**Monika Aggarwal** (0:04)
You are listening to Agent Sense, the podcast where we keep AI simple, practical, and grounded. I'm your host, Monika Aggarwal. My co-host, Frank Chavez, is on vacation, so I'm hosting this episode by myself.
This is episode 8, Governed Catalog of AI Assets.
Today, we will talk about day 3 and day 4 of implementing multi-agent AI architecture in the enterprise. While it's true what is possible, production creates harder questions. What has already been built? Who owns it? What data does it touch? How was it tested? Can it be trusted and reused? Without clear answers, enterprises risk agent sprawl, duplicate builds, and unclear ownership. To help us talk through this, we have Jyotsna Narayanan with us. Jyotsna is a Principal Product Manager for WatsonX Orchestrate at IBM. Jyotsna, in your role, as organizations move from one agent to an agentic enterprise, what problems are you seeing with how agents, tools, and MCP servers are being created and reused?
**Jyotsna Narayanan** (1:21)
Thank you for having me, Monika. As organizations move from one agent to an agentic enterprise, the problem is no longer only building agents. The problem becomes how to manage the growing number of agents, tools, and MCP servers across the enterprise. Business teams may build agents for their own workflows.
IT may build similar assets. Partner may bring their own tools or accelerators. Without a shared standard, these assets can become hard to find, even hard to trust and reuse. Builders need to know what already exists, who owns it, what system it connects to, what data it touches, how it was tested, whether it's approved for reuse. Without that visibility, organizations risk agents' sprawl, duplicate work, unclear ownership, and more technical debt. As organizations scale, that duplication doesn't just add up, it compounds. A banking CIO told me recently that I want people building agents only when it's absolutely necessary. That's the point.
Because building from scratch, instead of reusing what already exists, it's 45% more time, effort, and more importantly, token spend. So the real problem isn't more agents, it's a governed catalog.
A centralized, curated, trusted library people can check before they build anything new.
**Monika Aggarwal** (3:11)
That is a very eloquent way of framing the problem or the tension which organizations have right now. What should a governed catalog show beyond the name and description of an agent or a tool or an MCP server?
**Jyotsna Narayanan** (3:30)
Sure.
It should show more than a name and a description. It should show clear ownership, version, approval status, test results, security posture, compliance and known risks. For builders, this information is important because reuse is not only about finding an asset, it is about knowing if the asset is safe, current, tested and ready for reuse. The catalog should help builders answer simple questions such as, can I use this asset? Can I trust it? What are the risks?
**Monika Aggarwal** (4:14)
So Jyotsna, as a builder, I am building my agents, multi-agent architecture, and there is a governed catalog, as you say, of these assets. How would I know that this asset is trusted and I can reuse it?
**Jyotsna Narayanan** (4:34)
Right.
So builders need a practical evaluation approach before reusing AI assets. They should look at journey success metrics, latency, reliability, resilience to teaming attacks, compliance, and other metrics. They should also understand how the asset was tested and what approvals are required before use. Evaluation references like OASP Talk 10, that stands for Open Worldwide Application Security Project, help teams think about common risks such as prompt injection, sensitive data exposure, insecure outputs, and excessive agency. Secure AI, also known as COSI, brings a broader view of secure AI development and deployment practices, both for agents and MCP servers. These references give builders a more disciplined way to assess reuse readiness before an asset is actually adopted in real workflows.
So the governed catalog becomes a control plane for safe reuse.
**Monika Aggarwal** (5:49)
Brilliant. So what are the main ways a governed catalog can help an organization reduce agent sprawl and improve enterprise adoption?
**Jyotsna Narayanan** (6:03)
Sure.
I can provide four practical ways. First, governed catalog improves visibility. Builders can see what agents or other AI assets already exists across their enterprise. Second, it supports trusted reuse.
Builders can review testing, approval status, and risk before adopting an asset. Number three, it creates accountability. Each asset has an owner, version, lifecycle status, and a clear auditable path. Number four, it helps manage risk over time. Agents and tools are not static. They need monitoring, updates, testing, and retirement when they are no longer safe or useful. This helps enterprises move from scattered agent builds to a more governed and reusable operating model.
2 more minutes of transcript below
Thousands of transcripts fetched by people building searchable podcast archives
Try it now โ copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/YOUR_EPISODE_ID