$AgentInSight: Declared Is Not Deployed---Reconciling Agent Tool Governance\\ with Signed Provenance and Tamper-Evident Audit$
Abstract
AI-agent governance rests on \emph{declared} artifacts---manifests, consoles, registry entries---which may not reflect the live deployed tool surface. We present AgentInSight, a provenance layer that enforces tool calls against Ed25519-signed manifests below the SDK layer (failing closed), records agent and tool activity as SHA-256 hash-chained canonical events, and reconciles the declared surface against live connection metadata and pre-authentication protocol enumeration. AgentInSight combines fail-closed enforcement, tamper-evident audit, and declared-versus-deployed reconciliation, which sandboxes and governance platforms do not. In a case study on one organization's infrastructure---not a census---reconciliation found the project's default outbound MCP connection unauthenticated; a server registered for one declared tool exposing 59 under disjoint names; and a world-writable store of third parties' content on the same server---all pre-authentication, credential-free. A rule set for content-level injection detection reached 100\% specificity at 68\% sensitivity on a hand-authored probe set---zero false positives, one attack in three missed---which is why we locate control at what an agent is provably permitted to reach rather than at content inspection. Enforcement is an attribution backstop: it raises in-process bypass cost without eliminating it.