Browse documentation

Build reliable agent inventory

The Agent inventory gives every governed agent a clear owner, purpose, environment, risk posture, and lifecycle. Good inventory makes approvals faster and incidents easier to investigate.

What to record

Before adding an agent, collect:

FieldGood practice
NameStable and recognizable, such as support-triage-prod.
EnvironmentSeparate production, staging, development, and local use.
OwnerA team and a person or on-call path that can respond.
PurposeThe business job the agent is expected to perform.
VersionThe deployed application or agent release.
Risk tierBased on the highest-impact action the agent may request.
Allowed actionsNarrow operation classes and systems, not a broad “all tools” grant.
PolicyThe default governance posture for this agent.

Register an agent

Open Agents, choose the add action, and work through the staged review. Confirm ownership and environment first, then risk, authentication references, allowed actions, and policy association.

Use the final review to catch mismatches such as a low-risk label on an agent that can modify production data.

Manage lifecycle deliberately

Lifecycle describes administrative intent. Update it when the agent is introduced, paused, disabled, revoked, or retired, and record why the change happened.

Changing a registry state does not stop software running elsewhere. Pair an emergency registry change with the appropriate credential revocation, deployment action, and destination-system control.

Keep the record current

Review an agent record after:

  • a new production deployment;
  • an ownership or on-call change;
  • a credential rotation;
  • new tools or systems are added;
  • a policy exception is granted; or
  • an incident changes the agent's allowed scope.

Verify the real integration

Registration establishes inventory, not connectivity. Send a controlled low-risk request through the agent and confirm the decision appears under the expected organization and agent identity.

For important actions, verify both sides:

  1. the Sernixa decision and evidence; and
  2. the destination system's result.

Next step

Define the agent's policy and approval posture, then review its explicitly authored relationships in the Trust Graph. If the agent uses MCP, continue with MCP servers.