Skip to content
Patronus
Website

Inventory and register

Separate discovered AI use from the decisions your organization records about it.

The AI Asset Inventory shows observed use. The AI Register records how your organization governs each connection.

An AI system is the discovered product or runtime capability. An endpoint is the network host used to reach it. An AI connection combines one system with one endpoint.

For example, the same AI tool can use two different endpoints. Those connections can have different owners, purposes, data expectations, and policies.

The inventory combines observed use across users and devices. Filter it to the systems and activity under review.

For each connection under review:

  1. Check the system and endpoint against observed use.
  2. Assign an owner who can explain its purpose.
  3. Record the business purpose and relevant data categories.
  4. Set the governance status appropriate to that review.
  5. Create or update policy if future matching activity needs a specific treatment.

AI category describes the connection’s classification. Data categories describe what it handles, such as internal information, source code, or customer data. They answer different questions.

A discovered entry is not automatically approved. Governance status does not replace an effective allow, block, or data-protection policy. Check the published policy and device rollout before assuming a register decision is enforced.

Revisit records when usage or ownership changes. The inventory describes observed activity; the register adds the organization’s review context.