Purpose Register

Every agent was built for a reason.
Almost none of them say what it is.

An agent's purpose lives in the head of whoever built it. When that person changes team, the agent keeps running and the reason is gone. The Purpose Register makes purpose a declared, signed, versioned record - and checks daily whether the agent still matches it.

Purpose drift is the gap between what an agent was approved to do and what it does today. It opens quietly: a tool is added, a knowledge source is attached, an instruction is edited. No alert fires, because nothing broke.

0
Declared purposes agents with a written, signed purpose in a live connected tenant of 625 agent records Measured on a connected Microsoft Copilot Studio and Power Platform tenant. Zero is not a failure of the customer - it is the normal state of every estate we have looked at, because no platform asks the question.

Why "what does it do?" is unanswerable today

Ask an agent platform what an agent is for and it will tell you what it is wired to - connectors, topics, channels. That is configuration, not intent. Intent is the thing an auditor, a risk committee and the EU AI Act all ask for, and it is the one field nobody stores.

1
Declare

A named accountable person writes what the agent is for, in plain language, with the business outcome it serves. Directory-backed, so the accountable name resolves to a real identity rather than free text.

2
Sign

The declaration is signed and versioned. A later edit creates a new version rather than overwriting the old one, so the record of what was approved, by whom, and when survives the edit.

3
Evaluate for drift, daily

Each day the agent's observed configuration is compared against its declared purpose. New tool reach, new knowledge sources, and autonomy changes surface as drift against the signed version - not as a generic change log.

4
Act on it

Drift can be accepted into a new version, or the agent can be demoted or stopped from the console. Every decision is written to a tamper-evident audit chain.

What this gives a risk committee

A named humanAccountability that is a person, not a mailbox or a service principal.
A version historyWhat was approved, by whom, on what date - and what changed since.
A daily checkDrift found by comparison, not by someone remembering to look.
An evidence trailHash-chained records that map to ISO/IEC 42001 and EU AI Act obligations.

Where it fits the frameworks

Purpose is not a nice-to-have field. Several obligations assume it already exists.

EU AI Act

Intended purpose is the anchor for risk classification. An estate with no declared purposes cannot classify its systems, and cannot show that it did. Note that the August 2026 obligations remain subject to the Digital Omnibus trilogue, so timelines may move.

ISO/IEC 42001

An AI management system requires defined objectives per AI system and evidence they are reviewed. A signed, versioned purpose with a daily drift evaluation is that evidence.

OWASP Agentic Top 10 - ASI01, Agent Goal Hijack

Detecting that an agent's goal has been subverted requires a recorded goal to compare against. Without a declared purpose there is no baseline, and the risk is undetectable by construction. See our honest coverage matrix.

Govern360 decides and compiles; it does not execute changes on your platforms without human review. The Purpose Register records intent and surfaces drift - it does not silently rewrite an agent. Nothing derives a purpose for you: a person has to declare it, which is the point.

Questions

What is an agent purpose register?

A purpose register is a record of what each AI agent is for - a written, signed and versioned declaration by a named accountable person, stored alongside the agent's identity. It turns intent from tribal knowledge into an auditable field that can be compared against what the agent actually does.

What is purpose drift?

Purpose drift is the widening gap between what an agent was approved to do and what it does now. It happens when tools, knowledge sources, permissions or instructions change after approval. Because nothing breaks, no alert fires - the drift is only visible if the original purpose was recorded and something compares against it.

Why do most AI agents have no declared purpose?

Because no agent platform asks for one. Platforms record configuration - connectors, topics, channels - not intent. In a live connected tenant of 625 agent records, zero had a declared purpose before Govern360 was connected.

Does Govern360 generate the purpose automatically?

No, and deliberately so. A purpose inferred from configuration would just restate the configuration. Govern360 requires a named accountable person to declare it, then signs and versions that declaration and evaluates drift against it daily.

See it on your own estate.

Book a 30-min demo