AI-BOM An exportable bill of materials
Agents, the models they are associated with, the policies that govern them and the frameworks in use — exported as JSON or as a PDF, and fingerprinted with a content hash over the inventory so a post-hoc edit is detectable.
FINDINGS Provenance on every row
Each finding keeps every source channel that observed the subject, the first and last time it was seen, its event count and a bounded set of sample events. An identity feed and an egress feed agreeing is visible as two channels, not one merged assertion.
COVERAGE A grid that admits gaps
Source families against contributions — discovery, enrichment, attribution and prevention context. A cell is only covered when a source is genuinely connected. Available-but-not-live is partial, and nothing shippable at all is an explicit gap, never a blank.
ATTRIBUTION Managed, unmanaged, or honestly unknown
Where an identity source is connected, findings roll up how many distinct principals behind them are inside your governed directory and how many are not. Where no directory is wired, the answer is unknown — and the rollup says so rather than assuming.
// GET /api/v1/aibom/export?format=json
{
"agents": [ /* id, name, namespace, environment, models, policies */ ],
"models": [ /* registry entry, approved_by provenance */ ],
"guardrails": [ /* policies covering at least one agent */ ],
"frameworks": [ "langchain", "langgraph", "crewai", "n8n" ],
"owners": [],
"tools_mcp": [],
"data_sources":[],
"notes": [
"Ownership is honest-empty: GovernorAI records agent registrant"
" and model approver PROVENANCE, not a designated owner.",
"Tools/MCP inventory is honest-empty: no per-tenant"
" agent-to-tool binding is recorded today.",
"Guardrail coverage reflects the governance-graph projection"
" as of <timestamp> and may lag live policy assignments."
],
"content_hash": "sha256:…"
}