One source of truth for every agent.
An AI agent registry is the system of record for every agent that can act in your systems. In Lutril, each agent gets a record: a named owner, its purpose, the integrations and scopes it holds, an expiry date, a risk score, and its activity. Govern agents with the same lifecycle you already use for employees.
- Owner & scopes
- No anonymous agents; each one has an accountable owner.
- Credential rotation
- Rotate or expire an agent's keys on a schedule.
- Access reviews
- Include agents in the same campaigns as human accounts.
- One-click offboard
- Revoke everything an agent can reach, instantly.
| Agent | Scopes | Status | ||
|---|---|---|---|---|
crm-sync-agent clde_7fRxP2 | Claude | hubspot.read | 2m | active |
ticket-triage-agent gpt_2aLm91 | GPT-5 | zendesk.rw | 14m | active |
billing-ops-agent clde_9kPv03 | Claude | stripe.read | 1h | paused |
docs-indexer-agent gmni_4xQ2 | Gemini | drive.read | 3d | revoked |
The agent lifecycle, end to end.
An agent is an identity. Governing it the way you govern an employee account closes the gap between what your agents can reach and what anyone can see.
Register
Onboard an agent with an owner, its model, and a scoped role drawn from the same library your employees use.
Rotate
Schedule credential rotation and short-lived tokens so a leaked key has a small blast radius.
Review
Surface idle or over-scoped agents in access reviews and tighten them with a decision that executes.
Offboard
When a project ends, retire the agent and revoke every grant across your SaaS in one action.
Questions buyers ask
What is an AI agent registry?
An AI agent registry is an inventory of the AI agents that can act in your company's systems, with who owns each one, what it can reach and whether it is still allowed to run. It plays the role for agents that your identity provider's directory plays for employees. Without one, agents run on API keys nobody tracks, and neither offboarding nor an audit can find them.
What does an agent record hold?
In Lutril: a name, a named owner, a purpose and tags; a state (draft, pending approval, active, suspended or revoked); an identity mode, acting as itself or on behalf of a user; an expiry date; a risk score from 0 to 100; its bindings, meaning each integration it can reach, read or write, optionally narrowed to named tools; its credentials; its tool activity over the last 30 days; and an append-only history of every state change. An agent found by code scanning also links back to its repository and to the framework, models and tools declared in its code.
How do agents get into the registry?
Two ways. You register the agent directly, with a mandatory owner and an expiry date no more than 90 days out, and receive a single MCP token for it. Or code scanning finds the agent in GitHub or GitLab and an admin promotes the finding into the registry, with an owner suggested from commit authors. Either way, the agent only sees the tools of the integrations it is bound to.
How is an agent's risk score calculated?
From its bindings: which integrations it can reach, whether it can read or write, how many it holds, and the role of its owner. The score is recalculated every time a binding changes. For an agent found in code, Lutril also scores the capabilities declared in source, such as side-effecting tools, triggers, MCP reach and credential patterns, and the record keeps the higher of the two.
What happens to an agent when its owner leaves or changes teams?
You reassign it. Lutril re-checks least privilege against the new owner, removes any binding the new owner is not entitled to, and logs the change. If the owner's account is deleted in Lutril, every agent they own is revoked with that reason recorded. A suspended, revoked or expired agent is refused on its next tool call.
How do you rotate an AI agent's credentials?
Rotation issues a new secret, shown once. The previous secret keeps working for a 24-hour grace period so the agent can be redeployed, and stops once the rotation is confirmed or the grace period ends. Lutril stores only a keyed hash of each secret, never a recoverable copy.