Agent Register
For the security manager, SOC lead or IT risk lead who is about to be asked for it

Paste the AI tools your teams use. Get back what each one can act on, and who owns it.

Every agent, copilot and integration classified: what it can do on its own, what it reaches, whether a human is in the loop, whether your data leaves the tenant, and the controls ISO/IEC 42001 and the EU AI Act expect. Ten entries free, no account.

Paste your own listRuns in your browser. Nothing you paste leaves it until you choose to save.
An IT professional standing with crossed arms in a server room, smiling
Specimen, from the sample register
ToolActs onHuman in loopStanding
Zapierexecutes autonomouslynocontrol
Otter.aiexecutes autonomouslynocontrol
Microsoft 365 Copilotdrafts for a humanyesclear
OpenAI APIexecutes autonomouslynocontrol
Gongread onlyyesclear
Acme Insight Assistantunknownunknownunregistered
Six of 41 rows. Run the sample below to see all of them, with owner, reach and the controls.
One line per tool, agent or integration: Name, or Name, Department, or Name, Department, what it is connected to. A CSV or TSV export with a header row works, and so does the app list from a Google Workspace or Microsoft 365 admin export.
Classification runs in your browser against a published dictionary. Nothing is sent anywhere until you choose to save.
01

Paste the list you already have

The names are enough. A department and whatever the person who compiled the list knew ("connected to Salesforce", "personal account", "owner: Dana") sharpen the answer. Every name is matched against a published dictionary of agents, copilots, connectors and model APIs. A name that matches nothing is marked unregistered with the four questions to answer, never guessed.

02

Read the four answers per tool

What it can act on: read only, drafts for a human, executes with approval, or executes autonomously. What it reaches by default. Whether a human is in the loop. Whether your data leaves the tenant. Then the owner, and one standing per row: clear, control, or unregistered.

03

Take the controls to the review

Every finding maps to the controls ISO/IEC 42001 and the EU AI Act expect, with the requirement text, the artefacts an auditor accepts and the gap seen most often. The register is the inventory; the findings are the work list; the controls are what you show the assessor.

Why a register and not an AI security platform

The funded tools want to sit in your network and discover AI traffic before they tell you anything. Your teams can already name what they use, and an admin export of OAuth grants lists the rest. What that list lacks is the column that says what each tool can do on its own and who answers for it. That is the column this builds, in your browser, from the names you already have, with no agent, no proxy and no account.

The dictionary is ours and is published in full: every agent, copilot and integration it recognises, with what each one can act on and reach. Nothing is generated on the fly.