Agentic Inventory Matrix
What agents exist, what they touch, what threats they face?
Filter
Layers, by what they can actually enforce
- Self-declared — advisory
The agent reports itself. It can be wrong, stale, or absent entirely.
- Operator-declared — deterministic-when-invoked
The operator registered it. Accurate only as far as the operator knows.
- Discovered — deterministic-and-external
Found independently by scanning the target. Trusts neither of the above.
Showing 15 of 15.
Identity at Self-declared
Agent registers on startup with name, charter ref, owner email, instance ID. Heartbeats. Deregister on shutdown. Dead-mans-switch alerts on heartbeat lapse.
Identity at Operator-declared
Operator-maintained registry; agents.yaml in GitOps; ServiceNow CMDB; internal AI inventory tool. Owner-confirmed. Updated on charter signature.
Identity at Discovered
CloudTrail / GCP Audit Logs of SA and IAM principal usage. K8s controller watching SA+RoleBinding by naming pattern. Reverse-lookup from credential fingerprints in Sentinels.
Authorization at Self-declared
Agent reports allowed-tools list, MCP allowlist hashes, effective scope on registration. Updates on scope change.
Authorization at Operator-declared
Operator records authorized scope in registry, linked to RBAC manifest paths and IAM policy ARNs.
Authorization at Discovered
K8s RBAC API list, AWS IAM Access Analyzer effective permissions, Kyverno PolicyReports of policies actually applied.
Blast radius at Self-declared
Agent reports declared risk tier, damage cap, forbidden operations from its charter. Reports current environment and data class access.
Blast radius at Operator-declared
Operator records blast-radius profile per agent. Worst-case impact statement (revenue, customer, compliance).
Blast radius at Discovered
Threat-modeling output (MAESTRO Layer 7, MITRE ATLAS, lateral-movement path analysis). Behavioral observation of what the agent has touched.
Approval gating at Self-declared
Agent reports last charter signature date, next review due, current charter version on registration. Refuses to start if charter is expired.
Approval gating at Operator-declared
Operator-maintained review calendar. Quarterly attestation. Tracks pending and overdue reviews.
Approval gating at Discovered
Registry of charter files in source control. Last-modified, last-PR-merged. Cross-reference with self-declared and operator-declared.
Supply chain at Self-declared
Agent reports current dependency manifest on registration: foundation model + version, MCP server names + hashes, base image SHA, lockfile fingerprint. Updates on change.
Supply chain at Operator-declared
Operator records authorized-dependency manifest from agent charter. Linked to Covenants L2-C5 and L3-C5 allowlists. Version-controlled audit trail.
Supply chain at Discovered
Image-registry pull events, package-manager logs, runtime introspection of loaded models and connected MCP servers, SBOM scanning. Drift between actual and authorized = alert.