You cannot control what nobody wrote down.
Most organizations find out during an audit that nobody has a current list of the AI they are running. Swiftward keeps that list as it enforces policy: an agent is added to the registry on its first call.
Built into the Swiftward service you run.
What is on the record for each agent
| What it is | name, owner, business purpose |
| What it runs on | the model, the provider, the endpoint |
| What it may call | tools, endpoints, and the limits on each |
| What governs it | the ruleset and the version in force |
| What it has done | every decision, with the rule that produced it |
Nobody types an agent in. It is added to the registry on its first call, before anything is served to it, even when policy refuses that call. You add an owner and a risk level to that row. The traffic keeps the registry current, so it cannot go out of date the way a spreadsheet does.
Material for your technical documentation
The declarations, the rule versions and the decision history are what technical documentation is written from: what the system does, which controls sit on it, what it decided and on which version. You export them and write the document.
Your system's risk tier under the law is a legal decision about how you use the system. You make it with your counsel, and no vendor can make it for you. See our read of the EU AI Act.