Pages
Policy Config — Agent Registration
Source: c65 policy-definitions.md P1 — toggle + exceptions shape
‹ Policy Catalog
Agent Registration
Agents must be registered and monitored before they run. Every framework that asks "do you know what AI is running?" is answered here — shadow-AI discovery is this policy's violation feed.
Identity & Access
medium
P1Satisfies
OWASP ASI
AI RMF
CSF 2.0
ISO 27001
ISO 42001
SOC 2
EU AI Act
HIPAA
Underlying control— show
install: covered = falseedit as custom control →3 unmonitored installs right now
claude-code on dev-mbp-14 · cursor on eng-042 · codex-cli on eng-017 — install the tap or add a scoped exception below.
Exceptions
Scoped carve-outs with a reason and an expiry — accepted risk, on the record.
| Scope | Value | Reason | Expires | |
|---|---|---|---|---|
| host | lab-03.qpoint.dev | Air-gapped research machine — no tap possible | 2026-09-30 | |
| adapter | ci-ephemeral-* | Short-lived CI runners, covered by the image policy | never | |
Remediation shown on findings: Install the tap on the unmonitored host, or register the agent and bind it to policy.