For three years, "AI-ready" was the badge every enterprise chased: models selected, data pipelines built, use cases approved, a strategy slide the board liked. Then agents arrived, and the badge stopped covering the risk. An agent is not a model you call — it is software that acts: it holds credentials, calls tools, writes to systems of record, and increasingly talks to other agents. If you are taking that shift to Gartner IT Symposium/Xpo 2026, here is the argument for making one investment before all the others: the master AI agent registry.
Agent-ready is an accountability property
The test of agent-readiness is not how many agents you run. It is whether you can answer, under pressure — from a regulator, an auditor, an incident bridge at 2 a.m. — four questions: What agents do we run? Who owns each one? Which were approved, for what? And can we stop one, now?
Every one of those answers assumes the same substrate: a single, current, trustworthy list. Policy without an inventory is aspiration. Containment without an inventory is whack-a-mole. Evidence without an inventory is a reconstruction project every audit. That is why the registry is the first agent-readiness investment, not the last — every other control inherits its coverage.
Why "master" is the load-bearing word
Your platforms already have registries. Azure AI Foundry lists Foundry agents; Salesforce lists Agentforce agents; ServiceNow, Bedrock and Vertex each keep their own. Every one of those lists is true, and every one is bounded — the platform governs inward, and its list ends at its console.
The master registry is the layer above: connectors harvest each platform's agents through its API into one list with one record shape, alongside the agents you build and run yourself. Then comes the step that turns a directory into governance — reconciliation. Every harvested agent is matched against the approved-use-case registry. Matched agents are governed. Unmatched agents are shadow AI: flagged, assigned, and either brought into governance or retired. The regional team's Salesforce agent, the Vertex prototype that quietly became production — reconciliation finds the agents nobody remembers to declare, because it never depends on anyone declaring them.
The record model: eleven fields
A registry is only as strong as its record. The model we use — the same one in our free registry template and on the master registry page — carries eleven fields per agent:
Name and technical identifier. Owner and business unit. Platform and runtime. Model and tools. Use case. Autonomy tier. Data classes touched. Risk classification. Approval state. Last observed activity. Lifecycle state.
Two of these do most of the governance work. Owner — because when an agent misbehaves, the registry either produces a phone number or it produces a meeting. And approval state — because the EU AI Act made who approved this, when, for what a first-class artifact rather than a courtesy. A record missing either one is a catalog entry, not accountability.
From discovery to lifecycle
What happens after an agent is found is where registries earn their keep: assign an owner, classify the risk, approve the use case, govern the traffic, monitor the behaviour, retire the agent when its job ends — credentials revoked, record archived, evidence kept. Each transition lands on the audit trail. Run that loop for a quarter and something changes in kind: the registry stops being a list you maintain and becomes the system of record other controls consult — the gateway checks it, the compliance bundles cite it, the kill switch resolves targets against it.
If you want the working plan rather than the theory, the 30-day agent inventory walks the first month step by step, and the registry pillar guide covers build-vs-buy honestly — including when a spreadsheet is genuinely enough to start.
What to pressure-test in Barcelona
Vendors will show you agent lists all week. Three questions separate a master registry from a long list: Which platforms can you harvest from automatically — and what happens with the ones that have no API? (Manual registration with tagging is a fine answer; silence is not.) Show me the reconciliation — approved use cases against discovered agents, and the queue where the unmatched land. What does retirement do? If deleting an agent's record also deletes its evidence, the registry fails its most important audit the day it matters.
We will be running that exact demo on the expo floor, 9–12 November — harvest, match, flag, resolve — as one workflow with the gateway and the kill switch. Book a meeting before the event, or email sales@kosmoy.com with the days you are on site. Bring your current agent list, however partial; the gap between it and the harvest is the most persuasive slide you will see all week.
FAQ
What makes an enterprise agent-ready rather than AI-ready?
AI-ready meant models, data pipelines and approved use cases. Agent-ready adds accountability for software that acts: one registry of every agent across every platform, an owner and risk tier per record, policy enforced on agent traffic, and the ability to stop an agent mid-run. The registry comes first because every other control assumes you know what exists.
What fields should a master AI agent registry record carry?
Name and technical identifier, owner and business unit, platform and runtime, model and tools, use case, autonomy tier, data classes touched, risk classification, approval state, last observed activity and lifecycle state. A record missing the owner or the approval state is a directory entry, not governance.
How is a master agent registry different from each platform's own list?
Platform registries govern inward — Foundry lists Foundry, Salesforce lists Salesforce. The master registry is the layer above: it harvests all of them through connectors, holds one record shape, reconciles against approved use cases, and is owned by the enterprise rather than any vendor. Accountability lives at that layer because that is where the whole estate is visible.
Gartner and Gartner IT Symposium/Xpo are trademarks of Gartner, Inc. and/or its affiliates. Kosmoy is an exhibitor at the 2026 Barcelona conference. Gartner does not endorse Kosmoy or its products.