Agent Management
Register, profile, and govern every AI agent in your organization. Track ownership, dependencies, costs, and behavioral health across your entire agent estate.
Where to find it in the app
Dashboard → Agent Registry.
The Agent Registry is the canonical inventory. It opens with a domain tab bar:
- OpenAI — agents using OpenAI / Azure OpenAI models
- Claude — agents using Anthropic models
- Browser Agents — browser-based AI assistants discovered in your fleet
- MCP — agents that operate through the Model Context Protocol gateway
Two additional views sit alongside the domain tabs:
- Resources — datasets, APIs, and integrations that aren't agents themselves
- Explore — graph view of the agent estate
A context header below the tabs shows the governance breakdown for the selected domain (counts of unsanctioned, uncontrolled, governed, quarantined, and a % governed coverage figure), plus a search box and a Status filter (All, Governed, Quarantined, Terminated, Unsanctioned). An Advanced Filters button opens additional filters including Agent Type (Browser Agents, MCP Servers, etc.).
Click any agent row to open the agent detail drawer, which has these tabs:
| Tab | What's here |
|---|---|
| Overview | Profile, ownership, environment, lifecycle status, recent activity |
| Authority & Policy | The agent's authority envelope (autonomy contract). See Authority Envelopes. |
| Instructions | Captured system prompts and instructions; ties to Instruction Intelligence drift events |
| Activity | Session and event timeline for this agent |
| Compliance | Per-agent compliance evidence and verifications |
| Dependencies | Declared and runtime asset usage, including shadow dependencies |
| History | Lifecycle and governance state changes (approvals, quarantines, owner changes) |
Two distinct action surfaces are exposed in the drawer:
- Inline action buttons under the agent header — these are the lifecycle actions: Approve / Deny (for unsanctioned agents), Quarantine, Terminate, and Reactivate (shown based on current status).
- ⋮ Actions menu — exports and identity utilities: Export PDF report, Export JSON, Download DID document, Export AIBOM (CycloneDX), Export AIBOM (SPDX 3.0), Check trust status, Open identity record, Copy agent ID, Copy DID.
How agents get into the Registry
Every AI agent that sends traffic through Rivaro gets an agent identity — a persistent record with ownership metadata, behavioral metrics, trust score, and lifecycle status. Agents land in the Registry two ways:
- Explicit registration — created through the UI or registered programmatically when an integration is wired (see Getting Started).
- Discovery — surfaced automatically by traffic the proxy sees, by code scans, or by IAM analysis. Discovered agents start in
PENDING_APPROVALand appear in the Registry under the Unsanctioned status filter (and are shown with the orangeUNSANCTIONEDbadge on the agent card).
Agent identity
Each agent record has these fields, all visible on the Overview tab of the detail drawer.
Core identity
| Field | Description |
|---|---|
agentId | Unique identifier in the format ag_<16chars> |
agentName | Internal name (e.g. customer-support-bot) |
displayName | Human-readable name shown in the dashboard |
description | What this agent does |
adapterType | Provider the agent uses: gpt-4, claude-3, azure-openai, etc. |
appContextId | Linked AppContext (provider routing config) |
Ownership & accountability
| Field | Description |
|---|---|
ownerEmail | Email of the person responsible for this agent |
ownerName | Owner's full name |
businessUnit | Department: Finance, Sales, Engineering, Legal, HR, etc. |
environment | DEVELOPMENT, STAGING, or PRODUCTION |
agentType | BROWSER, INTERNAL_CUSTOMER_FACING, INTERNAL_EMPLOYEE_FACING, or THIRD_PARTY |
modelName | The LLM model used (GPT-4, Claude-3, etc.) |
Owner and AppContext are shown on the Overview tab. Changing ownership or rebinding to a different AppContext is done through the API or via your IdP-driven owner sync.
Identity strength
Identity strength reflects how well-verified an agent is. It caps the trust an agent can earn and serves as a zero-trust signal: a stronger identity is a precondition for higher autonomy, not a consequence of good behavior.
| Strength | Criteria |
|---|---|
| BASIC | Unknown or unresolvable — seen in traffic but not registered |
| STANDARD | Registered agent with no approved assets |
| VERIFIED | Registered and has at least one approved asset |
| STRONG | Approved asset + bound to a verified user identity |
Identity strength is available through the API and feeds the trust score engine. See Actor Governance.
Status & metrics
| Field | Description |
|---|---|
status | PENDING_APPROVAL, ACTIVE, QUARANTINED, or TERMINATED |
trustScore | 0–100. Starts at 0 (zero trust). See Actor Governance |
totalSessions | Lifetime session count |
totalViolations | Lifetime policy violation count |
totalIncidents | Lifetime incident count |
firstSeenAt | When this agent first sent traffic |
lastSeenAt | Most recent activity timestamp |
lastViolationAt | Most recent violation timestamp |
Status changes are governance events and are recorded in the History tab.
Dependencies and blast radius
Open an agent and switch to the Dependencies tab to see what the agent actually uses. Rivaro tracks both declared dependencies (code references, IAM policies) and runtime dependencies (live traffic observed through the proxy), so you can see what each agent is supposed to depend on versus what it actually does.
Observation types
| Type | Confidence | How detected |
|---|---|---|
RUNTIME_USAGE | CONFIRMED | Agent sent live traffic to this asset through the Rivaro proxy |
CODE_REFERENCE | INFERRED | Found as an import or API call in source code scan |
IAM_POLICY | INFERRED | Service account has an IAM permission to access this asset |
DISCOVERED | SUSPECTED | Found by a discovery scan in the same environment |
Per-dependency metrics
Each dependency row shows usage count, cost attribution, last runtime call, and a first-seen / last-seen window so you can spot dormant dependencies and unexpected new ones.
Shadow dependencies
A shadow dependency is an asset the agent calls at runtime but that isn't declared in code or IAM. The Dependencies tab surfaces these in a dedicated section. Example: an agent that starts calling a new API endpoint not referenced in its codebase — the dependency shows up in runtime observations but has no code reference. Investigate shadow dependencies before they become incidents.
Blast radius
For any asset, Rivaro can answer: if this asset goes down or is revoked, which agents break? From an asset's detail view, open Blast radius to see the affected agent count, the list of affected agents with environment and owner, and a composite impact score. Use this before decommissioning an asset, rotating credentials, or blocking a discovered endpoint.
Orphaned agents
An agent is orphaned when it has no assigned owner. Orphaned agents are a governance gap — violations have no responsible party and incidents have no escalation path.
The Command Center dashboard surfaces an orphaned-agent count in the actors-at-risk panel so this stays visible. To investigate, click through from the Command Center actor-risk panel into the agents involved.
Owner assignment is driven by your IdP sync or through the API.
Lifecycle
Agents follow this lifecycle:
- Discovered — first seen in proxy traffic or via discovery scan, status:
PENDING_APPROVAL - Approved — administrator approves the agent, status:
ACTIVE, initial trust granted - Active — agent sends traffic, trust score builds or degrades based on behavior
- Quarantined — risk threshold exceeded, all requests blocked pending review
- Terminated — permanently blocked; requires admin reactivation to restore
To approve a pending agent, set the Status filter to Unsanctioned, open the agent, and click Approve (or Deny) in the inline action buttons under the agent header. Quarantine, Terminate, and Reactivate also appear as inline buttons in that same area, gated by the agent's current status. Quarantine prompts for a reason; reactivate and terminate confirm before taking effect.
The same lifecycle buttons (Approve / Deny / Quarantine / Terminate / Reactivate) are also available directly on each agent card in the Registry grid, so you can act without opening the detail drawer.
See Actor Governance for the full trust score and escalation mechanics.
Exports
Per-agent exports live in the detail drawer's ⋮ Actions menu:
- Export PDF report — Agent-on-a-Page summary as a PDF, for share-out to auditors or stakeholders.
- Export JSON — Same summary as structured JSON for downstream tooling.
- Download DID document — W3C DID document for the agent. See Agent DID.
- Export AIBOM (CycloneDX) — Machine-readable bill of materials in CycloneDX (broad tooling support). See AI BOM.
- Export AIBOM (SPDX 3.0) — Same BOM in SPDX 3.0 (government / EU AI Act tooling).
The same menu also exposes identity utilities: Check trust status, Open identity record, Copy agent ID, and Copy DID.
Next steps
- Actor Governance — Trust scores, quarantine, and termination mechanics
- Authority Envelopes — The autonomy contract per agent
- Sessions — What gets recorded per agent session
- Discovery & Shadow AI — How agents are discovered automatically
- Asset Management — The assets agents depend on