Skip to main content

Agent Management

Register, profile, and govern every AI agent in your organization. Track ownership, dependencies, costs, and behavioral health across your entire agent estate.

Where to find it in the app​

Dashboard → Agent Registry.

The Agent Registry is the canonical inventory. It opens with a domain tab bar:

  • OpenAI — agents using OpenAI / Azure OpenAI models
  • Claude — agents using Anthropic models
  • Browser Agents — browser-based AI assistants discovered in your fleet
  • MCP — agents that operate through the Model Context Protocol gateway

Two additional views sit alongside the domain tabs:

  • Resources — datasets, APIs, and integrations that aren't agents themselves
  • Explore — graph view of the agent estate

A context header below the tabs shows the governance breakdown for the selected domain (counts of unsanctioned, uncontrolled, governed, quarantined, and a % governed coverage figure), plus a search box and a Status filter (All, Governed, Quarantined, Terminated, Unsanctioned). An Advanced Filters button opens additional filters including Agent Type (Browser Agents, MCP Servers, etc.).

Click any agent row to open the agent detail drawer, which has these tabs:

TabWhat's here
OverviewProfile, ownership, environment, lifecycle status, recent activity
Authority & PolicyThe agent's authority envelope (autonomy contract). See Authority Envelopes.
InstructionsCaptured system prompts and instructions; ties to Instruction Intelligence drift events
ActivitySession and event timeline for this agent
CompliancePer-agent compliance evidence and verifications
DependenciesDeclared and runtime asset usage, including shadow dependencies
HistoryLifecycle and governance state changes (approvals, quarantines, owner changes)

Two distinct action surfaces are exposed in the drawer:

  • Inline action buttons under the agent header — these are the lifecycle actions: Approve / Deny (for unsanctioned agents), Quarantine, Terminate, and Reactivate (shown based on current status).
  • ⋮ Actions menu — exports and identity utilities: Export PDF report, Export JSON, Download DID document, Export AIBOM (CycloneDX), Export AIBOM (SPDX 3.0), Check trust status, Open identity record, Copy agent ID, Copy DID.

How agents get into the Registry​

Every AI agent that sends traffic through Rivaro gets an agent identity — a persistent record with ownership metadata, behavioral metrics, trust score, and lifecycle status. Agents land in the Registry two ways:

  • Explicit registration — created through the UI or registered programmatically when an integration is wired (see Getting Started).
  • Discovery — surfaced automatically by traffic the proxy sees, by code scans, or by IAM analysis. Discovered agents start in PENDING_APPROVAL and appear in the Registry under the Unsanctioned status filter (and are shown with the orange UNSANCTIONED badge on the agent card).

Agent identity​

Each agent record has these fields, all visible on the Overview tab of the detail drawer.

Core identity​

FieldDescription
agentIdUnique identifier in the format ag_<16chars>
agentNameInternal name (e.g. customer-support-bot)
displayNameHuman-readable name shown in the dashboard
descriptionWhat this agent does
adapterTypeProvider the agent uses: gpt-4, claude-3, azure-openai, etc.
appContextIdLinked AppContext (provider routing config)

Ownership & accountability​

FieldDescription
ownerEmailEmail of the person responsible for this agent
ownerNameOwner's full name
businessUnitDepartment: Finance, Sales, Engineering, Legal, HR, etc.
environmentDEVELOPMENT, STAGING, or PRODUCTION
agentTypeBROWSER, INTERNAL_CUSTOMER_FACING, INTERNAL_EMPLOYEE_FACING, or THIRD_PARTY
modelNameThe LLM model used (GPT-4, Claude-3, etc.)

Owner and AppContext are shown on the Overview tab. Changing ownership or rebinding to a different AppContext is done through the API or via your IdP-driven owner sync.

Identity strength​

Identity strength reflects how well-verified an agent is. It caps the trust an agent can earn and serves as a zero-trust signal: a stronger identity is a precondition for higher autonomy, not a consequence of good behavior.

StrengthCriteria
BASICUnknown or unresolvable — seen in traffic but not registered
STANDARDRegistered agent with no approved assets
VERIFIEDRegistered and has at least one approved asset
STRONGApproved asset + bound to a verified user identity

Identity strength is available through the API and feeds the trust score engine. See Actor Governance.

Status & metrics​

FieldDescription
statusPENDING_APPROVAL, ACTIVE, QUARANTINED, or TERMINATED
trustScore0–100. Starts at 0 (zero trust). See Actor Governance
totalSessionsLifetime session count
totalViolationsLifetime policy violation count
totalIncidentsLifetime incident count
firstSeenAtWhen this agent first sent traffic
lastSeenAtMost recent activity timestamp
lastViolationAtMost recent violation timestamp

Status changes are governance events and are recorded in the History tab.

Dependencies and blast radius​

Open an agent and switch to the Dependencies tab to see what the agent actually uses. Rivaro tracks both declared dependencies (code references, IAM policies) and runtime dependencies (live traffic observed through the proxy), so you can see what each agent is supposed to depend on versus what it actually does.

Observation types​

TypeConfidenceHow detected
RUNTIME_USAGECONFIRMEDAgent sent live traffic to this asset through the Rivaro proxy
CODE_REFERENCEINFERREDFound as an import or API call in source code scan
IAM_POLICYINFERREDService account has an IAM permission to access this asset
DISCOVEREDSUSPECTEDFound by a discovery scan in the same environment

Per-dependency metrics​

Each dependency row shows usage count, cost attribution, last runtime call, and a first-seen / last-seen window so you can spot dormant dependencies and unexpected new ones.

Shadow dependencies​

A shadow dependency is an asset the agent calls at runtime but that isn't declared in code or IAM. The Dependencies tab surfaces these in a dedicated section. Example: an agent that starts calling a new API endpoint not referenced in its codebase — the dependency shows up in runtime observations but has no code reference. Investigate shadow dependencies before they become incidents.

Blast radius​

For any asset, Rivaro can answer: if this asset goes down or is revoked, which agents break? From an asset's detail view, open Blast radius to see the affected agent count, the list of affected agents with environment and owner, and a composite impact score. Use this before decommissioning an asset, rotating credentials, or blocking a discovered endpoint.

Orphaned agents​

An agent is orphaned when it has no assigned owner. Orphaned agents are a governance gap — violations have no responsible party and incidents have no escalation path.

The Command Center dashboard surfaces an orphaned-agent count in the actors-at-risk panel so this stays visible. To investigate, click through from the Command Center actor-risk panel into the agents involved.

Owner assignment is driven by your IdP sync or through the API.

Lifecycle​

Agents follow this lifecycle:

  1. Discovered — first seen in proxy traffic or via discovery scan, status: PENDING_APPROVAL
  2. Approved — administrator approves the agent, status: ACTIVE, initial trust granted
  3. Active — agent sends traffic, trust score builds or degrades based on behavior
  4. Quarantined — risk threshold exceeded, all requests blocked pending review
  5. Terminated — permanently blocked; requires admin reactivation to restore

To approve a pending agent, set the Status filter to Unsanctioned, open the agent, and click Approve (or Deny) in the inline action buttons under the agent header. Quarantine, Terminate, and Reactivate also appear as inline buttons in that same area, gated by the agent's current status. Quarantine prompts for a reason; reactivate and terminate confirm before taking effect.

The same lifecycle buttons (Approve / Deny / Quarantine / Terminate / Reactivate) are also available directly on each agent card in the Registry grid, so you can act without opening the detail drawer.

See Actor Governance for the full trust score and escalation mechanics.

Exports​

Per-agent exports live in the detail drawer's ⋮ Actions menu:

  • Export PDF report — Agent-on-a-Page summary as a PDF, for share-out to auditors or stakeholders.
  • Export JSON — Same summary as structured JSON for downstream tooling.
  • Download DID document — W3C DID document for the agent. See Agent DID.
  • Export AIBOM (CycloneDX) — Machine-readable bill of materials in CycloneDX (broad tooling support). See AI BOM.
  • Export AIBOM (SPDX 3.0) — Same BOM in SPDX 3.0 (government / EU AI Act tooling).

The same menu also exposes identity utilities: Check trust status, Open identity record, Copy agent ID, and Copy DID.

Next steps​