Global AI Assurance · Layer 02

    Agent Identity Registry

    An agent that can act inside a regulated institution is an institutional entity. It needs an identity, an owner, a purpose, a jurisdiction and an authority envelope, on the same terms as a person holding a mandate. Anything less and the institution cannot say who did what.

    The registry record

    Every field is here because a supervisor, an auditor, a resilience test or an incident review asks for it.

    Agent ID

    A durable institutional identifier, independent of the platform hosting it.

    Named human owner

    One accountable person. Not a team, not a mailbox, not a vendor.

    Purpose

    The single business purpose the agent was approved for, in operator language.

    Jurisdiction

    The supervisory regimes that bind the activity the agent performs.

    Model and version

    Behaviour changes with the version. Assurance has to be version-aware.

    Tools

    Every tool the agent may invoke, declared before it runs.

    Permissions

    Scoped authority per tool rather than access or no access.

    Data access

    Classes of data reachable, with the transfer basis for each.

    Financial authority

    The value ceiling above which the agent must stop and escalate.

    Action authority

    Which actions are recommend-only and which may be executed.

    Escalation authority

    Who receives the escalation, and within what tolerance.

    Evidence route

    Where the agent's actions and refusals are written, and for how long.

    A sample register

    Bounded sample. The unassigned entry is deliberate: it is what discovery usually finds first, and it is why the registry exists.

    AG-0114Institutional

    Treasury liquidity agent

    Position reads and funding recommendations

    Owner
    Group Treasurer
    Jurisdiction
    UK, EU
    Autonomy
    Recommend only
    AG-0207Supervised

    Sanctions screening assistant

    Alert triage and narrative drafting

    Owner
    MLRO
    Jurisdiction
    UK, US, SG
    Autonomy
    Human-gated execution
    AG-0318Institutional

    Third-party review agent

    Vendor questionnaire analysis

    Owner
    Head of TPRM
    Jurisdiction
    EU, CA
    Autonomy
    Bounded execution
    AG-0422Supervised

    Client correspondence drafter

    Regulated communications drafting

    Owner
    Head of Compliance
    Jurisdiction
    US
    Autonomy
    Human-gated execution
    AG-0509Supervised

    Settlement exception agent

    Break investigation and routing

    Owner
    Head of Operations
    Jurisdiction
    EU, JP
    Autonomy
    Bounded execution
    AG-0611Institutional

    Model documentation agent

    Validation dossier assembly

    Owner
    Head of Model Risk
    Jurisdiction
    US, UK
    Autonomy
    Recommend only
    AG-0733Restricted

    Vendor-embedded summariser

    Unapproved feature in licensed software

    Owner
    Unassigned
    Jurisdiction
    Undetermined
    Autonomy
    Bounded execution

    Why identity comes before control

    Attribution

    Without an agent identity, an action is attributed to a service account and the accountability chain breaks at the first question.

    Revocation

    Authority you cannot name is authority you cannot withdraw. Identity is what makes an intervention possible.

    Evidence

    Every refusal and every permitted action is written against the identity, which is what turns oversight into a record.

    Identity establishes who the agent is. The permission fabric establishes what it may do.

    Agent Permission Fabric