AI Agent Identity and Authorization: How aizome Implements the NIST NCCoE Framework
aizome maps its production architecture against the five agentic identity failure modes identified by NIST NCCoE - credential sharing, static credentials, broadly scoped access, local user account deployment, and over-reliance on human-in-the-loop controls.
This technical brief details how aizome's inline MCP identity broker eliminates each failure mode structurally, and maps the implementation against NIST SP 800-63, SPIFFE, OAuth 2.0, Rich Authorization Requests (RFC 9396), and the emerging WIMSE standard. Includes the six-stage SAML impersonation model, full audit trail schema, and compliance framework mapping across NIST AI RMF, SANS Stage 3, OWASP Agentic Top 10, and EU AI Act Article 12.
