Identity — Certificates, Registry, and Archetypes

Identity is the first pillar of the Nomotic AMP and the starting point for every governed agent. The principle is simple: you cannot govern an agent you cannot identify. Identity solves that.

The agent registry

The registry is the authoritative list of every agent your organization has registered with Nomotic. It shows each agent’s name, certificate status, zone, archetype, and trust score. Think of it as your organization’s official agent roster.

Every agent in the registry has a certificate. Every agent without a certificate is ungoverned.

Agent certificates

When you register an agent, Nomotic issues it a cryptographically signed certificate. The certificate establishes who the agent is, what it is authorized to do, and binds its identity to the governance policies in effect at the time of issuance.

Certificates use Ed25519 signatures and are hash-bound to your governance configuration. Just as SSL certificates authenticate websites, agent certificates authenticate AI agents — providing verifiable proof of identity that persists across every action the agent takes.

You can view, renew, and revoke certificates from Identity → Certificates. Revoking a certificate immediately blocks that agent from submitting governance evaluations.

Archetypes

An archetype is a governance template that calibrates evaluation for a specific type of agent. Rather than configuring 20 dimension weights from scratch, you pick an archetype and governance is pre-calibrated for that role.

Nomotic includes 25 built-in archetypes covering roles like financial analyst, customer support, healthcare assistant, HR operations, legal research, data pipeline, and more. Each archetype sets appropriate thresholds for the sensitivity of that domain.

You assign an archetype when registering an agent. You can change it at any time — the new archetype applies to all evaluations from that point forward.

Nomotic Radar

Radar scans your organization’s infrastructure for AI agents operating without governance — unregistered, uncertified, and outside policy. Shadow agents are one of the fastest-growing enterprise security risks. Radar surfaces them so you can bring them under governance or make an informed decision to retire them.

Radar is available on Team and above plans. Results appear in Identity → Radar.

Was this article helpful?

On this page