AgentRoster

Know every AI burning tokens in your company.

The registry for every token-consuming Asset: its owner, its cost, and its risk.

Prepared for Curriculum Associates · Internal review

Why now

AI is expanding across the company faster than governance can keep up.

Copilots, agents, batch jobs, Claude Code instances. Every team is adopting AI tools on their own timeline, and nobody has a central picture of what's running.

The blind spot

Nobody can answer four basic questions about our AI.

01How many agents are running across the company?
02Who owns each one?
03What data do they touch?
04Which are sanctioned, and which are not?

Framing from a Microsoft / Hypothesis Group survey of 1,725 security leaders, Feb 2026.

The risk

Every unsanctioned AI tool is another attack surface you can't see.

Each shadow agent potentially sends company data to a third-party API nobody vetted. In a world of SaaS vendor breaches, every unregistered AI tool widens the blast radius.

Data exposure

Prompts, context, and outputs flowing to APIs outside your security perimeter.

No audit trail

When a breach happens, you can't say which AI systems were in scope or what data they touched.

Student data liability

For us specifically: an unregistered agent touching student records is a FERPA/COPPA exposure at board level.

The cost

Untracked AI spend bleeds across every team.

Data Eng
Product
Content
Support
Attributed to an owner Nobody can say whose this is

The other world

Picture every AI Asset, accounted for.

  • Every token-consuming Asset is named and registered.
  • Each one is owned by exactly one team.
  • Its cost is attributed, every month.
  • Its risk tier is set, and reviewed before production.

Introducing

AgentRoster is the registry for every token-consuming Asset.

AgentRoster · Assets
AssetFrameworkOwner30-day costRiskState
i-Ready Tutor Assistantclaude-codeData Eng$4,210Tier 3production
Lesson Draft GeneratoropenclawContent$1,980Tier 2production
Support Triage BotlanggraphSupport$640Tier 1development
Roster ETL Nightlybatch scriptPlatform$305Tier 3production

How it works

Three steps: register, attribute, govern.

01 · Register

Every Asset, named

Anything that burns tokens goes in, regardless of framework or provider.

02 · Attribute

Owner & cost

Each Asset sits under one Org Unit and pulls real spend from the provider.

03 · Govern

Lifecycle & risk

Set a risk tier and clear approvals before anything reaches production.

Deployment

Runs inside your network. Nothing leaves.

01

On-prem artifact

You receive a self-contained deployable. It runs on your infrastructure.

02

You operate it

Your team runs the instance. No vendor access to your environment.

03

Metadata only

Reads aggregated usage — token counts, cost, timestamps. Never prompts, responses, or student PII.

04

No data exfiltration

Nothing leaves your network. No telemetry, no call-home, no external dependencies.

05

Full control

Turn it off any time. Nothing persists outside your environment.

Why not just use what we have

A registry, not another dashboard.

A spreadsheetGoes stale the day after you make it, and nobody owns it.
Observability (Langfuse, Datadog)Great at traces and latency. It doesn't hold the org-level inventory of who owns each Asset.
FinOps / cloud-cost toolsShow spend. They don't track lifecycle, ownership, or FERPA/COPPA risk tier per Asset.

AgentRoster is the layer above those: the system of record for every AI Asset.

The ask

Let's run a 30-day design-partner pilot.

Curriculum Associates gives

  • An executive sponsor
  • A pilot owner, a few hours a week
  • Read-only access to provider usage
  • A reference if it works

AgentRoster gives

  • A deployable artifact we run on our infra
  • Setup support and weekly check-ins
  • A build commitment on what we agree
  • Founder pricing locked for after
Success, agreed up front: 100% of the IT group's token-consuming Assets inventoried, each with an owner and a risk tier, and previously-unattributed spend surfaced.

Where it goes

From inventory today to control tomorrow.

The registry is the foundation. Next comes per-invocation observability and policy that can stop an Asset before it ever reaches production. You start by seeing everything. Then you start deciding what's allowed.

Appendix · Architecture

What the deployment looks like.

Your network

AgentRoster instance

Self-contained artifact. Runs on any Linux server or container runtime (Docker).

reads →

Provider usage APIs

Anthropic, OpenAI, Azure. Read-only access to token counts, cost, timestamps.

No data crosses this boundary
External

AgentRoster team

Support via email/call only. No access to your instance or infrastructure.

Appendix · Data & security

What it reads, what it doesn't.

Token counts per API call✓ Read
Cost / billing data✓ Read
Timestamps and model IDs✓ Read
API key names (not values)✓ Read
Prompts or completions✗ Never
Student PII or user data✗ Never
Source code or file contents✗ Never
Network traffic or logs✗ Never

Appendix · Provider scope

What's in scope for the pilot.

Anthropic / Claude

Claude Code, API calls, agents. Primary provider for the pilot.

OpenAI / Azure OpenAI

Supported. Add after initial inventory is complete.

Salesforce AI (Einstein, Agentforce)

Credit-licensed, not direct token consumption. Out of scope.

Other providers

Google, Cohere, Mistral, etc. Add as needed post-pilot.