Agent Registry
A formal inventory of every AI agent in your organisation. Classify risk, assign operators, track approvals, and generate compliance reports for EU AI Act and other regulatory frameworks.
What It Does
Without a registry, AI agents are invisible. They appear in your audit log when they send events, but nobody knows what they do, who owns them, or what data they access. The registry gives each agent a formal identity.
Every agent that sends events to Wytness is automatically discovered and added to the registry. From there, your team classifies each agent's risk level, documents its purpose, assigns a human operator, and approves it for use. All changes are tracked in an audit trail.
Risk Classification
Each agent is assigned a risk level aligned with EU AI Act Article 6:
| Risk Level | Meaning | Example |
|---|---|---|
| Unclassified | Not yet assessed | Newly discovered agents |
| Minimal | No regulatory obligations | Spam filters, game AI, internal tools |
| Limited | Transparency obligations only | Chatbots, content generators |
| High | Conformity assessment required | Employment decisions, credit scoring, critical infrastructure |
| Prohibited | Banned AI practices | Social scoring, mass biometric surveillance |
Approval Workflow
Each agent moves through a four-stage approval lifecycle:
| Status | Meaning | Who Can Change |
|---|---|---|
| Discovered | Auto-created when agent first sends events | System (automatic) |
| Pending Review | Submitted for review by a team member | Members, Admins, Owners |
| Approved | Cleared for use by an admin or owner | Admins, Owners |
| Deprecated | Marked as no longer active | Admins, Owners |
Approval transitions are enforced: you cannot skip from Discovered straight to Deprecated, and only admins and owners can approve or deprecate agents. Every status change is logged in the agent's audit trail.
Agent Profile
Each agent's profile card includes:
| Field | Purpose |
|---|---|
| Display Name | Human-readable name shown alongside the technical agent ID |
| Description | What the agent does and its scope of operation |
| Intended Use | Documented purpose (EU AI Act Article 11) |
| Risk Classification | EU AI Act risk tier with justification for high-risk agents |
| EU AI Act Category | Annex III high-risk area (e.g. employment, critical infrastructure) |
| Data Classes Accessed | What types of data the agent processes (internal, personal, sensitive, restricted) |
| Assigned Operator | The person responsible for overseeing this agent (EU AI Act Article 13) |
| Approval Status | Current lifecycle stage |
| Version Notes | Change log entry explaining why the profile was updated |
Compliance Dashboard
The Registry page provides a compliance overview at a glance:
| Metric | What It Measures |
|---|---|
| Total Agents | How many agents are registered |
| Classified | Agents with a risk level other than Unclassified |
| Compliance Score | Percentage of agents that are both classified and approved |
| Pending Review | Agents awaiting approval |
Risk distribution and approval status charts show where your agent portfolio stands. Click any agent to view its full profile, timeline, and audit trail.
Registry Export
Export your full agent registry as CSV or JSON for auditors, compliance reports, or internal review. The export includes every profile field: agent ID, risk classification, justification, intended use, data classes, operator, approval status, and approver.
EU AI Act Alignment
| Article | Requirement | Wytness Control |
|---|---|---|
| Art. 6 — Classification | Classify AI systems by risk level | Risk classification with 5 tiers + Annex III categories |
| Art. 11 — Technical Documentation | Document intended purpose, risk assessment, data governance | Agent profile with intended use, risk justification, data classes |
| Art. 13 — Human Oversight | Designate human operators for high-risk systems | Assigned operator field on agent profile |
| Art. 71 — Registration | Register high-risk AI systems | Agent registry with approval workflow and audit trail |
Ready to classify and govern your AI agents?
Start recording