Free browser tool
AI Agent Inventory Tool
Use an AI agent inventory tool to record deployments, owners, tools, permissions and data, then download a local CSV for review.
AI agent inventory tool for manual records
This AI agent inventory tool turns a JSON array or local JSON file you supply into reviewable records. Use it as an AI inventory tool after your team assembles its source list; it does not discover agents or scan accounts. The generated CSV can serve as an AI agent inventory CSV template for your own records, but this page does not provide a separate blank workbook. Paste a JSON array or read a local JSON file. Every field must be a string. Use an empty string for missing owner, purpose, platform, tools, permissions or review date. Use unknown for data class, autonomy or environment. Store references to credentials, never credential values.
Fields and allowed values
Record agent, owner, purpose, platform, environment, tools, data_class, permissions, autonomy and review_date. Environment is development, test, production or unknown. Data class is public, internal, confidential, restricted or unknown. Autonomy is read, draft, write, approve or unknown. Review dates use YYYY-MM-DD. Agent names must be unique, ignoring case.
Published triage rules
Restricted data, approve autonomy, or confidential data with write autonomy triggers high-priority review. Other write actions, confidential data, or missing context trigger needs review. Remaining records receive routine review. A review at least 90 days old adds a follow-up. These are transparent editorial triage rules, not NIST scores, EU AI Act classifications or proof of safety.
Worked example
The CRM summary assistant drafts from confidential data: needs review even when all fields are complete. The invoice posting agent handles restricted data, has no owner, and was last reviewed in June: high-priority review with ownership and stale-review gaps. The research sandbox uses public data and read actions: routine review, which still needs verification by its owner.
CSV, PDF and next steps
Export the CSV to an approved spreadsheet and use the browser’s Print / save PDF option for a summary. The export preserves every field and the triage reasons. Keep the raw inventory, tool/configuration versions, source evidence and review decisions separately. This tool cannot discover agents, inspect your network, access a cloud account or determine whether the input list is complete.
Frequently asked questions
Does the builder discover agents automatically?
No. Paste a JSON array or choose a local JSON file. The tool does not inspect cloud accounts, identity providers, networks, repositories or running endpoints, so the owner must confirm that the supplied list is complete.
Which fields are required?
Each record needs ten string fields: agent, owner, purpose, platform, environment, tools, data_class, permissions, autonomy and review_date. The agent name cannot be blank; use the allowed enum values or unknown where the field is an enum.
What does the triage label mean?
It routes attention from the submitted values using the published rules. It is not an EU AI Act class, NIST score, legal conclusion, safety test or approval to deploy.
Does the export include secrets or connect to a spreadsheet?
The CSV contains the input fields and review_age_days, triage, gaps and as_of. Do not enter credentials or secret values. The browser downloads the CSV locally; import it into your own approved spreadsheet if useful. The site does not create a Google Sheet or an Excel workbook.
Continue with the AI inventory template, AI agent inventory template, or shadow AI discovery guide.
Primary sources and review
- NIST AI Risk Management Framework: voluntary risk-management context
- ISO/IEC 42001:2023: AI management system overview
- Regulation (EU) 2024/1689 (Artificial Intelligence Act): official EUR-Lex text, including Articles 6, 49 and 71
- Model Context Protocol: official specification
- OWASP LLM06:2025: permissions, functionality and autonomy
Published by Agent Inventory Tool. Updated . Sources are linked on this page. Outputs do not certify compliance.