On this page

Pattern: Agent Registry

A runtime-aware inventory of every model, service and agent, each with an owner, a scope and an expiry, written by the deploy pipeline, not by hand.

Layer 02 · Inventory & Transparency In the chapter 05 catalogue

Summary: Maintain a runtime-aware inventory of every model, service and agent, each entry carrying an owner, a scope and an expiry, fed by the deployment pipeline rather than typed by hand. The registry is the object that policies evaluate and runtime controls attach to.

Agent Registry and Scoped Identity An architecture diagram generated by Archify. Model Owner · renew or entry expires · Architecture component Model Owner renew or entry expires Deploy Pipeline · registers at deploy · Governance plane: register, scope, evaluate Deploy Pipeline registers at deploy Agent Registry · owner, scope, expiry · Governance plane: register, scope, evaluate Agent Registry owner, scope, expiry Workload Identity · scoped credential · Governance plane: register, scope, evaluate · SPIFFE/SPIRE Workload Identity scoped credential SPIFFE/SPIRE Agent · delegated authority · Runtime plane: agent acts under scoped identity Agent delegated authority APIs, Tools, Agents · channel auth (MCP) · Architecture component APIs, Tools, Agents channel auth (MCP) Policy Gate · deny unregistered · Governance plane: register, scope, evaluate Policy Gate deny unregistered Shadow-AI Reconcile · flag runtime drift · Governance plane: register, scope, evaluate Shadow-AI Reconcile flag runtime drift Evidence Log · signed, per identity · Runtime plane: agent acts under scoped identity Evidence Log signed, per identity Auditor · attributes actions · Architecture component Auditor attributes actions register at deploy issue scoped credential carry workload identity act, least privilege renew, 90-day expiry evaluate entry admit, deny unregistered log actions attribute reconcile vs running, flag drift Governance plane: register, scope, evaluate Runtime plane: agent acts under scoped identity Legend Backend Database Security External
Agent Registry and Scoped IdentityHow the deploy pipeline registers each agent, issues it a scoped workload identity, and files signed evidence an auditor can attribute, with a policy gate that denies the unregistered. Generated from the Body of Knowledge.Open interactive diagram (opens in a new tab)

Objectives

Answer “what AI is running, and what is it allowed to do?” from a live source, and make registration a precondition of reaching production.

Target users

AI governance engineer, platform team, security engineer.

Impacted stakeholders

Model owners, deployers, auditors, incident responders.

Relevant principles

Register and bound every actor before it acts; make the governed path the easiest path.

Context

An organisation deploying models and agents across teams, where no single source knows what is live.

Problem

A hand-maintained inventory is correct on the day it is edited and wrong within a week. Without owner, scope and expiry, an action cannot be attributed, a scope cannot be enforced, and a stale agent lingers with standing access no one revisits.

Solution

Make the registry an API the deploy pipeline writes to: a new model or agent registers itself at deploy with an owner, a declared scope and an expiry after which the entry must be renewed or is deactivated. Deny production access to unregistered artefacts. Reconcile periodically against what is actually running (see Shadow-AI Discovery) and flag drift.

Illustrative schema for a registry entry:

{
  "id": "csa-01",
  "version": "2026-09-18",
  "owner": "team-support-platform",
  "scope": ["refunds:read", "orders:read"],
  "expiry": "2026-12-17"
}

Consequences

Attribution, scope enforcement and lifecycle control become possible, and every other layer gets an object to anchor to. The cost is pipeline integration and the governance to enforce the expiry.

Agent Identity & Scoped Credentials; AIBOM; Shadow-AI Discovery; Kill Switch / Circuit Breaker.

Maps to: EU AI Act Art. 49/71, Art. 11 · ISO/IEC 42001 · NIST AI RMF (Map) · CSA AICM · OWASP Agentic ASI10 · Layer 02 Inventory & Transparency.

Threat IDs follow the OWASP Top 10 for Agentic Applications 2026 1 and function labels the NIST AI RMF2. Mappings are illustrative, not a claim of conformity.

Sources

  1. [1] Top 10 for Agentic Applications 2026 (ASI IDs). OWASP GenAI Security Project. 2025-12-09. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ (verified: primary)
  2. [2] AI Risk Management Framework (AI RMF 1.0; Govern, Map, Measure, Manage). NIST. 2023-01-26. https://www.nist.gov/itl/ai-risk-management-framework (verified: primary)
Edit this page on GitHub
Cite this pattern

García Aibar, J. (2026). Pattern: Agent Registry. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), chapter 05, Patterns. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/patterns/agent-registry. CC BY 4.0

BibTeX

@misc{aige2026bok,
  author  = {Jorge García Aibar},
  title   = {{AI Governance Engineering: The Thesis \& Body of Knowledge}},
  chapter = {05. Patterns: Agent Registry},
  year    = {2026},
  version = {0.5.0},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/patterns/agent-registry},
  note    = {Version 0.5.0}
}
Share on LinkedIn