← Latest reporting

Agent identity must survive the whole delivery path, not just the login

NIST NCCoE is scoping a DevSecOps implementation in which AI agents are identified, authenticated and authorised through the software lifecycle. The useful test is continuity from delegated intent to every resulting action.

Policy, Standards and GovernanceAI Capability Frontier
A full-scale conceptual corridor carries one pale blue authority ribbon through several physical checkpoints while a broken orange handoff falls into quarantine.
Conceptual illustration generated with AI under editorial direction; it does not depict a real event.

What happened

On 24 September NCCoE said DevSecOps Build 3 would use one implementation to combine agentic development, build and test with its Software and AI Agent Identity and Authorization project. The project is being scoped and updated material remains open for comment until 9 November.

Why it matters

Authentication proves an identity at one moment; it does not preserve who delegated a task, which code and tools were allowed, how sub-actions inherited authority or who can revoke it. A delivery pipeline needs evidence across every handoff.

NIST's National Cybersecurity Center of Excellence said on 24 September that its third DevSecOps example implementation will explore agentic AI used to develop, build and test code. The DevSecOps team and the Software and AI Agent Identity and Authorization team plan one implementation showing how agents can be identified, authenticated and authorised within the software development lifecycle.

This is a scoped example, not a completed standard or proof that a particular identity architecture works. NCCoE is collaborating with 14 technology companies on its wider DevSecOps work, and recently updated parts of its live document remain open for public comment until 9 November. An October webinar will present the Build 3 scope.

Start with the delegation record

Most identity systems answer who or what presented a credential. An agent workflow also needs to answer who delegated the task, the intended outcome, the limits, the approving policy and the time window. Create a delegation record before the agent receives a token. Bind it to the exact agent build, model, tools, repository, branch and environment.

Issue short-lived, task-specific credentials rather than a reusable service account. The token should express resource, action, time, spend and environment constraints. When an agent spawns a sub-agent or invokes a build service, the child authority must be narrower and linked to the parent record. No component should silently replace delegated identity with a broad pipeline credential.

Preserve continuity through artifacts

Identity evidence must travel with the work. Commits, build artifacts, test results, deployment packages and change approvals should point to the initiating delegation and every material automated action. Sign artifacts and verify them at the next stage, but do not confuse a valid signature with an authorised purpose. Policy must check both origin and allowed use.

Make revocation end-to-end. Disabling an agent identity should invalidate queued jobs, derived tokens and deployment rights, not just block a new login. Exercise the sequence while work is in flight. Confirm that partial artifacts are quarantined, state is preserved for investigation and resumption requires new named authority.

The counterargument is that such granularity will slow delivery and flood logs. Risk tiers can keep the system usable. Read-only analysis in an isolated repository may receive broad visibility with no write path. Code changes, package publication, secrets, infrastructure or production deployment need progressively stronger confirmation and separation of duties. Summarise routine events while preserving tamper-evident detail for consequential actions.

Evaluation should include confused-deputy and handoff failures. Ask an agent to use a valid tool for a purpose outside the delegation, reuse an artifact in another environment, accept instructions from untrusted content and continue after revocation. Measure policy denials, unexplained privilege expansion, orphaned credentials, trace completeness and time to stop.

The NCCoE implementation will be valuable if it exposes concrete failure modes and interoperable evidence, but organisations need not wait to inventory their authority paths. Map every place an agent receives identity, code, data, tools or approval. Give one owner responsibility for reconciling identity-provider logs, pipeline events and model/tool traces.

Do not let observability become a substitute for prevention. A perfect trace can explain an unauthorised deployment after the fact but cannot make it acceptable. Combine immutable evidence with pre-action policy checks, short-lived credentials and independent approval at high-consequence boundaries. Logs then support verification and recovery instead of carrying the whole control burden. Review the resulting exceptions with both security and delivery owners each week.

The Skills Intelligence glossary can support a common language for identity, authorization and delegation. The operating decision is more specific: no state-changing agent should enter a delivery pipeline until its authority can be followed from human or policy intent through every child action, artifact and revocation point.