Agent Registry inventories every Copilot, bot and autonomous agent across Teams, Copilot Studio, M365 Copilot Agent Builder, Azure AI Foundry, SharePoint, Entra and Security Copilot — plus external platforms like Amazon Bedrock, Google Vertex AI, Salesforce Agentforce and Databricks Genie — then scores each one for governance risk, so you can focus only on the high-risk agents that can harm your environment. Token forwarding only; nothing is stored server-side.
Makers spin up Copilot Studio bots, M365 Copilot Agent Builder agents, Foundry assistants and SharePoint agents faster than IT can track them. Agent Registry gives you the one place to see, and judge the risk of, all of it.
Teams app catalog, Copilot Studio, M365 Copilot Agent Builder, Foundry projects, SharePoint .agent files and Entra agent identities. Unified, searchable, sortable.
Flags autonomous orchestration, external HTTP calls, write-capable tools, non-business connectors, orphaned identities and dormant service principals.
Default scopes are .Read across every workload. Delete actions are a separate, opt-in, admin-consented grant. Never the default.
One-click .xlsx / .pdf export, plus a cross-source Copilot activity view straight from the unified audit log.
Exact Copilot credits per agent and per user, plus messages and sessions from transcripts. Pulled with your normal sign-in, no device code, month to date or last 3 months.
Checking every agent in the tenant doesn't scale, and doesn't make sense. The inventory is ranked by risk score, so the agents that can actually harm your environment sit at the top of the list.
One dashboard tells you where to look first, before you ever open the grid.
The risk score isn't a gut feeling, it's calculated from the agent's actual properties: what its capabilities can do, where it's published, and who (if anyone) owns it. The result is a weighted 0 to 100 score that puts the agents that matter in front of you.
Click any row and see exactly what the agent can do: why it got its risk score, which tools and connectors it holds, where it's published, and who owns it.
Exact Copilot credits per agent, straight from the Power Platform licensing API with your normal sign-in, no device code, no export to paste. Sessions and messages are counted from the conversation transcripts, on the same window Copilot Studio's own Monitor uses.
No agents to install, no database to host. It runs in your browser and talks to Microsoft directly.
Create a single-page App Registration in Entra, or run the in-browser Grant admin consent flow. Paste the Application (client) ID and you're set. You'll be asked to consent multiple read permissions. All are described below.
Delegated and read-only. The app acts as you and forwards your token; it never holds standalone application rights.
Inventory, risk scores and audit populate across all sources instantly. Drill into any agent's tools, connectors and permissions, then export.
The whole point is to see every agent in the tenant without changing anything. Inventory, risk analysis and every export run entirely on read scopes.
Your browser talks to Microsoft directly. The app forwards your token and stores nothing server-side.
It acts as you, never as a standalone app with its own rights. Single- or multi-tenant, your choice.
The two ReadWrite scopes that unlock Delete are separate and never part of the default consent.
A missing role only hides one source or one signal. It never breaks sign-in for everything else.
Agent Registry is delegated-only: it acts as you, never as an app. The App Registration is single-tenant. It lives in your tenant and only accounts from your tenant sign in to it. The first sign-in triggers a standard Microsoft consent prompt; a Global Administrator approves once, and every user in that tenant can then sign in normally.
Inventory, risk analysis, every export and every drill-through run entirely on the .Read.* scopes below.
The two ReadWrite scopes that unlock per-agent Delete live in a separate section below, not in the default admin-consent flow.
Foundry agent deletes are likewise role-gated, not scope-gated.
OAuth scopes alone aren't enough; these are role assignments. The app degrades gracefully per source: a missing role only hides one source or one signal, never breaks sign-in.
The sample report shows you the agents already living in your environment that carry real risk: autonomous bots, external API callers and over-permissioned identities that can read your data, take actions and do real harm. See exactly what Agent Registry would surface in your tenant. No sign-in, no data leaves your browser.
Amazon Bedrock
Google Vertex AI
Salesforce Agentforce — you'll end up with a My Domain URL, a Consumer Key and a Consumer Secret. In Setup:
Databricks Genie
ServiceNow AI Agents
Available now
Coming next