Agent Inventory Tool

Free browser tool

AI Inventory Template

Use an AI inventory template to record systems, use cases, models, owners, data and review evidence without implying approval or completeness.

An AI inventory template should make the system boundary, business use and evidence source clear. An AI system inventory template can identify a model or deployed application; an AI use case inventory template records how it is used in a workflow. An AI register template links the two through stable identifiers rather than collapsing separate uses into one row.

What to record per AI system

Use one row for each AI deployment or workflow whose purpose, owner, data, environment or permitted actions need separate review. A shared model can support several systems, so the model name alone is not a reliable inventory unit. This page describes the fields in the site's manual agent builder; it is not a universal data schema for every AI system.

Template fields

The builder accepts a JSON array with these ten string inputs. Descriptive values may be blank when unknown; the agent identifier must be present. The three enum fields have the allowed values shown here.

Input fieldWhat to recordAccepted values / notes
agentUnique deployment or workflow nameRequired and unique, ignoring case
ownerAccountable ownerUse blank when unknown; the builder flags the gap
purposeIntended task and useUse blank when unknown
platformHost, product or runtimeUse blank when unknown
environmentDeployment stagedevelopment, test, production, or unknown
toolsConnected tools or integrationsUse blank when unknown; this is free text, not a discovered connector list
data_classData categorypublic, internal, confidential, restricted, or unknown
permissionsGranted scopes and allowed operationsUse blank when unknown; do not enter secret values
autonomyAllowed action levelread, draft, write, approve, or unknown
review_dateLast review dateYYYY-MM-DD; blank schedules a first-review gap

The CSV adds four calculated columns: review_age_days, triage, gaps, and as_of. The triage values are published editorial routing rules, not risk scores or legal classifications. The CSV does not include separate fields for model ID, evidence link, risk-register ID, credential reference, review owner or review cadence; maintain those in your controlled register if needed.

Download

Open the builder, load its synthetic JSON example or read your own local JSON file, review the output, and choose Export inventory CSV. Import that CSV into Excel, Google Sheets or another approved spreadsheet yourself. The site does not generate an Excel workbook, create a Google Sheet, or connect to either service. Browser print/save-to-PDF is a separate summary option; it is not a generated spreadsheet or a legal register.

Filled-in example

Illustrative synthetic record, not a real deployment or system-discovery result:

agentownerpurposeplatformenvironmenttoolsdata_classpermissionsautonomyreview_datereview_age_daystriagegapsas_of
CRM summary assistantDemo sales operationsDraft account summaries for a human reviewerExample hosted workflowproductionCRM search; document readerconfidentialCRM read on approved accountsdraft2026-10-015needs reviewNo completeness gaps found; verify against source systems2026-10-06

The example follows the builder's sample data and rules. A confidential-data record routes to needs review even when the fields are complete. The output does not establish that the owner, use, or connected sources are accurate.

Owner and review cadence

Assign a person who can confirm purpose, platform, data and permitted actions. The builder has an owner field and a review_date field; it does not set a review frequency or assign an owner. Choose a cadence and change triggers under your organization's policy. The builder adds a follow-up when a review is at least 90 days old, but that threshold is an editorial rule, not a universal review requirement.

Linking to risk register

Use a stable system identifier to connect this CSV row to your risk register, impact assessment, approval and incident records. Those references are not dedicated builder columns: add and maintain them in your controlled register or spreadsheet. An inventory row does not itself accept risk, approve deployment or establish compliance.

NIST AI RMF is intended for voluntary use; its Map function provides context for documenting intended purpose and deployment setting. ISO/IEC 42001 is an AI management-system standard, but this page does not claim a clause or Annex A mapping because its licensed normative text was not reviewed. EU AI Act Article 49 covers specified registration cases; this builder does not determine whether a duty applies or submit a registration. Check the current EUR-Lex consolidated Act and obtain qualified legal review when needed.

References: NIST AI RMF Map Playbook; NIST AI RMF status and voluntary-use overview; ISO/IEC 42001 public overview.

Continue with the AI agent inventory builder, the AI agent inventory template, or the shadow AI discovery guide.

Separate system, model and use-case records

A model inventory template can include model name or family, version, provider, deployment location, intended purpose and owner. A machine learning model inventory may also need development or training provenance, evaluation references and known limits; use fields the organization can maintain rather than inventing completeness scores. For a generative AI inventory, record which workflow uses the model, what data enters it, what outputs can do and where a human checks them.

When teams ask how to build an AI inventory, start with authorized source records and define how an AI use case register links to the system record. An AI systems register example might show one shared model tied to separate support-drafting and invoice-review workflows, each with its own owner and permissions. Keep examples illustrative and validate real records with their owners.

Approved tools and third-party use

An AI tools approved list template should distinguish approved, restricted, unreviewed and retired states according to internal policy. An approved AI tools list for employees is a communication aid; it does not show whether someone installed an extension or connected an unlisted service. A third-party AI tools inventory should identify provider, business purpose, data-sharing terms, access route and review contact, with links to procurement or privacy records where appropriate.

These fields support governance but do not establish certification or satisfy every audit requirement. See the ISO 42001 inventory guide, EU AI Act inventory guide and agent-specific spreadsheet. Updated 2026-10-08. Sources are linked on this page.

When deciding how to create an AI system register, first choose stable IDs and define how system records relate to use-case records and model versions. An AI model risk inventory can link a system to its separate risk assessment, evidence owner and treatment decisions; it should not turn an inventory entry into a risk score or compliance conclusion.

Primary sources and review

Published by Agent Inventory Tool. Updated . Sources are linked on this page. Outputs do not certify compliance.