AIPolicyTracker
RegisterFree · no accountEU AI ActNIST AI RMF

AI Agent Registry and Permission Matrix

A register for agents that act — with tools, credentials and autonomy — and a permission matrix stating what each may do alone, with approval, or never.

Formats: XLSX and DOCX · Version v1 · Built from dataset 914895c3103e · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

What's inside

  • Registry sheet: agent, purpose, model, tools, credentials, owner, kill switch, logging
  • Permission matrix sheet: agents against actions (read, write, send, execute, pay, browse, act for a user) with Allowed / With approval / Denied dropdowns
  • Duties sheet: the oversight and transparency duties on record that apply to autonomous systems

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Registry · 13 columns · blank, 100 rows ready to fill
First rows of the Registry sheet
Agent IDAgent namePurpose and scopeModel(s)Tools and integrationsCredentials it holdsAutonomy level ▾Hard limits (spend, scope, rate)Accountable ownerKill switch tested ▾Actions logged ▾Last reviewNotes
Rows are yours to fill; the dropdowns, formulas and colour rules are already in place.
Sheet: Permission matrix · 10 columns · blank, 100 rows ready to fill
First rows of the Permission matrix sheet
AgentRead internal data ▾Write or change data ▾Send messages or email ▾Execute code ▾Make payments or commit funds ▾Browse the internet ▾Call other agents or tools ▾Act on behalf of a named person ▾Actions allowed alone ƒ
Rows are yours to fill; the dropdowns, formulas and colour rules are already in place.

One row per agent. Four or more actions allowed alone turns the count red: that is an agent that needs the oversight procedure, not a note.

Sheet: Oversight duties · 14 columns · 34 rows from the records
First rows of the Oversight duties sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6)Human oversightAustralian Voluntary AI Safety StandardAustraliaDeployer / user organisation, Provider / developerVoluntaryGuardrails 4, 5 and 6Test AI models and systems before deployment and monitor them in operation; enable meaningful human control and intervention; and inform end users about AI-enabTest reports and user disclosure recordsMEASURE and MANAGE functionsSource-linkedhttps://aipolicytracker.org/obligations/australia-vaiss-testing-human-control-transparency
Frontier developers must publish a transparency report before deploying a new frontier modelTransparency and disclosureCalifornia SB 53California (United States)General-purpose AI model provider, Provider / developerLegal requirementBusiness and Professions Code Section 22757.12 (as added by SB 53)2026-01-01Before or at the time a frontier developer deploys a new frontier model, or a substantially modified version, it must publish a transparency report on its websiPublished model transparency report; Redaction justification logAnnex A.8.2, A.8.3GOVERN 4.2, MAP 5.1, MEASURE 2.6Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report
Notify consumers and explain adverse consequential decisionsTransparency and disclosureColorado AI ActColorado (United States)Deployer / user organisationLegal requirementC.R.S. 6-1-1703(4)2026-06-30Before a high-risk system makes a consequential decision, deployers must notify the consumer that AI is used, describe its purpose and nature, and provide contaConsumer notice and adverse-action explanation templatesGOVERN 5.x, MANAGE 4.xSource-linkedhttps://aipolicytracker.org/obligations/us-colorado-consumer-notice-and-adverse-decision-explanation
Deployers must publish a statement about the high-risk AI systems they useTransparency and disclosureColorado AI ActColorado (United States)Deployer / user organisationLegal requirementC.R.S. 6-1-1703(5)2026-06-30A deployer must make available on its website, or in another public way, a clear and readily available statement summarising the types of high-risk AI systems iPublic statement on high-risk AI useAnnex A.8.5GOVERN 4.2, MAP 5.2Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-colorado-ai-act-deployer-public-statement
Deployers and developers must disclose to consumers that they are interacting with an AI systemTransparency and disclosureColorado AI ActColorado (United States)Deployer / user organisation, Provider / developerLegal requirementC.R.S. 6-1-17042026-06-30Any developer or deployer that makes an AI system available to consumers that is intended to interact with them must disclose to each consumer that they are intAI interaction disclosure copy and screenshotsAnnex A.8.5GOVERN 5.1, MANAGE 4.1Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-colorado-ai-act-consumer-ai-interaction-disclosure
Design high-risk systems to log events automaticallyRecord keeping and loggingEU AI ActEuropean UnionProvider / developer, Deployer / user organisationLegal requirementArticle 12; Article 26(6) for deployers2026-08-02High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operatiLogging specification and retention policyAnnex A control on event loggingMEASURE 2.x, MANAGE 4.1Source-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-record-keeping

Document outline (DOCX)

  1. Agents are systems that act
  2. Permission levels
  3. Duties that apply
  4. Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6)
  5. Enable and assign effective human oversight
  6. Employers and employment agencies must let candidates request an alternative selection process or accommodation
  7. Determine the appropriate level of human involvement in AI decisions
  8. Operators of high-impact AI must ensure human management and supervision
  9. Respect the right to object to automated decision-making without human intervention
  10. Provide routes to contest AI outcomes and seek redress
  11. Apply safeguards to solely automated decisions with significant effects

Duties this template covers (35)

Each is cited in the file with its source reference and a link back to the record.

See all 35 duties →

Legal basis

Version history

Versions of AI Agent Registry and Permission Matrix
VersionBuiltDatasetWhat changed
v1914895c3103eFirst version, built from dataset 914895c3103e.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

Is the AI Agent Registry and Permission Matrix free?
Yes. Download the XLSX and DOCX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 914895c3103e: 42 recorded duties are cited in it, drawn from 13 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Is the AI Agent Registry and Permission Matrix free?
Yes. Download the XLSX and DOCX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 914895c3103e: 42 recorded duties are cited in it, drawn from 13 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.