Most businesses that try to solve AI agent sprawl start by building a list. Someone opens a spreadsheet, asks around, and fills in agent names.
Within three months the list is wrong, and everyone knows it is wrong, so nobody uses it.
The problem is not effort. It is that the list was missing the fields that would have kept it alive. A register survives because it is load-bearing — because real decisions depend on it — not because someone was asked nicely to maintain it.
Here is what belongs in one.
Start with the obvious fields
Every agent needs a name, a description, a business function, an environment, a status, and the platform it runs on.
These are table stakes. They make the list readable. They will not keep it accurate.
The five fields that do the real work
1. An accountable owner — one named human
Not a team. Not a department. Not a shared mailbox.
Shared ownership is the same as no ownership. The moment this field allows a group, every difficult question about the agent becomes somebody else’s.
One name. And it must be checked when people leave, which is why this field needs to be joined to your HR system rather than typed once and forgotten.
2. A review date, set when the agent is created
This one field does more than any other to prevent sprawl.
Agents do not announce that they are obsolete. They keep running, keep costing money, and keep holding credentials, long after the reason for them has gone. Nobody switches them off because nobody is prompted to ask.
Requiring an expiry or review date at the moment of creation turns that from a memory problem into a calendar problem. Reviews can extend the date. They just cannot skip it.
3. A value metric, required before go-live
What would tell you this agent is working?
If nobody can answer, the agent should not go live. That sounds strict, and it is — but the alternative is what most businesses have now: agents whose value is asserted and never measured, and which therefore can never be honestly retired.
The metric does not need to be sophisticated. It needs to exist and to be named before launch, because after launch nobody defines it.
4. Record confidence — how you know
This is the field almost everyone leaves out, and it is what makes the register honest.
Some agents are in your list because their builder registered them. Others are there because you found them in a billing export or an identity log and inferred the rest.
Those are not the same quality of record, and a register that treats them identically is lying to you.
Mark how each record was obtained: declared, discovered, or inferred. Then apply the rule that matters — an agent you only inferred cannot be counted as governed. It counts as found. That distinction is the difference between a governance report and a wish.
5. Approved by — and it is never your vendor
Every agent that passed a go-live gate should record who approved it.
If you use a partner to run your agents, this field must still hold one of your names. The moment your supplier can approve their own work into production, your gate is decoration.
What else to link, once the basics hold
A useful register is not one flat table. Around the agent record sit several linked sets:
- Identity grants — which credentials the agent holds, scope, issue and expiry dates
- Tool bindings — what the agent can call, and what each call can do
- Data bindings — what it reads, what it retains, and the classification of both
- Components — the models, frameworks and libraries it depends on, so a vulnerability announcement becomes a query rather than an investigation
- Evaluations — what tests it passed, when, and against which version
- Incidents — what has gone wrong, linked back to the agent
- Cost records — spend attributed per agent and per period
- Chains — which agents call which other agents
That last one deserves attention. Agents increasingly call other agents. When one misbehaves, the question “what else does this touch?” is unanswerable without a chain map — and it is asked in exactly the moment when nobody has time to work it out.
The test of a good register
Not “is it complete?” — it never will be.
The test is whether you can answer these, today, without a project:
- How many agents are in production, and how many of those did we choose to have?
- Which agents hold credentials into our customer data?
- Which agents have no review date within the next twelve months?
- What did agents cost us last month, by business unit?
- If this model provider had a breach, which agents are affected?
If those take longer than a few minutes, the gap is not effort. It is fields.
Where to start
Building an agent inventory is the first stage of the Agent Readiness Audit — and the part most businesses find hardest to start. We do it as a fixed-scope engagement, and the inventory is yours to keep whatever you decide next.
