A governance inventory should track executions, not only installed tools. For each run I would record the initiating human, agent and model version, repository and branch, granted capabilities, external data sources, approvals, produced commits, and verification evidence. That turns 'which agents have production access?' into a query instead of an incident-response archaeology exercise. The same record can support cost and outcome metrics, so security controls and business-value evaluation share one source of provenance.
Ahmet Özel
A governance inventory should track executions, not only installed tools. For each run I would record the initiating human, agent and model version, repository and branch, granted capabilities, external data sources, approvals, produced commits, and verification evidence. That turns 'which agents have production access?' into a query instead of an incident-response archaeology exercise. The same record can support cost and outcome metrics, so security controls and business-value evaluation share one source of provenance.