Why agents differ from models
A model is one component; an agent deployment also has a purpose, owner, runtime, connected tools, permissions and an allowed action level. Two workflows using the same model can need separate records when their data, access, human review or business owner differs. This manual template describes deployment context, not model weights or a runtime registry.
Required fields
The site's builder accepts ten string inputs in a JSON array. The agent name must be present and unique. Descriptive fields may be blank when unknown; use the specified unknown value for enum fields.
| Input field | Record | Allowed values / behavior |
|---|---|---|
agent | Unique deployment name | Required; case-insensitive uniqueness check |
owner | Accountable person or team | Blank is allowed; output gap is Record owner |
purpose | Task and intended use | Free text; blank is flagged |
platform | Runtime or hosting platform | Free text; blank is flagged |
environment | Deployment stage | development, test, production, unknown |
tools | Tools and integrations the agent can call | Free text; blank is flagged |
data_class | Data category | public, internal, confidential, restricted, unknown |
permissions | Granted scope and permitted operations | Free text; blank is flagged |
autonomy | Allowed action level | read, draft, write, approve, unknown |
review_date | Last review date | YYYY-MM-DD; blank schedules a first-review gap |
The CSV adds review_age_days, triage, gaps, and as_of. There is no dedicated model ID, version, evidence link, review cadence, risk-register ID, or credential-reference column. Maintain those in a controlled system as appropriate; do not imply that the builder records fields it does not accept.
Tool and credential fields
List callable services in tools and describe scopes or operations in permissions, such as “Invoice API; Supplier lookup” and “Invoice write; Supplier read.” The schema has no separate credential field. Never paste a password, token, key or secret into the JSON or CSV. Keep secrets in an approved secrets manager and maintain any safe reference in your organization's controlled documentation without exposing secret values.
Inventory capability and permission separately: a tool name says what may be connected; the permission description says what the identity can do. Ask the platform owner to verify both against current configuration. The builder does not inspect endpoints or prove that the written scope matches the live grant.
Download
Load the builder's synthetic JSON example or read a local JSON file, run the review, and download the CSV. The CSV can be imported into Excel or Google Sheets by the user; the website does not generate an .xlsx workbook or create/connect to a Google Sheet. Browser print/save-to-PDF creates a separate printable summary through the browser. The tool is manual and does not discover agents or populate a live registry.
Example
Illustrative synthetic record and output for an as-of date of 2026-10-06:
| agent | owner | purpose | platform | environment | tools | data_class | permissions | autonomy | review_date | review_age_days | triage | gaps | as_of |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Invoice posting agent | Demo finance operations | Post invoices after validation | Example local runtime | production | Invoice API; Supplier lookup | restricted | Invoice write; Supplier read | write | 2026-06-01 | 127 | high-priority review | Review is at least 90 days old; check your policy | 2026-10-06 |
The labels and data are fictional. Under the published rule, restricted data triggers high-priority review; a review date at least 90 days old adds the displayed follow-up. This routing output is not a risk score, an approval, or a compliance conclusion.
Maintenance routine
Ask the owner and platform operator to confirm purpose, tools, permissions, data class and environment when a deployment changes. Update review_date after review and retain prior exports and decision evidence in your approved records system. The builder does not maintain history or set a mandatory cadence. NIST AI RMF offers voluntary context-documentation guidance; this page makes no ISO/IEC 42001 clause mapping. EU AI Act Article 49 registration, where applicable, is a separate legal process: a CSV is not an EU database entry.
References: NIST AI RMF Map Playbook; NIST AI RMF status and voluntary-use overview; ISO/IEC 42001 public overview; EUR-Lex consolidated AI Act.
Continue with the AI agent inventory builder, the AI inventory template, or the shadow AI discovery guide.