Skip to content
CapabilitiesIdentity & Registry
15CORE PRODUCT

Agent Registry

If an agent cannot be found and understood in the registry, it should not receive privileged authority.

Priority
P0
Phase
MVP
Primary owner
Product / Platform
Status
Blueprint

Objective

The registry is the system of record for agent identity, ownership, purpose, risk and lifecycle. It should feel like a purpose-built CMDB for autonomous software, but with dynamic fields for models, tools, delegation, policies and business intent.

What to build

  • Maintain canonical profile for every agent and agentic application.
  • Track business owner, technical owner, approving executive and support team.
  • Store intended purpose, data classes, approved tools, environments and permitted autonomy level.
  • Link credentials, deployments, versions, model providers, MCP servers and policies.
  • Track lifecycle states: discovered, claimed, registered, verified, privileged, suspended, retired.

Implementation decisions

  • Support bulk ownership assignment and API-driven registration from CI/CD.
  • Require stronger metadata before an agent can enter privileged state.
  • Record all registry changes as auditable events.
  • Expose inventory filters for risk, business unit, provider, owner, data class and environment.

Definition of done

  • No production privileged agent exists without owner and purpose.
  • Registry history shows who changed sensitive metadata and why.
  • Retiring an agent triggers credential and access-review workflows.

Success metrics

  • Owned-agent percentage
  • Stale agents
  • Time to claim discovered agent
  • Privileged agents with complete metadata

SYSTEM OF RECORD

If an agent cannot be found and understood in the registry, it should not receive privileged authority.

This control is specified on page 15 of the blueprint.