AI agent registry
An AI agent registry is a structured catalog of agent metadata used for discovery and inventory. Records can describe capabilities, endpoints, ownership, deployment versions and status. Runtime discovery services and enterprise inventories share this core, although some products add governance or identity functions. In this entry, the term names the metadata layer: the presence of a record does not by itself authenticate a running agent or establish what it may do.
Origin and context
The May 2024 agent-design-pattern preprint described a Tool/Agent Registry for locating reusable capabilities. A separate 2025 survey preprint compared centralized, enterprise and distributed approaches, including Agent Cards and discovery directories. These are research sources, not evidence of a universal registry standard. Microsoft documented its enterprise registry in December 2025. The Cloud Security Alliance's March 2026 specification is explicitly a draft proposing richer agent, trust and lineage records.
Why it matters
A system with many agents needs a way to connect a capability description to a particular deployment. Without that connection, an orchestrator may know what work it needs but not where to send it; an administrator may see activity without a clear owner. Registries address these lookup and inventory problems. They can also reference policy or evaluation records, but whether those records affect execution depends on the surrounding identity, authorization and governance systems.
Example
As an illustrative design, a document-classification agent has a registry entry containing its endpoint, supported document types, owner and deployment version. Another application searches for a matching capability and reads the entry before contacting the endpoint. An administrator marks the old deployment retired after a replacement is introduced. The example separates three operations: discovering metadata, establishing the identity of the service, and deciding whether the requested interaction is permitted. A registry can participate in all three without making them equivalent.
How it differs
Agent2Agent Protocol
A2A defines how agents advertise capabilities and communicate, including Agent Card metadata. A registry can index those cards or endpoints, but A2A does not require every enterprise inventory or governance function. The protocol and catalog are complementary layers rather than synonyms.
Agent identity
Agent identity establishes which principal or workload is acting and supports authentication and delegation. A registry stores or references metadata about that identity. A record can exist without a cryptographically verified identity, so discovery should not be treated as authentication, authorization, or attestation.
Maturity and evidence
Maturity is rated 3. Independent architectural research, a comparative survey and an enterprise implementation support the shared discovery-and-inventory meaning. The rating is deliberately limited: registry schemas, federation approaches and trust functions differ across the reviewed systems, and the CSA document is a draft rather than an adopted universal standard. Evidence for one product's richer controls does not establish that every registry has them.
Limits and open questions
Metadata can become stale, omit deployments or describe claimed rather than verified capabilities. A retired record and a stopped workload are not necessarily the same event. Skills Intelligence therefore distinguishes catalog completeness from runtime enforcement: evaluating a registry requires knowing which agents it covers, who updates records, and how consumers interpret status. This entry describes that architectural boundary, not a certification or legal-compliance procedure.
Related terms
References
- Agent Design Pattern Catalogue: A Collection of Architectural Patterns for Foundation Model based AgentsIndependent academic collaboration / arXiv · 2024-05-16 · class A
- Evolution of AI Agent Registry Solutions: Centralized, Enterprise, and Distributed Approaches (v3 preprint)Independent academic collaboration / arXiv · 2025-10-20 · class A
- New capabilities for AI admins from Ignite 2025Microsoft · 2025-12-18 · class A
- Agent Registry SpecificationCloud Security Alliance AI · 2026-03-27 · class A
Last updated: 2026-09-05
This term is also covered in the Skills Atlas as ai agent design skill.
This term is also covered in the Skills Atlas as multi agent systems skill.