Control objective
An agent and tool inventory connects each deployed agent to an owner, approved purpose, human or workload authority, host, model, prompt or policy set, memory, MCP client and servers, tools, credentials, reachable targets, versions, provenance, and retirement state.
Required relationships
Record immutable artifact or configuration identity where possible. Include tool schema digest, transport, server identity, deployment environment, audience, credential source, high-impact actions, approval rule, evidence source, and containment owner.
Reconciliation
Compare declared inventory with running processes, network connections, MCP discovery, credential issuance, gateway records, target actions, and deployment state. Alert on unknown agents, servers, tools, versions, credentials, or targets.
Failure and residual risk
Self-reported agent names are not identity. Dynamic tools and models can change between scans. An approved component can be compromised after inventory. Dormant queues and credentials can outlive a retired agent.
Pomerium boundary
Pomerium can provide evidence for routed MCP servers, methods, tools, and identities that it observes. It cannot inventory local stdio tools, model providers, host processes, prompts, memory, or bypass traffic. Operators must join several control and target sources.
Evaluation checklist
- Does every agent have an owner, purpose, identity, host, version, and retirement state?
- Are every server, tool, credential, target, and high-impact action linked?
- Is provenance tied to immutable artifacts or reviewed configuration?
- Can runtime and target evidence find undeclared components or actions?
- Does retirement remove connections, credentials, queues, memory, routes, and trust?
