Asset Management
The central registry of every AI asset in your organization — discovered, approved, and actively governed. Assets are the foundation of agent dependency tracking, blast radius analysis, and access control.
Where to find it in the app
Dashboard → Administration → AI Estate → DISCOVERY → Attack Surface Monitors → Discovered Assets.
To get there:
- Click Administration in the main sidebar (opens the Administration view in a new tab).
- Open AI Estate in the Administration sidebar.
- Switch the stage tab at the top to DISCOVERY.
- Open the Attack Surface Monitors sub-tab and select Discovered Assets.
The Discovered Assets view is your asset registry. Filter by status = PENDING_APPROVAL to see your approval queue, or by status, category, and risk level to find assets needing remediation.
What is an asset?
An asset is any AI-related resource in your environment: an API endpoint, a model, a training data repository, a container image, a cloud service, or a service account with AI permissions. Assets are discovered automatically via discovery channels or added manually.
Asset fields
The asset detail panel shows these fields. Sortable / filterable columns in the Discovered Assets table are marked.
Core identification
| Field | Description |
|---|---|
id | Unique asset identifier |
name | Asset name (e.g. openai-api-prod, customer-data-vector-db) |
description | What this asset is and what it's used for |
externalId | Fingerprint used for cross-channel deduplication |
discoveryChannelId | Which channel first found this asset |
Classification
| Field | Description |
|---|---|
assetCategory | Broad category: AI_SERVICE, AI_MODEL, DATA_STORAGE, ML_PIPELINE, SOURCE_CODE, CONTAINER, IDENTITY_ACCESS, USAGE_PATTERN |
assetType | Specific type — 60+ types including ML_ENDPOINT, AI_BOT, MCP_SERVER_INSTANCE, AI_REPOSITORY, etc. |
metadata | Platform-specific details: endpoint URL, repository owner, cloud region, container registry, etc. |
Status & risk
| Field | Description |
|---|---|
status | Current lifecycle status (see below) |
riskLevel | NONE, LOW, MEDIUM, HIGH, or CRITICAL — computed from findings |
activeRiskCount | Number of open, unresolved findings against this asset |
Lifecycle timestamps
| Field | Description |
|---|---|
firstSeenAt | When the asset was first discovered |
lastSeenAt | Most recent confirmation the asset still exists |
lastScannedAt | Most recent security scan |
Asset status lifecycle
| Status | Meaning | Transitions to |
|---|---|---|
PENDING_APPROVAL | Discovered, awaiting review | APPROVED, BLOCKED |
APPROVED | Reviewed and cleared for use | ACTIVE, PROMOTED, REMOVED, ARCHIVED |
ACTIVE | Approved and in active use by governed agents | REMOVED, ARCHIVED |
BLOCKED | Denied — no agent may access this asset | — |
PROMOTED | Graduated to a fully governed entity | ARCHIVED |
REMOVED | No longer detected in the environment | ARCHIVED |
ARCHIVED | Retained for audit history only | — |
UNKNOWN | Status could not be determined | Any |
Approving and denying assets
In Discovered Assets, set the status filter to PENDING_APPROVAL to see assets awaiting review. Click any asset row to open the detail panel.
The detail panel shows the asset's risk score, open findings, source channels (so you can see which scanners detected it and how), and recent activity. Review this before deciding:
- Approve — clears the asset for use by governed agents. Add an optional review note.
- Deny — blocks the asset. No governed agent may access it. Add a review note explaining why.
Both actions move the asset out of the approval queue and become part of the asset's audit trail.
Promoting assets
An approved asset can be promoted — converted into a fully governed entity with an AppContext, detection key, and active enforcement. This is how shadow infrastructure becomes official, monitored infrastructure without disruption.
Open an approved asset and use the Promote action. Choose a target type:
| Type | What it becomes |
|---|---|
| AGENT | A registered agent identity — gets a trust score, ownership fields, and appears in agent governance |
| DATA_SOURCE | A governed data source with access policy enforcement |
| MODEL | An approved model in an AppContext's allowed model list |
| INTEGRATION | A governed third-party integration |
| SERVICE | An approved AI service endpoint with active enforcement |
After promotion, the asset gains a presence in the Agent Registry (for AGENT) or the AppContext list (for the others) — and you can configure policy on it from Policies & Authority.
Risk scoring
Each asset has a riskLevel computed from its open findings. Risk levels are: NONE, LOW, MEDIUM, HIGH, CRITICAL. An asset with a CRITICAL finding (e.g. exposed credentials in its source code) will be riskLevel: CRITICAL until that finding is resolved.
The approval workflow surfaces the risk score prominently in the detail panel so reviewers can make informed decisions. High-risk assets should either be blocked or remediated before approval.
Stale asset detection
Assets that haven't been confirmed by any discovery channel for an extended period are flagged as stale in the Discovered Assets table. Stale assets that are still in APPROVED or ACTIVE status may represent decommissioned infrastructure that hasn't been cleaned up from Rivaro — or legitimate assets whose discovery channel isn't scanning frequently enough. Filter by stale status to triage.
Relationships and blast radius
Assets don't exist in isolation — they form a dependency graph with the agents that use them. From an asset's detail panel, open Blast radius to see:
- Affected agent count — how many agents currently use this asset
- List of affected agents — with their environment, owner, and last usage timestamp
- Impact score — composite severity score
Use this before decommissioning an asset, rotating credentials, or blocking a discovered endpoint.
The same dependency graph powers:
- Access surface mapping — per agent, what categories of assets can it reach
- Shadow dependency detection — agents using assets not declared in code
- Cost attribution — total spend per asset across all agents that use it
See Agent Management for the agent-side view.
Adding an asset manually
To register an asset Rivaro hasn't discovered automatically, use the Add asset action in the Discovered Assets toolbar. Provide name, category, type, and any platform-specific metadata. The asset lands in PENDING_APPROVAL like any discovered asset.
Next steps
- Discovery & Shadow AI — How assets are found and what channels are supported
- Agent Management — Agent dependency graphs and blast radius