Blog

2026.09.20

AI Agent Registry: Xây Control Plane trong 90 ngày

AI Agent Registry: Xây Control Plane trong 90 ngày

AI Agent Registry không chỉ là danh sách tên agent. Đây là hồ sơ quản trị nối mục đích kinh doanh, technical owner, business sponsor, danh tính, quyền, kênh công bố, dữ liệu phụ thuộc, quyết định thay đổi, tạm dừng, ngừng sử dụng và bằng chứng. Khi PoC phát triển riêng lẻ theo phòng ban, cùng một agent thường được sao chép sang nhiều môi trường, quyền vẫn còn sau khi người tạo chuyển việc và không ai chắc instance nào đang chạy production. Bài viết này đưa ra cách làm vendor-neutral cho doanh nghiệp tại Việt Nam, Thái Lan và nhiều địa điểm: mô hình dữ liệu, RFP, PoC, kế hoạch 90 ngày, quản lý thay đổi, suspension, retirement và audit evidence.

Kết luận: tách sổ đăng ký khỏi AI control plane

Áp dụng sáu nguyên tắc:

  1. Registry là system of record về trách nhiệm hiện tại; control plane thực thi và quan sát quyết định ở runtime.
  2. Tách technical owner khỏi business sponsor và luôn có người chịu trách nhiệm kinh doanh cho production agent.
  3. Ghi identity, quyền, channel và data dependency theo instance—development, test, production—không chỉ theo tên logic.
  4. Tách discoverable, available, deployed, pinned và machine-to-machine invocation.
  5. Thiết kế change, suspension và retirement ngay khi đăng ký, gồm ngày review, kill path và giữ bằng chứng.
  6. Trong 90 ngày đầu, chứng minh vòng đời từ discovery đến retirement thay vì ép toàn doanh nghiệp dùng một sản phẩm.

Tài liệu Microsoft hiện tại định vị Agent 365 là registry/control plane hợp nhất để tìm và quản lý agent, còn Microsoft Entra Agent ID là nền tảng identity và access control. Registry trong Microsoft 365 admin center cũng tập hợp agent của Microsoft, đối tác bên ngoài, nội bộ công bố và người tạo chia sẻ. Hướng đi này hữu ích, nhưng tiêu chuẩn của bên mua không nên bị giới hạn bởi portal của một vendor. Một từ vựng chung phải mô tả được cloud khác, on-premises, API sản xuất, RPA, MCP server và business SaaS.

AI Agent Registry: Xây Control Plane trong 90 ngày - figure 1

Vì sao quản lý AI Agent nên bắt đầu từ registry

Application inventory truyền thống tập trung vào tên hệ thống, server, phòng ban, hợp đồng và liên hệ sự cố. Những trường đó không cho biết capability thực của agent. Agent chỉ soạn văn bản khác rất xa agent có thể gửi email, ghi ERP, dùng quyền thay mặt user hoặc tự chạy ban đêm.

Microsoft mô tả agent là ứng dụng hiểu environment/context, ra quyết định và dùng tool để đạt mục tiêu. Thành phần chính gồm model, orchestration, memory và tools như web search, database, API và file system. Vì vậy đối tượng đăng ký không chỉ là giao diện chat mà còn phải nối orchestrator, runtime identity, tool, memory, knowledge source, channel và downstream system.

Không nhìn thấy thì không thể kiểm soát

Các dạng shadow agent phổ biến gồm agent do nhân viên chia sẻ qua Teams hoặc intranet; service identity và connector còn lại sau PoC của SIer; RPA thêm LLM nhưng không đăng ký là hệ thống AI; child agent dưới orchestrator; job được cho là đã ngừng nhưng API key và schedule còn chạy; dev/UAT/prod dùng cùng display name khiến user nhầm lẫn.

Registry của Microsoft phân biệt agent không có owner và unmanaged agent. Bài học thực tế không phải hứa inventory chính xác tuyệt đối ngay ngày đầu mà là duy trì chu trình discover → provisional register → confirm accountability → connect controls → periodic reconciliation.

Danh sách identity không phải business registry

Microsoft Entra có thể liệt kê agent identity object và agent dùng service principal, kèm status, Object ID, Blueprint App ID, owner/sponsor, permission, audit log và sign-in log. Business registry còn cần purpose, process, audience, expected value, prohibited use, data classification, legal basis và fallback procedure.

Không nên dùng identity directory làm system of record duy nhất. Hãy liên kết hai hệ thống bằng stable identifier. Agent chưa có identity vẫn được provisional register với identity status = missing. Ngược lại, identity đã tồn tại không đủ để production approval nếu chưa xác nhận purpose và sponsor.

Mô hình dữ liệu tối thiểu cho AI Agent Registry

Quá nhiều trường bắt buộc sẽ khiến registry nhanh lỗi thời. Tách mandatory field, conditional field và evidence link; nêu rõ field owner và nguồn sync.

NhómTrường tối thiểuCâu hỏi quản trị
IdentificationRegistry ID, name, instance ID, environment, versionĐây là runtime instance nào?
Purposebusiness purpose, process, audience, prohibited useVì sao cần và không được làm gì?
Accountabilitytechnical owner, business sponsor, operator, delegateAi đổi kỹ thuật, ai quyết định tiếp tục?
Publicationchannel, audience, discoverable/deployed/pinnedAi tìm thấy và dùng được?
Identityprincipal, authentication, delegated/autonomous, secret storeHoạt động dưới thẩm quyền của ai?
Authorizationtool, action, resource, scope, expiry, approvalĐọc hoặc thay đổi được gì?
Datasource, classification, storage, border, retention, training useDữ liệu nào vào memory hoặc output?
Dependenciesmodel, orchestrator, MCP/API, downstreamMột thay đổi lan tới đâu?
OperationsSLO, monitoring, correlation ID, on-call, runbookAi phát hiện và xử lý bất thường?
Lifecycleregistration, approval, review, suspension, retirementKhi nào review và dừng?
Evidencedesign, approval, test, permission delta, logsCó tái dựng được quyết định không?

Tách Registry ID và instance ID

Một business agent có thể có dev, integration, UAT, production và DR. Mục đích giống nhau nhưng quyền và data khác nhau. Registry ID đại diện logical product/use case; instance ID đại diện runtime. Ví dụ agent tra cứu mua hàng là AGR-PROC-017, instance production tại Thái Lan là AGR-PROC-017-PRD-TH01. Object ID, application ID và workload identity gắn với instance.

Tách technical owner khỏi business sponsor

Mô hình Microsoft Entra Agent ID phân biệt owner—quản trị kỹ thuật về configuration, credential và operation—với sponsor, người chịu trách nhiệm về purpose, access review, renewal, retention và removal. Tài liệu hiện tại nói agent identity và blueprint cần ít nhất một sponsor, còn owner là optional. Owner có thể là user hoặc service principal nhưng không phải group; một số loại group có thể làm sponsor.

Vai tròTrách nhiệm chínhKhông nên tự phê duyệt
Business sponsorpurpose, audience, budget, continuation, residual riskcredential và production configuration
Technical ownerconfiguration, identity, permission, monitoring, recoverybusiness necessity của chính mình
Data ownerdata use, classification, retention, transfer, deletiontoàn bộ production approval
Security/ITstandard, exception, access review, incidentbusiness value
Service operatordaily monitoring, triage, evidencescope expansion hoặc high-risk change

Ghi delegate, succession deadline và điều kiện auto-suspend khi thiếu accountability. Nếu dùng sponsor group, vẫn chỉ định người đại diện có thể quyết định. Microsoft lưu ý rằng dynamic-group membership change có thể cần tới 24 giờ trước khi authorization check thành công; emergency succession không nên phụ thuộc duy nhất vào group sync.

Tách publication channel khỏi permission

Teams, Outlook, Copilot, SharePoint, web, mobile, API và batch là bề mặt user hoặc system tiếp cận agent. Cùng một channel vẫn khác rủi ro khi audience, tenant, country, device hoặc thời gian khác nhau.

  • Discoverable: nhìn thấy trong search/catalog.
  • Available: user đủ điều kiện tự thêm.
  • Deployed: admin phân phối cho audience.
  • Pinned: được đặt ở vị trí nổi bật.
  • Callable: API hoặc agent khác gọi được.

API-only không phải “không có channel”; đăng ký là A2A/API. Với child agent, giữ caller allowlist, delegated context, rate limit và recursion control.

AI control plane phải thực thi gì ở runtime

Registry chính xác vẫn không tự chặn API call quá quyền. Control plane dùng registry để nối runtime identity, policy, tool, data boundary, observability và revocation. Nó có thể là tổ hợp identity provider, API gateway, secret manager, policy engine, SIEM và approval workflow chứ không nhất thiết là một sản phẩm.

AI Agent Registry: Xây Control Plane trong 90 ngày - figure 2

Identity riêng và least privilege

Mẫu least privilege của Microsoft khuyến nghị mỗi agent có dedicated identity, named owner/sponsor và approver, đồng thời ghi purpose, approved data, tool dependency và environment. Scope phải theo resource, data và action; tool chưa review và cross-tenant path bị deny mặc định.

Đừng ghi “truy cập ERP”. Hãy ghi:

TrườngVí dụ tốtCần tránh
Actionpurchase_order.readdùng ERP
Resourcepháp nhân Thái Lan, Plant 01, supplier được duyệttoàn doanh nghiệp
Dataamount, due date, item; loại bank accountdữ liệu mua hàng
Modeautonomous read; human-approved writekế thừa mọi quyền user
Duration90 ngày, review theo quývĩnh viễn
Evidencepolicy ID, approval, test resultđồng ý qua email

Với thao tác đặc quyền, dùng short-lived token, JIT hoặc action-specific approval. Phải đánh giá aggregate effective permission vì nhiều role hẹp có thể kết hợp thành capability end-to-end rất rộng.

Allowlist tool và action

“MCP enabled” quá rộng. Đăng ký server, tool, action, input schema, resource, volume, timeout, retry, idempotency và human approval. Search agent không cần delete. Ticket agent có thể có create/update nhưng deny delete/admin. Bulk update, external transfer, payment và privilege change cần gate riêng.

Downstream system phải revalidate identity và scope mỗi lần, không chỉ tin orchestrator. Văn bản AI nói “đã được duyệt” không phải authorization evidence. Dùng một correlation ID để nối policy decision, API enforcement và result.

Audit trail không chỉ là conversation log

Evidence cần requester, agent identity, on-behalf-of user, role, scope, tool, action, resource, policy version, approval, outcome, correlation ID và timestamp. Giữ mọi prompt vô hạn sẽ tạo rủi ro privacy và secret. Tách structured event cần cho reconstruction khỏi nội dung hội thoại nhạy cảm, với purpose, masking, retention và access rõ ràng.

Thiết kế bốn lớp suspension

  1. Discovery: ẩn khỏi user mới.
  2. Invocation: từ chối session, API call và schedule mới.
  3. Privilege: revoke token, rotate key, remove role và downstream allowlist.
  4. Data/Lifecycle: xử lý queue, memory, evidence, output, legal hold và deletion.

Phân biệt incident suspension có thể đảo ngược với planned retirement không đảo ngược. Incident ưu tiên disable nhanh; retirement ưu tiên migration dependency và bảo toàn evidence.

Roadmap 90 ngày cho AI agent inventory

90 ngày là mốc khởi động continuous governance, không phải cam kết integration hoàn hảo.

Ngày 0–15: discovery và provisional registration

IT, security, data, procurement và business team thống nhất định nghĩa. Bao gồm hệ thống tự lập kế hoạch và gọi tool, cùng execution unit được agent khác gọi, không chỉ chatbot. Nguồn discovery gồm identity directory, cloud app registration, API gateway, secret store, SaaS console, network log, contract/expense, browser extension, RPA, MCP config, repository và attestation của phòng ban. Kết quả tự động đi vào discovered/unverified.

Deliverable gồm registration standard, minimum fields, RACI, provisional list, impact tier và missing-owner queue. Ưu tiên ownerless agent có high privilege, external sharing, confidential data, payment hoặc delete.

Ngày 16–30: xác nhận accountability và risk tier

Gán technical owner, business sponsor và xác nhận purpose, audience, channel, data, tool, environment. Giao agent ownerless cho temporary custodian; suspend nếu không có sponsor trước deadline.

TierVí dụControl tối thiểu
T1tìm và tóm tắt thông tin công khaiterms, citation, basic log
T2tìm nội bộ và soạn thảoidentity, data boundary, owner/sponsor, access review
T3ghi có giới hạn vào business systemdedicated ID, action allowlist, approval, negative/stop test
T4tự động ảnh hưởng cao hoặc đổi quyềnindependent approval, JIT, enhanced monitoring, exercise, executive risk acceptance

Ngày 31–45: nối registry và identity

Map instance ID với Object ID, service principal, workload identity và API client. Lập kế hoạch identity cho agent còn thiếu và loại shared credential dần. Không dùng chung identity giữa development và production.

Sync tự động các fact khách quan như state, last sign-in, credential expiry, role, owner và channel. Business purpose, prohibited use, sponsor decision và residual risk vẫn cần human approval. Gán field owner để sync không xóa evidence thủ công.

Ngày 46–60: hiển thị permission, channel và dependency

Tạo graph từ agent tới tool, data source và downstream system, gồm user delegation, managed identity, service account, webhook, batch và queue. Bắt đầu bằng read/write/admin rồi phân rã T3/T4 theo action/resource. Xác nhận discoverable, available, deployed, pinned, callable, audience và external sharing; kiểm tra retirement dừng được API và schedule chứ không chỉ ẩn catalog.

Ngày 61–75: chứng minh control plane và stop path

Chọn agent low/medium/high risk, áp runtime policy từ registry. Test forbidden resource, expired approval, wrong channel, other tenant, excessive volume, duplicate, missing owner và revoked credential chứ không chỉ success case.

Dùng hướng dẫn nghiệm thu AI Agent để cấu trúc expected, abnormal, approval và evidence case. Kết hợp với vận hành API cho AI Agent về monitoring, idempotency, retry và rate limit. Bài này tập trung vào registry toàn doanh nghiệp và lifecycle, không lặp lại kiểm thử chất lượng câu trả lời.

AI Agent Registry: Xây Control Plane trong 90 ngày - figure 3

Ngày 76–90: thiết lập nhịp quản trị và KPI

Hàng tuần review new registration, missing owner, expired access, failed sync và high-risk change. Hàng tháng cung cấp cho sponsor dữ liệu necessity và usage. Review access theo quý hoặc khi thay đổi lớn. KPI gồm tỷ lệ production agent có unique identity; valid owner/sponsor; quyền có expiry và evidence; action trace được end-to-end; thời gian từ phát hiện ownerless đến containment; thời gian từ disable request đến invocation denial/token revocation; số agent hết hạn/không dùng được retire; và tỷ lệ major change hoàn tất review/retest.

Yêu cầu RFP cho AI Agent Registry

Đặt yêu cầu theo capability và deliverable kiểm thử được, không khóa vào tên sản phẩm.

  1. Discovery coverage: cách tìm và deduplicate Microsoft, SaaS khác, custom, on-premises, API-only, service-principal, identity-less và parent/child agent; nêu source of truth và delta detection.
  2. Data model/API: tách logical agent/instance, extensible field, history, evidence link, import/export, API, webhook, change event, stable ID và audit retention sau khi xóa.
  3. Accountability: trường riêng cho technical owner, business sponsor, data owner, delegate; phát hiện workforce change; ownerless alert; deadline; group assignment; segregation of duties; recertification.
  4. Identity/permission/channel: liên kết agent identity, service principal, workload identity, delegated user, credential, role, scope, tool action và discoverable/deployed/pinned/callable.
  5. Lifecycle/change: draft, review, approved, active, suspended, retiring, retired; phát hiện riêng model, prompt, tool, source, permission và audience change.
  6. Audit/evidence: ai đổi field nào từ gì sang gì, khi nào, ai duyệt; correlation với runtime log; SIEM export, retention, masking, legal hold.
  7. Stop/retire/exit: session deny, schedule stop, token revoke, credential rotation, role removal, queue isolation, webhook removal, manual stop khi vendor outage, data return và deletion proof.

Yêu cầu sample logical/instance schema, connector scope/permission, demo ownerless và identity-less discovery, action-level allow/deny log, timed revocation test, portable export, RTO/RPO và toàn bộ license assumption. Preview và license thay đổi; vendor phải chứng minh trên tenant và hợp đồng của bên mua.

Tiêu chí PoC: kiểm thử vòng vận hành, không chỉ màn hình danh sách

PoC phải hoàn thành cả vòng: discover unmanaged agent; provisional register; gán owner/sponsor riêng; nối dedicated identity và expiring permission; publish chỉ qua approved channel/audience; chạy allowed/denied action và trace downstream; phát hiện model/tool change và quay lại review; mô phỏng sponsor rời công ty; emergency-disable session/token/queue/schedule; đối soát xóa quyền và giữ retirement evidence.

Đánh giá field completeness, sync latency, false positive/negative, permission delta, suspension time, audit reconstruction và operational effort. Test data cần duplicate name, deleted owner, missing identity, multi-instance, another tenant, shared credential và expired approval.

Quy tắc change, suspension và retirement

Trigger cần review lại

  • Chỉ đổi prompt, capability không đổi: owner review và regression test.
  • Đổi model: quality, safety và multilingual retest.
  • Thêm tool/action: permission, threat, audit và revocation review.
  • Đổi data source/storage: data-owner, privacy và transfer approval.
  • Mở rộng audience/channel/country: sponsor, security và legal review.
  • Tăng autonomy, volume, amount hoặc asset scope: xử lý như use case mới.

Trigger suspension

Thiếu owner/sponsor, lộ credential, privilege tăng bất thường, mất audit, forbidden action thành công, rò rỉ dữ liệu lớn, hết hợp đồng và overdue recertification là candidate cho automatic/emergency suspension. Quy định người quyết định và threshold ngay khi đăng ký.

Tiêu chí hoàn tất retirement

Dừng channel, shared link, endpoint, schedule; revoke identity, token, secret, certificate, role, membership; tháo tool, MCP, webhook, queue, downstream allowlist; xử lý memory, vector store, cache, output theo retention; thông báo parent/child dependency và user; giữ approval, last-use và deletion proof; xác nhận discovery scan sau không phát hiện lại.

Lỗi triển khai thường gặp

  • Xem spreadsheet làm một lần là đích đến thay vì sync fact và xử lý expiry liên tục.
  • Giữ creator làm owner vĩnh viễn dù nhân viên chuyển việc hoặc supplier rời dự án.
  • Deduplicate theo display name thay vì stable ID, endpoint, credential, manifest và tool graph.
  • Cho rằng mua control plane là có governance, trong khi purpose, accountability và risk acceptance vẫn thuộc doanh nghiệp.
  • Cho rằng có log là trace được, dù thời gian, identity và correlation ID không nối conversation, orchestrator, tool và downstream API.

FAQ: quản lý và sổ đăng ký AI Agent

AI Agent Registry là gì?

Là system of record doanh nghiệp về purpose, instance, technical owner, business sponsor, identity, permission, channel, data, tool, status và evidence. Nó chi tiết hơn application inventory và mang accountability cấp cao hơn runtime log.

Có thể dùng CMDB hoặc application inventory hiện có không?

Có, nếu mô hình hóa được logical agent/instance, delegated/autonomous identity, tool action, model/prompt/memory, channel, sponsor và review trigger. Nối specialized registry cho phần mô hình hiện tại không biểu diễn được.

AI control plane khác registry thế nào?

Registry ghi cái gì tồn tại, ai chịu trách nhiệm và cái gì đã được duyệt. Control plane áp identity, permission, tool, policy, monitoring và revocation ở runtime. Dù một sản phẩm có cả hai, vẫn đánh giá hai vai trò riêng.

Owner và business sponsor có thể là một người không?

PoC nhỏ có thể kiêm nhiệm nhưng vẫn ghi trách nhiệm riêng. Production và high-risk nên tách người thay đổi kỹ thuật khỏi người xác nhận business need và residual risk, đồng thời có delegate và approver cấp cao hơn.

Agent không có identity có nằm ngoài registry không?

Không. Đăng ký là identity missing và ưu tiên remediation. Discovery đi trước identity modernization. Muốn tiếp tục production phải có dedicated identity, scoped access và tested stop path.

Nên review bao lâu một lần?

Dùng event trigger cùng fixed cadence. Quyền cao có expiry ngắn; production thông thường có thể review theo quý; owner change, tool addition, data-source change, channel expansion hoặc incident phải review ngay.

Có thể quản trị toàn bộ agent trong 90 ngày không?

Doanh nghiệp lớn thường chưa thể đầy đủ. Mục tiêu 90 ngày là vận hành definition, discovery, accountability, minimum schema, identity linkage, stop test và governance cadence; ưu tiên high-impact agent và giữ unknown item luôn nhìn thấy để cải tiến liên tục.

Kết luận: nối registry với một vận hành có thể dừng

Giá trị của AI Agent Registry không nằm ở danh sách đẹp mà ở khả năng trả lời ai chịu trách nhiệm giải trình về sự cần thiết của agent, ai sửa cấu hình, quyền và channel nào thực sự được dùng, khi nào review, và có thể dừng hoàn toàn tới đâu. Tách logical agent/instance; nối technical owner, business sponsor, identity, tool action, data, channel, dependency và evidence. Đưa dữ liệu đó vào AI control plane để thực thi least privilege, allow/deny, audit, suspension và retirement. Trong 90 ngày đầu, chứng minh một lifecycle hoàn chỉnh trên vài agent high-risk trước khi chuẩn hóa platform toàn doanh nghiệp.

TOMAS TECH có thể hỗ trợ thiết kế schema trước khi chọn sản phẩm, discovery từ identity/API/CMDB, RFP, PoC 90 ngày, cơ chế họp quản trị và kiểm thử suspension/retirement. Doanh nghiệp có thể liên hệ ngay cả khi chưa biết chính xác đang có bao nhiêu agent hoạt động.

Primary sources

Đây là hướng dẫn triển khai vendor-neutral dựa trên nguồn sơ cấp công khai. Tính năng, preview, license, giao diện và giới hạn có thể thay đổi; hãy kiểm tra tài liệu chính thức và điều khoản hợp đồng hiện hành trước khi triển khai.