Skip to main content
NCCoE Concept Paper Response · Submitted March 4, 2026

Accelerating the Adoption of Software and AI Agent Identity and Authorization

A 12-page technical response proposing Attested Governance Artifacts as the cryptographic proof for AI agent identity binding, continuous runtime authorization, and offline-verifiable audit evidence.

Download PDF· 12 pages
Overview

What this submission covers

This submission responds to the NCCoE concept paper on AI Agent Identity and Authorization by mapping Attested Governance Artifacts across six technical categories. It demonstrates how sealed policy artifacts, signed governance receipts, and tamper-evident continuity chains address identity binding, runtime authorization, and non-repudiation for autonomous AI agent systems.

Topics Addressed

Six technical categories

Section 1

Use Cases & Scenarios

Threat landscape for autonomous AI agents including credential theft, phantom execution, and retroactive fabrication attacks.

Section 2

Identification & Binding

Cryptographic identity binding through sealed policy artifacts with Ed25519 signatures and SHA-256 continuity chains.

Section 3

Authentication Mechanisms

Runtime authentication via integrity measurements at every tool call. Session-initiation checks alone leave a wide exposure window.

Section 4

Authorization Frameworks

Sealed policy artifacts define the permitted operations; the gateway renders and seals a permit-or-deny decision, and effecting it is a per-deployment integration point.

Section 5

Auditing & Non-Repudiation

Tamper-evident continuity chains and offline-verifiable evidence bundles built for air-gapped audit environments.

Section 6

Prompt Injection Defenses

Behavioral drift detection through runtime measurement of tool-call patterns against sealed baseline profiles.

Section 7

Proposed Lab Demonstration

A four-phase demonstration protocol for the NCCoE lab environment covering artifact creation and sealing, runtime measurement and sealed decisions with drift detection, evidence bundle generation, and offline verification by anyone holding the key.

Phase 1Seal & Attest
Phase 2Capture & Measure
Phase 3Bundle & Export
Phase 4Verify Offline
Standards Referenced

Anchored in NIST guidance

NIST SP 800-207 (Zero Trust)NIST SP 800-204 (Microservices Security)NIST SP 800-218 (SSDF)NIST AI RMF 1.0