# One source of truth for every agent.

> Register each AI agent with an owner, model, and scopes. Rotate credentials, review access, and offboard an agent the same way you would an employee.

Source: https://www.lutril.com/ai-governance/agent-registry

---

Every AI agent gets a record: an owner, the model it runs on, the scopes it holds, and its activity. Govern agents with the same lifecycle you already use for employees.

- Owner & scopes
- Credential rotation
- One-click offboard

- **Owner & scopes** No anonymous agents; each one has an accountable owner.
- **Credential rotation** Rotate or expire an agent's keys on a schedule.
- **Access reviews** Include agents in the same campaigns as human accounts.
- **One-click offboard** Revoke everything an agent can reach, instantly.

## The agent lifecycle, end to end.

An agent is an identity. Governing it the way you govern an employee account closes the gap between what your agents can reach and what anyone can see.

1. **Register** Onboard an agent with an owner, its model, and a scoped role drawn from the same library your employees use.
2. **Rotate** Schedule credential rotation and short-lived tokens so a leaked key has a small blast radius.
3. **Review** Surface idle or over-scoped agents in access reviews and tighten them with a decision that executes.
4. **Offboard** When a project ends, retire the agent and revoke every grant across your SaaS in one action.
