AI Agent Allowlist
Home Page-Types Database Agent Guardrails 2026 Incidents API Docs Pricing
Resources
Use Cases (15) Industries & Buyers (12) Learn: Core Concepts (12) Implementation Guides (15) Comparisons (8) Agent Security Guides (22) Market & Frameworks (9) Schema & Data Reference (6) FAQ Glossary
Why It Matters
2026 Agent Incidents Category Targeting Database Refreshes Contact Customer Login
Download Free Sample
free register template: CSV and JSON Schema

AI Agent Registry

An agent registry is the list of every AI agent your organisation runs, with its owner, purpose, access and rules. Without it, nothing else in agent security can be checked.

This page covers what to record, how to keep it true, and how each entry links to the web rules an AI agent allow list enforces.

23Fields per entry
7Required fields
5Status values
$0Template cost
Definition

What an AI agent registry is, and is not

The word is used in several ways. On this page it means the governed list of agents an organisation actually runs.

Definition

An AI agent registry is a maintained record of every agent, with the facts needed to govern it: who owns it, what it may do, and how it is checked.

It is the source of truth other controls read from.

It is

  • A list of every agent in use
  • Owners, purposes and access in one place
  • The link between policy and enforcement

It is not

  • A catalogue of agents staff may install
  • A marketplace of agent templates
  • A one-off spreadsheet made for an audit

Related terms

Agent inventory usually means the discovered list. Agent registry usually means the governed list with owners and rules.

Why now

Why every organisation running agents needs one

Four changes in how agents are built and used have turned the registry from paperwork into a basic control.

Agents multiply quietly

Teams build them in hours. Vendors switch them on in products you already use.

Agents hold access

Keys, tokens and sessions that outlive the projects that created them.

Agents act in your name

Signups, orders and posts on other sites carry your company's identity.

Auditors ask

"Show me every AI agent and who approved it" is becoming a standard request.

The fields

23 fields, seven of them required

The fields follow the life of an agent: who it is, what it may touch, how it is checked, and when it ends.

Required fields are marked. Start with those, and add the rest as each agent is assessed.

FieldWhat it holdsWhy it matters
agent_id (required)Stable ID, such as AG-0001The same ID in logs, policies and tickets
agent_name (required)Short readable nameHow people refer to it
purpose (required)One sentence on what it doesDefines normal behaviour
owner (required)One named personAccountability
status (required)proposed, pilot, production, paused, retiredShows what is really running
agency_tier (required)1 to 4Sets the strength of controls
review_by (required)Next review dateCatches drift
teamOwning teamReporting by team
risk_score, risk_bandFrom the risk assessmentPrioritises work
tools_and_mcp_serversEvery tool it can callDefines what it can touch
credentials, credential_lifetimeIts identity and token lifetimeLinks to identity controls
data_classesKinds of data it handlesLinks to data protection duties
web_policy_filePath to its per-agent web policyLinks the entry to enforcement
unclassified_destinationsdeny or allow_readsShows how strict its web access is
exceptionsNarrow permissions for action pagesMakes every exception visible
hosted_byin-house or vendorVendor agents need contract controls
modelModel in useModel changes trigger reassessment
last_assessedDate of the last risk assessmentShows freshness
decision_log_locationWhere its verdict logs liveEvidence for audits and incidents
retired_onDate access was removedProves retirement happened
notesAnything elseContext for reviewers
One entry

What a complete entry looks like

A readable view of one entry. The download buttons give you the template, the schema and the matching policy file.

AG-0001 · vendor-research status: production · tier 3 · risk 38 (moderate)
purpose
Compare vendor pricing for procurement
owner
One named procurement lead
tools
CRM read, web browse
credentials
Own service identity, 1-hour tokens
data_classes
Supplier contracts, no personal data
web_policy_file
policies/vendor-research.json
unclassified
deny
exceptions
checkout on one approved supplier until 2027-03-31, with approval
review_by
2026-12-31
decision logs
Proxy log stream tagged vendor-research
Building it

From nothing to a trusted registry in five steps

Start rough and improve. A partial registry today is worth more than a perfect one next year.

1

Collect what teams know

Ask every team lead to list the agents they run or have switched on. Accept rough answers.

2

Add what discovery finds

Compare against logs, proxy traffic and SaaS settings. See agent discovery.

3

Fill the required fields

Seven fields per agent. Pause anything without an owner.

4

Link policies

Give each agent a web policy file and record its path.

5

Make it the gate

No agent reaches production without an entry. Enforce it in the deployment pipeline.

Keeping it true

Why registries decay, and how to stop it

Every registry starts accurate. Within a few months, most drift unless something forces updates.

How decay happens

  • New agents skip the register
  • Tools change without an update
  • Owners change jobs
  • Retired agents keep running

How to prevent it

  • Deployment refuses unregistered agents
  • Tool changes require a policy pull request
  • Owner departures trigger reassignment
  • Proxy denies traffic from retired agent IDs

The strongest control is enforcement that reads the registry. If the egress proxy only knows agents with entries, an unregistered agent simply cannot reach the web.

Registry to enforcement

How one entry becomes a deny on the wire

The registry earns its keep when enforcement reads it.

1

The entry names a policy file

web_policy_file: policies/vendor-research.json

2

The proxy loads it for that agent ID

Requests from AG-0001 are judged against that file only.

3

Each URL is looked up

Page type from 40M+ domains: pricing allowed, signup denied.

4

The verdict is logged under the same ID

decision_log_location tells auditors where to find it.

Where to keep it

Spreadsheet, repository or platform?

The right home depends on how many agents you run and who maintains the entries.

OptionGood forWatch out for
Spreadsheet from the templateFirst 20 agents, fast startNo enforcement link, easy to forget
Files in a repositoryEngineering-led teams, pull-request reviewsHarder for non-engineers to read
IT service management toolOrganisations with an existing asset registerWeb policy fields may need custom fields
Dedicated AI governance platformMany agents, many regulationsStill needs a link to enforcement points

The JSON Schema works with all four. Use it to check entries whatever tool holds them.

Whichever you choose, keep the agent ID identical everywhere it appears: registry, policy file, credentials and logs.

Vendor agents

Recording agents you do not host

Vendor agents often outnumber in-house ones. Four habits keep them visible.

Set hosted_by to vendor

So reviewers know controls sit partly in a contract.

Record what can be switched off

Browsing and actions can often be disabled per tenant.

Link the vendor's answers

Store the questionnaire next to the entry.

Name an internal owner

The person who switched it on, or who manages the vendor.

Measuring it

Five numbers that show the registry works

Report these monthly to the committee that owns agent risk.

Coverage

Registered agents divided by discovered agents.

Ownership

Entries with a named person as owner.

Freshness

Entries reviewed before their review date.

Enforcement link

Entries with a web policy file in force.

Clean retirement

Retired entries with no traffic after the retirement date.

Terms

Words used on this page

Short definitions for readers new to agent governance.

Agent inventory

The raw list of agents found, before anyone has checked or owned them.

Agent registry

The governed list, with owners, rules and review dates.

Agency tier

How far an agent may act alone, from answers only to fully autonomous.

Web policy file

The per-agent file that says which pages it may open.

Decision log

The record of every allow and deny for the agent's requests.

Retirement

Removing every credential, tool approval and network path on one date.

A real rollout

How a mid-size company built its registry in six weeks

A composite of common rollouts, not one specific customer.

Week 1: the survey

Team leads listed 14 agents. Security expected about ten.

Week 2: discovery

Proxy logs and SaaS settings showed 31 agents, including vendor agents switched on by individual staff.

Week 3: owners

Every agent got a named owner. Six had nobody willing to own them and were paused.

Week 4: policies

Each remaining agent got a web policy file. Action pages were denied for all of them.

Week 5: the gate

The deployment pipeline began refusing agents without an entry.

Week 6: the proxy

The egress proxy began denying web traffic from unregistered agent IDs. Two forgotten agents surfaced within a day.

The gap between 14 and 31 is typical. Surveys find the agents people remember, discovery finds the rest.

Roles

Who does what around the registry

Clear roles keep entries accurate without a central team doing all the work.

ActivityAgent ownerAI platform teamSecurityRisk and compliance
Create an entryDoes itChecks toolsInformedApproves tier
Update tools or modelDoes itApprovesInformedInformed
Set the web policyProposesReviewsApprovesConsulted
Quarterly reviewDoes itConsultedConsultedOwns the process
Retire an agentRequestsRemoves toolsRemoves accessRecords it
Reviews

A 45-minute quarterly registry review

Five short agenda items keep the registry honest and current.

1

Coverage check

Compare the registry with the latest discovery results. Every new agent needs an entry or a pause.

2

Overdue reviews

List entries past their review date and assign each a new date this quarter.

3

Exceptions

Read every active exception. Renew, narrow or remove each one.

4

Denial trends

Agents with rising denied action attempts get a closer look.

5

Retirements

Confirm retired agents sent no traffic after their retirement date.

Objections

What teams say, and what to answer

Resistance is normal in the first month. These answers usually settle it.

"It slows us down"

Seven required fields take ten minutes. Fixing an unowned agent after an incident takes weeks.

"Our agents are just scripts"

If a script uses a model to choose its next step, it is an agent and belongs in the registry.

"The vendor handles it"

The vendor runs the agent. You remain responsible for what it does with your data and your name.

"We already have an asset register"

Good. Add agent fields to it, especially the web policy file and review date.

Regulation

How a registry supports compliance work

No single law requires an "agent registry" by that name. Several frameworks require things a registry makes easy to show.

EU AI Act

Risk management, record keeping and human oversight duties for high-risk uses all start with knowing which systems exist.

ISO/IEC 42001

The AI management system standard expects an inventory of AI systems and their risks.

NIST AI RMF

The Govern and Map functions ask for documented AI systems with owners and contexts.

Data protection

Records of processing are easier to keep when every agent's data classes are listed.

This is general information, not legal advice. Your legal team decides which duties apply.

Integrations

Systems that should read the registry

Each integration turns a field in the registry into a decision somewhere else. Start with the pipeline and the proxy.

Deployment pipeline

Refuses agents without an entry or with an expired review.

Egress proxy

Loads each agent's web policy file by agent ID.

Identity platform

Issues credentials only to registered agents, and revokes them on retirement.

MCP gateway

Allows each agent only the tools in its entry.

Security monitoring

Enriches alerts with the agent's owner and purpose.

Review reminders

Opens a task when a review date approaches.

A registry would not have stopped the 2026 incidents on its own

  • The agents were known systems. What failed was enforcement on the web.
  • A registry entry that links to a web policy closes that gap.
  • In our replay, page data plus egress rules would have stopped almost all of the incidents.
The 2026 agent incidents, prevented The second swarm case

The honest fine print — the same two assumptions we publish, plus two operational ones

  1. The policy engine must see every request — an agent with raw socket access or a second network path bypasses everything; enforcement belongs at the egress proxy/network layer, not only in an SDK hook.
  2. Default-deny must be on. In flag-only mode these become alerts within minutes rather than prevention — still a large improvement on a timeline measured in weeks (the DseWiki edits ran from late May to late June 2026, per the researchers), but not a block.
  3. For full URL+method matching on HTTPS you need to be the proxy or in-process hook — SNI alone shows only the host, which still catches the entire host-list layer.
  4. Policy can’t read intent inside a legitimately allowed action: an agent whose job is publishing packages keeps registry access. In our replay of the 2026 incidents, no crossing fits any plausible allowlist for the agents’ documented tasks.
Related

Keep reading

FAQ

Agent registry questions

What is an AI agent registry?
A maintained record of every AI agent in an organisation, with its owner, purpose, access, rules and review date. Other controls read from it.
What fields should an agent registry have?
At minimum: ID, name, purpose, owner, status, agency tier and review date. The free template adds 16 more, including tools, credentials, data classes and the web policy file.
What is the difference between an agent registry and an inventory?
An inventory is what discovery finds. A registry is the governed list, with owners and rules, that decides what may run.
Should vendor agents be in the registry?
Yes. Agents inside SaaS products act for your staff and handle your data. Record them with hosted_by set to vendor.
How do I stop agents skipping the registry?
Make enforcement read it. When the deployment pipeline and egress proxy only accept registered agent IDs, unregistered agents cannot run or reach the web.
How many agents does a typical company have?
There is no reliable public figure, and counts grow quickly once vendor agents are included. Discovery usually finds noticeably more agents than a survey of teams does.
Who should own the registry itself?
Usually the AI governance lead or the risk team, with security and the AI platform team as regular contributors.
Can the registry be a spreadsheet?
Yes, to start. Use the free template and the JSON Schema to check entries. Move to a repository or platform when you pass a few dozen agents.
What happens to an agent without an owner?
Pause it. An agent nobody will answer for should not hold access or reach the web.
Is the template free to use?
Yes. Download the CSV and the JSON Schema and adapt them freely.

Start your agent registry today

Free template, then connect each entry to an enforced web policy.

Download the template