Build reliable agent inventory
The Agent inventory gives every governed agent a clear owner, purpose, environment, risk posture, and lifecycle. Good inventory makes approvals faster and incidents easier to investigate.
What to record
Before adding an agent, collect:
| Field | Good practice |
|---|---|
| Name | Stable and recognizable, such as support-triage-prod. |
| Environment | Separate production, staging, development, and local use. |
| Owner | A team and a person or on-call path that can respond. |
| Purpose | The business job the agent is expected to perform. |
| Version | The deployed application or agent release. |
| Risk tier | Based on the highest-impact action the agent may request. |
| Allowed actions | Narrow operation classes and systems, not a broad “all tools” grant. |
| Policy | The default governance posture for this agent. |
Register an agent
Open Agents, choose the add action, and work through the staged review. Confirm ownership and environment first, then risk, authentication references, allowed actions, and policy association.
Use the final review to catch mismatches such as a low-risk label on an agent that can modify production data.
Manage lifecycle deliberately
Lifecycle describes administrative intent. Update it when the agent is introduced, paused, disabled, revoked, or retired, and record why the change happened.
Changing a registry state does not stop software running elsewhere. Pair an emergency registry change with the appropriate credential revocation, deployment action, and destination-system control.
Keep the record current
Review an agent record after:
- a new production deployment;
- an ownership or on-call change;
- a credential rotation;
- new tools or systems are added;
- a policy exception is granted; or
- an incident changes the agent's allowed scope.
Verify the real integration
Registration establishes inventory, not connectivity. Send a controlled low-risk request through the agent and confirm the decision appears under the expected organization and agent identity.
For important actions, verify both sides:
- the Sernixa decision and evidence; and
- the destination system's result.
Next step
Define the agent's policy and approval posture, then review its explicitly authored relationships in the Trust Graph. If the agent uses MCP, continue with MCP servers.