The standards community is not asleep.
NIST’s AI Agent Standards Initiative and NCCoE work on agent identity
and authorization are asking whether enterprises can apply OAuth, OpenID
Connect, SPIFFE/SPIRE, and SCIM to autonomous agents. The OpenID
Foundation’s AI Identity Management community has been filing concrete
input: trust fabric, transaction tokens, workload federation,
accountability chains. CSA and others are publishing agent identity
governance frameworks that put lifecycle, sponsorship, and just-in-time
access on the table. Vendors are shipping Agent ID products into the
same conversation.
I want that work to succeed. I also want to say clearly what it is
and what it is not.
It is adjacent thinking applied to a new actor type. Extend the
credential. Extend the directory. Extend continuous access evaluation so
“robotic principals” show up in Shared Signals. That is necessary. It is
how serious industries avoid reinventing authentication from
scratch.
It is not yet a stepped-back look at the reality agents create.
Agents spawn. They delegate. They mimic humans. They pursue goals
across gateways, browsers, and side paths. They can be purpose-aligned
and still wrong. They can pass every identity check and still should not
act. Stretching the last successful identity model answers who
and can more cleanly for non-humans. It does not, by itself,
answer why and should.
That distinction is where Tamed Autonomy started for me — in the
identity world — and it is where new standards are needed if agentic
security is going to be a multi-vendor commons instead of a pile of
incompatible platforms.
Adjacent Is Useful.
Adjacent Is Not Enough.
I helped build parts of the identity industry the last time the model
broke. The pattern is familiar. First you stretch what you have. Better
ACLs. Better firewalls. Better service-account hygiene. Then you
discover the stretch has a structural ceiling, and a new layer appears
above.
We are in the stretch phase for agents.
Adjacent work (keep doing it):
- Give agents distinct, manageable identities — SPIFFE/SPIRE and
WIMSE-class workload identity, directory lifecycle, SCIM-shaped
provisioning. - Put agents on real authorization rails — OAuth/OIDC profiles, richer
authorization requests, sender-constrained tokens, on-behalf-of
patterns. - Propagate risk and session change in real time — CAEP and the OpenID
Shared Signals Framework, including non-human principals. - Harden the cooperative tool path — MCP gateways, policy at
connectors, enterprise audit on the managed channel.
Stepped-back work (barely chartered as shared
standards):
- Bind identity to declared purpose as an enforceable contract, not a
comment in a runbook. - Carry character across time — trajectory, relationships, delegation
provenance — without stuffing a JWT until it breaks. - Exchange trust as typed observations any vendor can consume, not as
a proprietary score locked in one console. - Express normative context — notice periods, trading blackouts,
clinical urgency, litigation holds — as machine-readable
constraints. - Define how identity, behavior, intent, trust, and context layers
hand off allow, deny, modulate, annotate, and escalate without one
monolithic policy engine owning the universe.
The adjacent band is crowded. The middle band is empty. Agentic
security fails in the empty band.
The Architecture: Floor,
Middle, Question
Here is the shape I want standards leaders to put on the
whiteboard.

The bottom band is the floor. Praise it. Fund it. Finish the agent
profiles.
The top line is the only question that matters when an autonomous
system is about to move money, data, or care.
The middle band is what makes the floor capable of answering the
question across vendors. Without it, every “complete agentic
security platform” is a silo with a marketing deck. With it, companies
can build different layers and still interoperate — the way federation
made identity a market instead of a single product.
Where New Standards Are
Needed
Six concrete gaps. Each one has an example. None of them is solved by
a better sub claim alone.
1. Intent declaration
contracts
What exists today: OAuth scopes, rich authorization
requests, “intent” as a vendor feature or a line in a system prompt.
What is needed: A standard, signed, amendable
purpose contract — resources, action classes, time bounds, data
classifications, delegation rights, amendment rules — that any PEP can
evaluate.
Example: An agent is allowed to “generate the Q3
sales report from CRM.” CRM reads for that purpose pass. The same valid
token mining HR for “additional context” fails as an intent mismatch.
Today that failure is a hope. It should be a protocol.
2. Character
enrichment above the name tag
What exists today: One issuer, one credential, one
lifecycle row. Vendor Agent ID. Workload SVIDs. I have argued before
that agent identity is a name tag that
needs to become character.
What is needed: Keep the token small. Standardize
how a relying party resolves purpose, behavioral trajectory,
relationships, and delegation provenance from multiple attesters — the
multi-source vision identity federation never finished for humans, now
required for agents at machine speed.
Example: An infostealer copies an agent’s credential
and memory files. Every today’s identity check still passes. Bilateral
relationship discontinuities and trajectory divergence should fail the
character layer within minutes — and that failure mode must be
expressible across products, not only inside one vendor’s “agent
ITDR.”
3. Portable trust
observations
What exists today: Proprietary risk scores.
Vendor-specific “trust” dashboards. CAEP events for session and device
change — necessary, still mostly event-triggered access
re-evaluation.
What is needed: Typed, portable trust observations —
intent compliance over time, behavior under stress, sponsorship stake,
anomaly pressure — that any trust or normative engine can consume.
Compete on how you compute. Standardize what you emit.
Example: Gateway A attests fourteen days of in-scope
behavior. Trust service B weights stress-earned history. Normative
engine C uses both without a bilateral integration project for every
pair of logos.
4. Trajectory and provenance
chains
What exists today: Logs. Three products. Three
formats. No shared notion of spawn, delegation hop, or attenuation.
What is needed: An append-only, dual-signable chain
format for what was declared versus what was done, plus lineage: who
spawned whom, under whose sponsorship, with what narrowing of scope and
trust.
Example: Agent A minting fifty children with
full-strength credentials should be representable — and rejectable — as
a standard provenance violation. “We have CloudTrail” is not a
provenance standard.
5. Normative context
(“should”) constraints
What exists today: Policy-as-code for can.
Compliance mappings after the fact. Human judgment in the breach
report.
What is needed: Machine-readable obligations and
prohibitions — HR status, trading blackouts, litigation holds, clinical
urgency, minor/crisis interaction rules — evaluated before, during, and
after action. I described this layer in The
Agent Did What It Said It Would Do. It Was Still Wrong..
Example: Identity valid. Intent in scope. Trust
high. Action still vetoed because HR_status = notice_period
and data_class = trade_secret. That veto should be a
standard decision type, not a custom script in one customer’s SOAR.
6. Layer handoff —
cooperative enforcement
What exists today: One PDP to rule them all. Or five
products that do not speak.
What is needed: A handoff protocol among specialized
enforcers — identity, behavior, intent, trust, context — each allowed to
allow, deny, modulate, annotate, or escalate, with the composed outcome
attested. I called the architecture layered cooperative enforcement.
Standards need the sockets; vendors compete on the engines.
Example: Intent layer annotates “narrowly outside
declared scope.” Normative layer permits under mandatory human review
within fifteen minutes because clinical urgency is critical. That
override is a standard attestation other systems can audit — not a Slack
thread that disappears.
This Is Not Only an Agent
Problem
I wrote The Identity Chain of
Custody because deepfake hiring exposes the same missing middle band
in a different costume.
Hiring already has adjacent point solutions: eKYC and identity
assurance, in-call deepfake detection, post-hire ITDR. Each stage can
verify “is this a real, document-checked human?” and you can still lose
— because a different real human answers at each stage.
Stage-substitution defeats snapshots the same way intent fragmentation
and composite “innocent” agent steps defeat per-request controls.
What hiring needs is continuity: an anchor, binding at every stage,
handoff past onboarding, assurance that decays unless behavior renews
it. Those are the same kinds of contracts — subject-keyed trust,
portable attestations, normative proportionality — that agents need for
purpose and should.
So the standards ask is larger than “AI agent identity.”
Charter profiles for different subjects if you must: agentic runtime,
candidate and workforce continuity, future actor types. Do not pretend
the governance gap is unrelated just because one subject shops for a job
and the other calls an API. The question is still: is this the same
actor, for a coherent purpose, under constraints that still apply, right
now?
A commons that only speaks “agent” will miss half the reason the
commons is needed.
What Should Stay Competitive
Standards should define sockets, not furniture.
Compete on detection quality, policy authoring UX, vertical
constraint packs, model choice, enforcement point performance, and how
well your trust physics or normative compiler works. Do not compete by
inventing a private dialect for “purpose” that no other PEP can read.
That is how the industry gets five agent platforms and zero agentic
governance.
If your product cannot emit and consume open intent, trajectory,
trust observations, and normative decisions, it is not a layer in a
stack. It is a silo with a roadmap slide.
A Call to Action
Standards bodies. Keep the Agent ID, SPIFFE,
OAuth-profile, and CAEP work. Then charter the middle band explicitly:
intent contracts, character resolution, trust observation exchange,
provenance/trajectory formats, normative constraint exchange, layer
handoff. Adjacent and stepped-back are both required. Only one is
currently staffed like an emergency.
Vendors. Publish schemas and exit ramps. Join
interop bake-offs. Stop marketing “we completed agentic security” when
you completed registration and a gateway. The category will be defined
either by open contracts or by whoever acquires the rest of the
stack.
CISOs and buyers. Put the middle band in RFPs.
“Supports Agent ID” is table stakes. Require open contracts for purpose,
provenance, and interoperable trust/context signals — including the
right to replace any one layer without forklifting the others. If you do
not ask, you will own the lock-in that follows the first catalytic
breach.
Researchers and builders. Treat interoperability
artifacts as first-class: schemas, fixture vectors, cross-vendor
scenarios. The identity industry did not get SAML because one company
won. It got SAML because enough parties needed a shared language more
than they needed a private one.
The Bottom Line
Agent identity standards are necessary. They are not sufficient.
The working groups extending OAuth, SPIFFE, SCIM, and Shared Signals
for agents are doing the right adjacent work. Praise it. Ship it. Just
do not confuse the floor with the building.
Autonomous systems create a governance question the floor cannot
answer alone: should this action happen, by this actor, for this
purpose, in this context, right now? Answering that across a
multi-vendor world requires a middle band of standards — intent,
character, trust observations, trajectory, normative constraints, layer
handoff — that barely exists as shared infrastructure today.
The same band would have given hiring a chain of custody instead of a
stack of disconnected verifications. Agents are the forcing function.
They are not the only subject.
I have been publishing the architectural case for those contracts
under Tamed Autonomy — intent, trust, provenance, attestation, and
normative constraints as the middle band above today’s identity floor. I
intend to publish draft RFCs for those primitives so they can be argued
with, forked, and improved in the open. That is a contribution to the
commons, not a claim to own it.
The industry still has a choice. Build the shared language now, while
the adjacent work is fresh enough to plug into. Or stretch the old model
until the first crisis forces a proprietary “platform” to become the
accidental standard.
We have made that mistake before. We do not have to make it again at
machine speed.
Tamed Autonomy is an independent personal research project
exploring AI agent governance beyond identity and authorization. See the
whitepaper, agentic identity, layered cooperative enforcement, and identity chain of
custody.
Leave a Reply