Home › Identify
Agentic Inventory Matrix
NIST CSF 2.0 · Identify (ID) · 5 concerns × 3 layers
What agents exist, what they touch, what threats they face?
Concern Self-declaredadvisory Operator-declareddeterministic Discoveredexternal
Identity Which agents exist, with what credentials, mapped to which charter, owned by which named human. 2 artifacts Agent registers on startup with name, charter ref, owner email, instance ID. Heartbeats. Deregister on shutdown. Dead-mans-switch alerts on heartbeat lapse. 1 artifact Operator-maintained registry; agents.yaml in GitOps; ServiceNow CMDB; internal AI inventory tool. Owner-confirmed. Updated on charter signature. 3 artifacts CloudTrail / GCP Audit Logs of SA and IAM principal usage. K8s controller watching SA+RoleBinding by naming pattern. Reverse-lookup from credential fingerprints in Sentinels. Authorization What scope each agent has. What RBAC roles or IAM principals it uses. What could it touch. 1 artifact Agent reports allowed-tools list, MCP allowlist hashes, effective scope on registration. Updates on scope change. 1 artifact Operator records authorized scope in registry, linked to RBAC manifest paths and IAM policy ARNs. 1 artifact K8s RBAC API list, AWS IAM Access Analyzer effective permissions, Kyverno PolicyReports of policies actually applied. Blast radius Worst-case damage if compromised. Environments. Data classes. Revenue or customer impact. 1 artifact Agent reports declared risk tier, damage cap, forbidden operations from its charter. Reports current environment and data class access. 1 artifact Operator records blast-radius profile per agent. Worst-case impact statement (revenue, customer, compliance). 1 artifact Threat-modeling output (MAESTRO Layer 7, MITRE ATLAS, lateral-movement path analysis). Behavioral observation of what the agent has touched. Approval gating Who approved, when last reviewed, when next review due, when retirement fires. 1 artifact Agent reports last charter signature date, next review due, current charter version on registration. Refuses to start if charter is expired. 1 artifact Operator-maintained review calendar. Quarterly attestation. Tracks pending and overdue reviews. 1 artifact Registry of charter files in source control. Last-modified, last-PR-merged. Cross-reference with self-declared and operator-declared. Supply chain Foundation model, MCP servers, base images, tool versions, dependency tree. 1 artifact Agent reports current dependency manifest on registration: foundation model + version, MCP server names + hashes, base image SHA, lockfile fingerprint. Updates on change. 1 artifact Operator records authorized-dependency manifest from agent charter. Linked to Covenants L2-C5 and L3-C5 allowlists. Version-controlled audit trail. 1 artifact Image-registry pull events, package-manager logs, runtime introspection of loaded models and connected MCP servers, SBOM scanning. Drift between actual and authorized = alert.
Walk a row left to right and ask one question at each layer: if the agent decides to
violate this concern, what stops it here ? All three populated is defense in depth. Only the
in-agent cell populated is an audit finding, because the model can be talked out of it.