# The Agent Registry Nobody Maintains

> An agent inventory becomes useful when it can answer who owns a running service, what it depends on, and how to retire it.

[Canonical HTML page](https://trustcyber.ca/insights/enterprise-ai-agent-registry/)

- Author: [Junior Williams](https://trustcyber.ca/about/)
- Type: Insight brief
- Published: 2026-09-26
- Modified: 2026-09-26
- Topics: Agentic AI, Enterprise architecture, AI governance

A registry can look complete on launch day and become unreliable a month later. The agent still appears in the catalogue, but its owner has changed teams, its connector has gained another permission, and the listed model version is no longer running.

The operational question is whether the record helps someone act. During an incident, can an operator find the person responsible? Before changing a shared tool, can its owner identify the agents that depend on it? When a pilot ends, can the organization confirm that its credentials and scheduled jobs have been removed?

## Give each record a job

Separate the stable identity of the agent from the changing details of its deployment. A durable identifier lets logs, approvals, service records, and evaluations refer to the same system even when its display name changes. A named business owner explains why it exists; a service owner explains who keeps it running.

![One agent record connects to business and service owners, its deployment, tools and credentials, and approval and evaluation records.](https://trustcyber.ca/images/insights/decision-series/registry-relationships.svg)

A proposed registry record acts as an index to authoritative systems. It does not need to duplicate every log or configuration file.

AWS’s agent portfolio guidance treats agents as a managed estate, with inventory, ownership, dependencies, and lifecycle considerations. Applying that idea well requires deciding where each field gets its truth. Deployment version should come from the deployment system where possible. Business purpose usually needs confirmation from a person.

**Keep the source of each field visible**

| Field | Prefer this source | Review trigger |
| --- | --- | --- |
| Running version and environment | Deployment system | Each release |
| Tools and effective permissions | Connector and identity configuration | Access change |
| Purpose and accountable owner | Named business owner | Transfer or change of use |
| Approval and evaluation history | Decision and test records | Material change |
| Retirement status | Decommissioning record | End of use |

## An entry is not an approval

Discovery and authorization serve different purposes. A registry may help another team find an agent, but the requester still needs permission to use it for a particular task. Avoid a catalogue badge that makes an experimental service appear generally approved. Make lifecycle status and permitted use easy to understand.

Treat an unknown owner as an operational exception. Establish who investigates it and what restrictions apply while ownership is unresolved. Otherwise, the registry can quietly preserve the appearance of accountability after the accountable person has left.

## Retirement is part of the product

Removing a catalogue entry is only one part of retirement. The owner needs to revoke credentials, stop scheduled work, remove tool routes, notify dependent teams, and preserve records required for business or investigation purposes. Keep the retired identifier searchable so historical logs remain intelligible.

A useful portfolio review can start with three short lists: agents with no current owner, agents with no recent use, and agents whose observed configuration differs from their record. Investigating those lists gives the registry a reason to stay current. The result is a catalogue that supports decisions throughout the agent’s life.

## Selected primary sources

- [AWS Well-Architected: Agent portfolio management](https://docs.aws.amazon.com/wellarchitected/latest/agentic-ai-lens/agentops03-bp04.html)
- [Microsoft Learn: Manage agent registry](https://learn.microsoft.com/en-us/entra/agent-id/identity-platform/what-is-agent-registry)
- [AWS: Agent Registry generally available](https://aws.amazon.com/about-aws/whats-new/2026/08/aws-agent-registry-generally-available/)
