Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 2135Recording Identifier, Owner, Identities, Credentials and Access for Each AI Agent

Every AI agent gets a register entry that names it, says who owns it and why it exists, and lists the identities, accounts, credentials, tools, permissions and data it can use.

record_voice_over

Plain language

An AI agent is software that acts on its own to complete tasks, often by logging in to systems, calling tools and reading or writing data. Because it behaves like a user with its own access, the organisation needs to know exactly what each one is and what it can touch. This control sets the minimum content of the AI agent register. For every agent, the register must record five things: a unique identifier so the agent can be told apart from every other agent; its owner and the business purpose it serves; the identities assigned to it; any user accounts and credentials it uses; and the tools, permissions and data repositories it can access. Why it matters: without these details, an agent can quietly accumulate access nobody is accountable for. If an agent is compromised, misbehaves or is simply forgotten, the organisation cannot quickly work out which accounts to disable, which credentials to rotate, which data it could have reached, or who to call. A complete register turns an unknown, hard-to-contain risk into something that can be reviewed, reduced and shut off when needed.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2026

Control Stack last updated

05 Sept 2026

E8 maturity levels

N/A

Topic

Artificial intelligence agent register

Official control statement

An AI agent register contains the following for each AI agent: - its unique identifier - its owner and business purpose - the identities assigned to it - any user accounts and credentials it uses - the tools, permissions and data repositories it can access.
policyASD Information Security Manual (ISM)ISM-2135
priority_high

Why it matters

If the register is missing or incomplete, the organisation loses visibility of what its AI agents can do. Orphaned agents keep running with live credentials after their purpose ends, over-privileged agents hold access to tools and data repositories no one approved, and when an agent is compromised or acts unexpectedly there is no fast way to identify its accounts, revoke its credentials or scope what data it could have exposed. Incident response slows, accountability is unclear, and a small agent fault can become a wider data breach.

settings

Operational notes

Day to day, the register is a living record rather than a one-off document. A new entry is created when an AI agent is approved, and it is completed with all five fields before the agent goes live: the identifier, the owner and business purpose, the identities assigned, the user accounts and credentials in use, and the tools, permissions and data repositories it can access.

Entries change whenever the agent changes. When an agent is given a new tool, a new permission, a new account or access to another data repository, the register is updated at the same time as the access is granted. When an owner leaves or a purpose changes, the entry is reassigned or amended. When an agent is retired, its entry is marked closed so the accounts and credentials listed against it can be removed.

Credentials themselves are not stored in the register; the register records which accounts and credentials the agent uses (for example the account name and where the secret is held) so they can be found and revoked. Access to the register is limited to those who need it, because it describes exactly how each agent can reach organisational systems.

build

Implementation tips

  • The AI or platform owner defines the register schema with one mandatory field for each item in the statement (unique identifier, owner, business purpose, assigned identities, user accounts and credentials used, and accessible tools, permissions and data repositories) and hosts it in a controlled system such as the CMDB, IAM tool or an access-controlled spreadsheet.
  • The change or onboarding process owner adds a gate so that no AI agent is deployed until its register entry is created and all fields are populated, and the identifier is generated by the register rather than chosen by the requester so it stays unique.
  • Each agent's business owner completes and signs off the owner and business purpose fields, and confirms the list of identities, accounts and credentials the agent uses by checking them against the identity provider and secrets store rather than from memory.
  • The identity and access team records the tools, permissions and data repositories each agent can access by exporting the agent's actual role assignments and integration scopes from the systems concerned, then pasting the result into the register entry so it reflects real access.
  • The register custodian links register updates to the access-change workflow so that every grant, change or removal of an agent's account, credential, tool, permission or data access automatically triggers an update to that agent's entry, and closes the entry when the agent is decommissioned.
fact_check

Audit / evidence tips

  • AskAsk for the AI agent register and a separate list of AI agents currently running in the environment, for example from the AI platform, integration catalogue or identity provider.Look atCompare the two lists and check that every running agent has a register entry with a unique identifier that is not shared with any other agent.GoodEvery deployed agent appears in the register exactly once, and there are no agents in the environment that the register does not know about.
  • AskAsk for a sample of register entries and the names of the people recorded as owners.Look atCheck that each entry names a current, identifiable owner and states a specific business purpose rather than a generic description.GoodOwners are real, current staff who confirm they own the agent, and the purpose is specific enough to judge whether the agent's access is appropriate.
  • AskAsk for the identities assigned to a sampled agent, as recorded in the register, and the corresponding records in the identity provider.Look atCheck that the identities in the register match those actually assigned to the agent in the identity system, with none missing or extra.GoodThe register and the identity provider agree on exactly which identities the agent holds.
  • AskAsk for the user accounts and credentials each sampled agent uses, as listed in the register, and evidence from the secrets store or account directory.Look atCheck that every account and credential the agent uses is listed, and that the register points to where the credential is managed rather than containing the secret itself.GoodAll accounts and credentials in use are recorded and traceable to their managed location, so they could be found and revoked quickly.
  • AskAsk for the tools, permissions and data repositories recorded for a sampled agent, plus the agent's actual role assignments, API scopes and data access from the systems it connects to.Look atCheck that the register reflects the agent's real access and that the entry has been updated when access changed.GoodThe recorded tools, permissions and data repositories match the live configuration, and change history shows the entry is kept current.
link

Cross-framework mappings

How ISM-2135 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 5.15ISM-2135 requires maintaining an AI agent register that records identifiers, ownership, assigned identities, credentials, and the tools/p...
sync_altPartially overlaps(1)expand_less
Annex A 5.17ISM-2135 mandates documenting user accounts and credentials an AI agent uses, alongside identities
handshakeSupports(1)expand_less
Annex A 5.18ISM-2135 requires recording identities, accounts, credentials, and access scope for each AI agent

ISO 42001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 4.2ISM-2135 requires an AI agent register entry that records identifiers, owner, assigned identities, credentials, and the tools/permissions...
handshakeSupports(2)expand_less
Annex A 4.3ISM-2135 requires an AI agent register entry listing data repositories accessible to each AI agent
Annex A 4.4ISM-2135 requires an AI agent register entry listing the user accounts/credentials used by the agent and the tools it can access

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system access controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls