What to record per AI system
Use one row for each AI deployment or workflow whose purpose, owner, data, environment or permitted actions need separate review. A shared model can support several systems, so the model name alone is not a reliable inventory unit. This page describes the fields in the site's manual agent builder; it is not a universal data schema for every AI system.
Template fields
The builder accepts a JSON array with these ten string inputs. Descriptive values may be blank when unknown; the agent identifier must be present. The three enum fields have the allowed values shown here.
| Input field | What to record | Accepted values / notes |
|---|---|---|
agent | Unique deployment or workflow name | Required and unique, ignoring case |
owner | Accountable owner | Use blank when unknown; the builder flags the gap |
purpose | Intended task and use | Use blank when unknown |
platform | Host, product or runtime | Use blank when unknown |
environment | Deployment stage | development, test, production, or unknown |
tools | Connected tools or integrations | Use blank when unknown; this is free text, not a discovered connector list |
data_class | Data category | public, internal, confidential, restricted, or unknown |
permissions | Granted scopes and allowed operations | Use blank when unknown; do not enter secret values |
autonomy | Allowed action level | read, draft, write, approve, or unknown |
review_date | Last review date | YYYY-MM-DD; blank schedules a first-review gap |
The CSV adds four calculated columns: review_age_days, triage, gaps, and as_of. The triage values are published editorial routing rules, not risk scores or legal classifications. The CSV does not include separate fields for model ID, evidence link, risk-register ID, credential reference, review owner or review cadence; maintain those in your controlled register if needed.
Download
Open the builder, load its synthetic JSON example or read your own local JSON file, review the output, and choose Export inventory CSV. Import that CSV into Excel, Google Sheets or another approved spreadsheet yourself. The site does not generate an Excel workbook, create a Google Sheet, or connect to either service. Browser print/save-to-PDF is a separate summary option; it is not a generated spreadsheet or a legal register.
Filled-in example
Illustrative synthetic record, not a real deployment or system-discovery result:
| agent | owner | purpose | platform | environment | tools | data_class | permissions | autonomy | review_date | review_age_days | triage | gaps | as_of |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CRM summary assistant | Demo sales operations | Draft account summaries for a human reviewer | Example hosted workflow | production | CRM search; document reader | confidential | CRM read on approved accounts | draft | 2026-10-01 | 5 | needs review | No completeness gaps found; verify against source systems | 2026-10-06 |
The example follows the builder's sample data and rules. A confidential-data record routes to needs review even when the fields are complete. The output does not establish that the owner, use, or connected sources are accurate.
Owner and review cadence
Assign a person who can confirm purpose, platform, data and permitted actions. The builder has an owner field and a review_date field; it does not set a review frequency or assign an owner. Choose a cadence and change triggers under your organization's policy. The builder adds a follow-up when a review is at least 90 days old, but that threshold is an editorial rule, not a universal review requirement.
Linking to risk register
Use a stable system identifier to connect this CSV row to your risk register, impact assessment, approval and incident records. Those references are not dedicated builder columns: add and maintain them in your controlled register or spreadsheet. An inventory row does not itself accept risk, approve deployment or establish compliance.
NIST AI RMF is intended for voluntary use; its Map function provides context for documenting intended purpose and deployment setting. ISO/IEC 42001 is an AI management-system standard, but this page does not claim a clause or Annex A mapping because its licensed normative text was not reviewed. EU AI Act Article 49 covers specified registration cases; this builder does not determine whether a duty applies or submit a registration. Check the current EUR-Lex consolidated Act and obtain qualified legal review when needed.
References: NIST AI RMF Map Playbook; NIST AI RMF status and voluntary-use overview; ISO/IEC 42001 public overview.
Continue with the AI agent inventory builder, the AI agent inventory template, or the shadow AI discovery guide.