Software and AI Agent Identity and Authorization
Sustainable Future Tech’s response to the NIST National Cybersecurity Center of Excellence concept paper on accelerating the adoption of software and AI-agent identity and authorization, proposing execution-layer governance as a complementary architecture for controlling consequential AI-enabled actions.
From Agent Identity to Execution Authority
This response argues that identity, authentication, and authorization are necessary foundations for secure AI-agent systems, but are not sufficient by themselves to govern actions that change operational state.
The submission identifies the central architectural problem as execution authority: determining whether a specific AI-enabled action remains authorized and admissible at the point where that action is about to be executed.
To address that problem, the response proposes an integrated governance architecture based on the Runtime Governance Architecture (RGA), the AI Governance Control Plane (AGCP), and the Practitioner’s Blueprint for Secure AI (PBSAI). Together, these components are presented as a governance-first reference model for deterministic validation, execution-bound authorization, cross-domain policy enforcement, and evidence-linked accountability.
Identity Is Necessary. Execution Governance Is the Next Layer.
The response distinguishes traditional identity and access control from the additional governance required when AI-enabled systems can initiate actions with consequential operational effects.
The submitted architecture treats AI-generated operational outputs as proposed actions that should pass through an independent governance layer before consequential execution is authorized.
- Probabilistic reasoning is separated from deterministic execution authority.
- Authorization is evaluated against the specific action and the relevant current context.
- Governance artifacts preserve evidence, policy references, and decision history.
- Control-plane invariants operate independently of configurable policy logic.
- Execution decisions are designed to be deterministic, replayable, and auditable.
An Integrated Model for Policy, Governance, and Execution
The response connects three SFT architecture and governance components into an integrated model for policy compilation, runtime enforcement, secure AI operation, and multi-domain governance.
Runtime Governance Architecture (RGA)
Provides the general architectural framework for translating governance requirements into consistent, machine-evaluable constraints and preserving governance semantics across systems and execution environments.
AI Governance Control Plane (AGCP)
Provides deterministic execution-layer governance, including action representation, context binding, policy evaluation, authorization decisions, invariant enforcement, and evidence-producing lifecycle controls.
Practitioner’s Blueprint for Secure AI (PBSAI)
Provides the broader secure-AI governance ecosystem linking identity, infrastructure, security, data, compliance, agent behavior, provenance, and structured evidence flows.
Execution Semantics & Safety Invariants
Establishes correctness properties governing action evaluation, authorization, lifecycle state, ordering, replayability, and execution behavior at consequential system boundaries.
Identity and Authorization Across the Action Lifecycle
The contribution addresses the NCCoE identity and authorization problem while extending those concepts toward execution-time governance of AI-enabled actions.
Identification
Binds workload identity and task context to the individual action rather than relying only on a generalized identity associated with an agent or service.
Authentication
Extends authentication toward cryptographic workload identity, continuous validation, and binding of authenticated identity to operational action context.
Authorization
Proposes execution-bound authorization in which policy, authority, and contextual conditions are evaluated in relation to the action rather than treated only as a static access grant.
Delegation & Human Authority
Connects delegated machine action to originating human or organizational authority and preserves evidence supporting verification of action performed on behalf of that authority.
Auditing & Non-Repudiation
Uses structured governance artifacts and append-only records to preserve traceability across proposal, evaluation, authorization, execution, and evidence.
Adversarial & Prompt-Injection Risk
Treats AI-generated operational outputs as potentially untrusted and subjects consequential actions to independent governance validation before execution.
Five Areas for Further Development
The response concludes with recommendations for future guidance, demonstrations, reference architectures, and standards-related work.
Proposed NCCoE Demonstration
The contribution recommends evaluating execution-layer governance through a reference implementation involving AI agents, enterprise identity, policy systems, and a deterministic governance control plane.
Evaluation Scope
AI agents integrated with enterprise systems, standards-based identity, policy mechanisms, and execution-layer governance.
Evaluation Metrics
Governance enforcement coverage, policy compliance, authorization integrity under adversarial conditions, and evidence completeness.
Test Scenarios
Prompt injection, privilege escalation, cross-domain policy conflicts, and multi-agent orchestration.
Collaboration Areas
Reference implementation development, governance evaluation methods, governance-artifact standardization, workshops, working groups, and pilot programs.
Status and Attribution
This page documents a technical response submitted by John M. Willis on behalf of Sustainable Future Tech, Inc. to a NIST NCCoE concept-paper process. The architectural concepts and recommendations described here are contributions for consideration and evaluation. They should not be interpreted as NIST guidance, NIST endorsement, or an adopted NCCoE reference architecture.