{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","framework":"nist-ai-agent-identity","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-ai-agent-identity/","description":"The paper asks how zero trust, changing agent context, aggregated data sensitivity, least privilege, and proof of authority for a specific action can inform agent authorization.","details":{"automation":"hybrid","control_category":"technical","control_id":"NIST-AGI-03","control_type":"preventive","domains":[],"framework":"nist-ai-agent-identity","group":"Agent Identity and Authorization Topics","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":0,"source_pages":"Concept paper pp. 4, 6: Authorization; Areas of Interest","source_url":"https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization-concept-paper.pdf#page=5","statement":"The paper asks how zero trust, changing agent context, aggregated data sensitivity, least privilege, and proof of authority for a specific action can inform agent authorization."},"id":"ctrl:nist-ai-agent-identity:NIST-AGI-03","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-ai-agent-identity%3ANIST-AGI-03","sourceIds":["nist-ai-agent-identity"],"sourceUrl":"https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization-concept-paper.pdf#page=5","title":"NIST-AGI-03 — Context-sensitive authorization and least privilege","type":"control"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:006bead217c48e8d5eea49d9e07d8efb6501dd8a46bf55cc57cae1f5e1243a8d","properties":{"control_id":"NIST-AGI-03","coverage":"guidance","delta":null,"framework":"nist-ai-agent-identity","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Concept paper pp. 4, 6: Authorization; Areas of Interest","source_version":"February 2026 draft concept paper"},"sourceDetailPath":"/data/v1/records/uc-uc-access-05-9b7f3e34.json","sourceId":"uc:UC-ACCESS-05","targetDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-03-0c271eec.json","targetId":"ctrl:nist-ai-agent-identity:NIST-AGI-03","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0ddade164badb762f67aff07dd69e64f6a995180b26f572da451591514483de1","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-03-0c271eec.json","sourceId":"ctrl:nist-ai-agent-identity:NIST-AGI-03","targetDetailPath":"/data/v1/records/std-nist-ai-agent-identity-5c357655.json","targetId":"std:nist-ai-agent-identity","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5cb0a2f1e9b62aa907b0447d1955357fa4ab1d0b0b7b96839bcd1346faacb4e8","properties":{"control_id":"NIST-AGI-03","coverage":"guidance","delta":null,"framework":"nist-ai-agent-identity","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Concept paper pp. 4, 6: Authorization; Areas of Interest","source_version":"February 2026 draft concept paper"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-03-0c271eec.json","targetId":"ctrl:nist-ai-agent-identity:NIST-AGI-03","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:646b3e051d76759d535f496d3e10af53505391b6086f3f8cb2e5787327ee0e11","properties":{"control_id":"NIST-AGI-03","coverage":"guidance","delta":null,"framework":"nist-ai-agent-identity","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Concept paper pp. 4, 6: Authorization; Areas of Interest","source_version":"February 2026 draft concept paper"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-03-0c271eec.json","targetId":"ctrl:nist-ai-agent-identity:NIST-AGI-03","type":"informed_by"}],"schemaVersion":1}
