product · registry
Registry
The inventory. Every agent, tool, and session your organisation runs — and seven anomaly rules watching them.
Most teams can name the two engineers who know which agents exist and what they call. Registry makes that knowledge a system: agents, tools, sessions, and permissions, captured by AGT, searchable by the people who answer for them.
the raw material
What an event looks like
After the wrapper tokenises PII and adds the signature envelope, this is what lands on /ingest and what you see in Registry → Events.
The PII: tokens are deterministic within a session — the same email resolves to the same token without ever revealing the value to us.
// Event identity:
// What the agent did:
// Parameters (PII tokenised):
// Integrity proof (3-layer):
behavioural detection
Seven rules. Running on every event.
Sub-second evaluation, deduplicated per rule and agent so one issue doesn't page you thirty times. Custom rules ship Q3 2026.
what's inside
Six views, one inventory.
events
Every tool call and message, searchable, with AGT's policy decision and envelope status.
agents
Last seen, event counts, trust score, key fingerprint, delegation history.
tools
Per-tool risk tier, owner, classification mix, destination breakdown.
sessions
A multi-step run reconstructed end-to-end by AGT trace ID.
permissions
Read-only view of AGT policy state; editing lives in Shield.
anomalies
The seven rules above, with a review queue.
availability
What each tier gets
| Starter | Growth | Business | Enterprise | |
|---|---|---|---|---|
| Events · Agents · Tools · Sessions · Permissions | ✓ | ✓ | ✓ | ✓ |
| Anomaly engine (7 rules) | Full | Full | Full | Full |
| Custom anomaly rules | — | — | API only | API + UI (Q3 2026) |
| Trust score history | 30 days | 90 days | 7 years | Custom |
See every agent. Catch what shouldn't be there.
Starter covers the full inventory and the full seven-rule anomaly engine.