Open governance framework · v1.3 · Practitioner-led · not an accredited standard, certification, or regulatory requirement · seeking shadow-evaluation partners
Home/Platform/Agent Registry

TrustLayer · Module 01

Agent Registry

A source of truth for AI agent identity. If you cannot enumerate your agents, you cannot govern them.

The problem

Agentic capability tends to arrive department by department. Revenue cycle stands up an eligibility agent; the pharmacy team pilots a different vendor; a business unit inherits three more through an acquisition. Six months later nobody can answer a simple question: how many AI agents call on our behalf, and who signed off on each one?

That is not a tooling gap. It is an accountability gap — overlapping agents, inconsistent controls, and no clear owner when something goes wrong.

TrustLayer runs the same deterministic controls as the open framework — this module adds operations around them, not different rules.

What the registry tracks

FieldPurposeExample
agent_idStable identifier for the agent across its lifetimeclaims-agent-prod-001
organizationThe entity the agent acts on behalf of, bound to its NPIRegional provider group
vendorWho builds and operates the agent softwareVoice-AI platform vendor
ownerThe named internal person accountable for this agentDirector, revenue cycle operations
purposeWhy the agent exists — the business workflow it servesEligibility and benefits verification
permissionsThe bounded scope of actions the agent may take["eligibility", "claim_status"]
expirationWhen delegated authority lapses without renewalFixed date, re-approval required
statusActive, suspended, expired, or revokedactive

Why expiration is a field, not a policy

Authority that never lapses is authority nobody reviews. Registry entries carry an expiration, so continued operation requires a deliberate act by a named owner. An agent that quietly outlived its business case stops working instead of quietly continuing.

The same principle underlies NHID-Auth in the open framework: scope and expiry are signed fields inside the agent passport, so an over-broad or stale credential fails verification rather than depending on someone remembering to revoke it.

Illustrative entry

registry / agents / claims-agent-prod-001
claims-agent-prod-001Active
organizationRegional provider group
ownerDirector, revenue cycle ops
purposeEligibility verification
permissionseligibility, claim_status
expirationRenewal required

Illustrative registry entry — not live product data.

Development status: TrustLayer is being built with design partners and is not yet generally available. Screens and outputs on this page are illustrative, not live product data.

Related

Identity is the input to enforcement and to evidence.

TrustLayer by NHID-Clinical is in active development. It is not an accredited standard, a certification, or a regulatory compliance guarantee. The open framework it enforces remains free under CC BY 4.0 and is never gated behind a plan.