AI INVENTORY & REGISTRY
Turn Your Agent Inventory
Into Access Control
Catalog agents, MCP servers, skills, and prompts with their owners, approvers, and risk tiers. Once a use case is approved, the AI Gateway enforces what its agents can reach.
Why Your AI Inventory
Needs to Keep Up with Your Agents
AI inventories usually start as spreadsheets or questionnaires filled in when something gets approved. They go stale as soon as a team adds a tool or swaps a model, and the approval never touches what the agent can reach in production. When something breaks or needs retiring, no one knows which other agents depended on it.
Lumenova AI replaces the spreadsheet with a versioned registry, so each change to an agent, tool, or prompt is recorded as a new version rather than lost. Agents that show up in gateway traffic without an entry are caught and held for review, which keeps the inventory complete.
The dependency graph shows which agents would break before you retire anything. And because the AI Gateway scopes access by approved use case, an approval on paper becomes a limit in production.
Capabilities
Know What Every Agent Uses, and What It May Reach
Catalog each AI component, track what depends on it, and carry each approval through to what agents can reach at runtime.
Versioned Artifacts
Version agents, MCP servers, skills, and prompts, pin or float them, and move each through active, deprecated, blocked, and deleted states.
Dependency Graph
See what depends on what, and check which agents would break before you retire a server or prompt.
Use Case Approvals
Record each use case’s status, approver, owner, risk tier, data classifications, bound resources, and GRC reference.
Runtime Enforcement
Scope each team’s gateway access by approved use case, starting in flag mode to log what would be blocked.
Attached Policy
Sync registered agents into platform projects and attach a policy stack to each, so its rules stay with its registry entry.
One-Click Deployment
Deploy agents from the catalog in one click, with scaling, restarts, secrets, and out-of-memory handling managed for you.
Import and Lifecycle Rules
Import MCP servers from npm and PyPI, scan for known vulnerabilities, and auto-block risky servers or revoke idle keys.
Shadow AI Inbox
Route agents seen in gateway traffic but missing from the registry to an inbox, where someone registers or rejects them.
From Discovery to Enforcement
An agent appears
It calls through the gateway without a registry entry, and the gateway holds it.
Register
Someone registers it under a use case, with an owner and a risk tier.
Approve
An approver sets the use case's approval status.
Access scoped
At the AI Gateway, the approved use case sets what the team's agents can reach.
Stays held
The agent stays held, and a key that keeps getting flagged is revoked once it crosses your threshold.
Policy attaches
The registered agent syncs into a platform project, where a policy stack attaches to it.
Frequently Asked Questions
No. The two work together. Each use case can reference its GRC record, so your GRC tool stays the system of record for governance, while the registry tracks what agents actually depend on and enforces what each use case was approved to reach.
Changes are recorded as new versions rather than overwritten, unregistered agents seen in gateway traffic are flagged for review, and MCP servers can be imported in bulk.
It’s flagged as deprecated, never silently deleted, so you can see which agents still depend on it and plan a replacement.
Each use case records its approver, owner, and approval status.
It can speed them up. The catalog shows builders which servers, agents, skills, and prompts are already approved, so they can start from components that will pass review instead of waiting to find out.