InvGate Asset Management now tracks certificates, AI agents, automation workflows, and scripts as native Configuration Items (CIs). Each one carries the ownership, lifecycle fields, alerts, and change history already applied to hardware and software records. The components that run daily operations without appearing in any inventory now have a place in one.
These four CIs are a starting point rather than the full definition of a digital asset. This article covers what a digital asset inventory is, what each of the four holds, and how change governance turns an inventory into evidence.
We introduced these capabilities at ENVISION'26, our global user conference. Explore everything else we announced!
What a digital asset inventory is
By digital asset inventory, we mean a record of the non-physical components a team owns, operates, and answers for, covering what exists, who owns it, when it last changed, and when it needs review. The four CIs in this release are part of that record rather than the whole of it, and most organizations keep the rest in spreadsheets, wikis, or nowhere at all.
A complete digital asset inventory reaches every component an IT team is accountable for that has no physical form:
- Domains.
- Access keys and other secrets.
- Service accounts and machine identities.
- Cloud resources and software subscriptions.
- Data pipelines and scheduled jobs.
- Software bots.
It's important to note that the term carries other meanings outside IT operations. In Marketing and Media, for instance, it refers to the image, video, and brand files. Meanwhile, in Finance it refers to cryptocurrency and tokenized instruments. Neither sense applies to what this article covers.
Why certificates, AI agents, workflows, and scripts come first
The four CIs were prioritized on consequence. Each one already breaks something measurable when nobody owns it, and each one already comes up when someone outside the team starts asking questions.
A certificate fails on a schedule known from the day it is issued and still causes unplanned outages, because that date lives in a calendar instead of a record with an owner attached. An AI agent with no registered owner becomes an audit finding the moment a regulator asks what is running. A workflow or a script with no change record leaves a business process that nobody on the team can fully explain.
The new family InvGate Asset Management now tracks
Each CI is native, with its own fields, its own lifecycle, and its own place in the asset record alongside hardware, software, and every other configuration item type. The records arrive shaped for the kind of asset they describe.
Certificates
Certificates fail on a known schedule and still cause outages, because the expiry date usually lives outside the systems that track everything else. Secure Sockets Layer and Transport Layer Security (SSL/TLS) certificates are trackable as Configuration Items, holding:
- Domain.
- Issuer.
- Expiry date.
- Renewal status.
- Responsible team.
Alerts fire ahead of the expiry date. A hospital IT team holding 45 certificates as CI records, each with an expiry date and an owner, is warned 60 days out and renews with time to spare, with a record of who approved the renewal and when.
AI agents
AI agents running in cloud or hybrid environments can be registered as Configuration Items, with an owner, a stated purpose, the systems they connect to, the environment they run in, and a review date. Registration is manual, so an agent enters the inventory when someone puts it there.
That matters most when the question comes from outside the team. A Financial services firm preparing for an AI governance audit pulls the AI agent and answers what is running and who owns it in minutes, with connected systems and last-reviewed dates attached to every record.
Automation workflows
Automation workflows come in two kinds, and the distinction is what makes tracking them worth the effort:
- Deterministic compliance workflows, which have to execute the same validated way every time for audit and regulatory reasons, and have to leave evidence that they did.
- Auto-remediation workflows, which fire in response to a detected issue, such as a certificate renewal or a correction for a known error condition.
Both are trackable as CIs, whether they run on InvGate Asset Management's own automation engine or on an external tool connected through an API. Each one gets an owner, a change record, and a version you can point at, which is what a compliance workflow needs in order to be certified in the first place.
Scripts
Scripts used in IT operations, for deployment, maintenance, and configuration, can be registered as CIs. That turns a file passed informally between teams into a record with a name, an owner, and a date of last change.
The value shows up in the questions that currently have no good answer. Which scripts are in use, who wrote the one running in production, and when it was last touched all become lookups instead of a thread in a chat channel.
Change governance in InvGate Asset Management
An inventory records what exists. Governance adds the evidence of who changed what and when, and that evidence is what an auditor asks for.
Audit evidence on every configuration change
Evidence capture is live on database Configuration Items, where a change to a critical property triggers a step that records the actual author, the effective date, and the reason behind it. That step is the model the digital assets follow as governance extends across them.
A change manager documenting that an automation workflow was modified under an approved change request finds that modification in the CI change history, with a timestamp, the user who made it, and a link to the request. The audit trail is a property of the record rather than something assembled afterward.
How this connects to CI connections
Change evidence answers what happened to one record. Connections answer what else that record touches, and the two together are what make a Configuration Item useful during an incident or an audit.
CI connections, the structured relationship layer that sits at the CI level, carries that second half. A certificate links to the service that depends on it, a workflow links to the systems it acts on, and working out what else an incident touches stops being guesswork.
Where the digital asset family is going
The four assets described here are the first of a longer list. The direction from here covers domains, jobs and pipelines, secrets and metadata, and eventually bots.
Automatic discovery is the other direction. AI agent registration is manual today, and moving toward discovery depends on what each platform exposes for that purpose, which is uneven across the market right now.
Conclusion
Certificates, AI agents, automation workflows, and scripts run production work every day without appearing in most asset inventories. Tracking them as native Configuration Items in InvGate Asset Management gives each one an owner, a lifecycle, alerts where they apply, and a change history that holds up under an audit.
The inventory answers what exists, and change governance answers who changed it and when. You can try both against your own environment with a 30-day free trial, or talk to Sales to work through how the new family map to what you already track.
Frequently Asked Questions
What counts as a digital asset in IT operations?
Any component the team is accountable for that has no physical form, which reaches well beyond the four CIs covered here into domains, secrets, data pipelines, and service accounts. The term means something different in media libraries and in finance, and neither of those senses applies in an IT context.
Why track a certificate as a Configuration Item?
Configuration Item status gives a certificate an owner, a review schedule, a change history, and relationships to the services that depend on it. It also makes the expiry date something the platform can alert on rather than something a person has to remember.
What is the difference between Change Governance and Change Management?
Change Governance refers to the audit evidence attached to a configuration change, showing what was modified, by whom, and when. Change Management refers to the Service Management process for requesting, reviewing, and approving a change before it happens.