single agent-governance standard yet, but the control set is converging — and it maps onto disciplines a regulated enterprise already runs.

01

Identity

Every agent uniquely identified — not sharing a person's or a service account's credential.

02

Authorization

Least privilege, scoped to a task, with hard limits — spend caps, approval thresholds.

03

Oversight

A required human checkpoint before consequential actions — the AI Act's human-oversight duty, in practice.

04

Logging

An immutable, reconstructable record of what each agent did, when, and under whose authority.

05

Monitoring

Behavioral monitoring and control over the tools and data an agent can reach.

Where it fits

It extends the inventory. It also feeds the governance.

The Agent Inventory is the action-layer companion to the AI Use Inventory — run together, or added once agents are in production. Its output feeds directly into AI Governance and the impact assessment underneath it.

Led directly by Ramon J. Matos — CISSP, ISO/IEC 42001 Lead Implementer, three decades in the identity, access, and infrastructure an agent actually runs on.

Know what your agents can do

Discuss an Agent Inventory.

We'll tell you whether your agents need remediation now, governance around them, or executive ownership — and we'll say so if they're fine.