diff --git a/data/protocols/protocol-BATCH-2026-001.json b/data/protocols/protocol-BATCH-2026-001.json new file mode 100644 index 0000000..d040184 --- /dev/null +++ b/data/protocols/protocol-BATCH-2026-001.json @@ -0,0 +1,134 @@ +{ + "protocol_id": "protocol-BATCH-2026-001", + "research_question": "How do public executive and institutional sources define governance requirements for AI-agent identities?", + "scope": "Discovery and selection of publicly accessible, canonically identifiable sources on identity, authentication, authorization, delegation, accountability, lifecycle, auditability, non-human identity, and human oversight for autonomous or agentic AI systems. Priority industries are financial services, technology and cloud, healthcare and life sciences, public sector and defense, critical infrastructure, and professional services.", + "time_period": "2020-08-15 through 2026-08-15, with pre-2020 foundational identity, zero-trust, authorization, and software-workload standards included only when they directly govern current AI-agent identity questions.", + "target_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel", + "role-board-director", + "role-ceo" + ], + "target_geographies": [ + "geo-global", + "United States", + "European Union", + "United Kingdom", + "Canada", + "Singapore", + "Australia", + "India", + "Japan" + ], + "target_languages": [ + "lang-en" + ], + "included_source_types": [ + "book", + "video", + "podcast_episode", + "keynote", + "panel", + "interview", + "conference_talk", + "essay", + "newsletter", + "public_letter", + "research_report", + "academic_paper", + "working_paper", + "executive_survey", + "event_recording", + "OFF_research", + "OFF_interview", + "OFF_video", + "public_policy_document", + "other_approved" + ], + "excluded_source_types": [ + "Non-public or confidential material", + "Anonymous summaries and content farms", + "AI-generated summaries", + "Scraped or unofficial transcripts", + "Duplicate syndication when the original is available", + "Low-substance promotional material" + ], + "inclusion_criteria": [ + "The source is publicly accessible or has stable public bibliographic metadata sufficient for a metadata-only candidate.", + "The work, episode, document, speaker, author, publisher, and date can be canonically identified.", + "The source materially addresses identity, credentials, authentication, authorization, delegation, lifecycle, auditability, accountability, or oversight for AI agents or directly applicable non-human workloads.", + "The source is original, an original-publisher copy, an official author or institution copy, or a stable bibliographic record used only for identity verification.", + "The source can contribute a distinct governance, technical, legal, operational, empirical, or dissenting perspective.", + "Rights and ownership can be recorded without copying third-party text." + ], + "exclusion_criteria": [ + "Generic AI governance material with no meaningful identity, delegation, access-control, accountability, or agent-lifecycle content.", + "Generic human IAM, API-key, bot, or workload-identity material with no direct relevance to autonomous or agentic systems.", + "Consumer chatbot usability, model benchmark, robotics-hardware, or autonomous-vehicle identity material outside enterprise-agent governance.", + "Search snippets, inaccessible claims, ambiguous authorship, unverifiable dates, or unresolved source identity.", + "Promotional reposts, third-party uploads of uncertain rights, non-public events, not-for-attribution material, and complete third-party transcripts.", + "Sources selected only for search visibility or quota filling rather than substantive relevance." + ], + "source_priority": [ + "Original standard, law, policy, paper, book, recording, report, or direct statement", + "Original publisher or event host", + "Official author, institution, regulator, standards body, or company research page", + "Stable bibliographic or archival source", + "Reliable independent contextual verification", + "Secondary summary used only to locate an original" + ], + "diversity_objectives": [ + "Cover security, technology, legal, board, chief executive, risk, architecture, and operations perspectives without using weak sources to fill categories.", + "Include financial services, technology and cloud, healthcare and life sciences, public sector and defense, critical infrastructure, and professional services.", + "Seek global, United States, European Union, United Kingdom, Canadian, Singaporean, Australian, Indian, and Japanese relevance while recording unmet geographic goals.", + "Balance standards, policy, academic evidence, practitioner analysis, books, and primary media.", + "Balance established and emerging contributors, academic and practitioner sources, operator and investor views, and supporting and challenging positions.", + "Measure consulting, vendor, hyperscaler, and OFF-owned concentration separately." + ], + "expected_limitations": [ + "The controlled vocabulary currently supports English only; non-English discovery is deferred and recorded as a gap.", + "AI-agent identity terminology is emerging and overlaps non-human identity, workload identity, machine identity, delegated authorization, and zero trust.", + "Vendor and consulting sources are likely to be more visible than independent empirical research.", + "Books may be evaluated at metadata level only unless lawful full-text access is available.", + "Public sources may underrepresent failures, internal controls, and board-level decision records.", + "The 2026 endpoint may include newly published material with limited independent evaluation." + ], + "planned_search_queries": [ + "AI agent identity governance authentication authorization delegation auditability", + "agentic AI identity non-human identity governance standard", + "AI agents identity access management CISO CIO CTO", + "AI agent authorization OAuth workload identity SPIFFE zero trust", + "AI agent identity NIST ISO OWASP CSA W3C IETF", + "AI agent governance law policy EU UK US Singapore Canada Australia Japan India", + "AI agent identity academic paper empirical study", + "AI agent security identity conference talk podcast interview", + "agentic AI governance book autonomous agents identity", + "AI agent identity financial services healthcare public sector critical infrastructure" + ], + "planned_batch_size": 120, + "created_at": "2026-08-15T10:34:21Z", + "created_by": "OpenAI Codex (machine-drafted; human review pending)", + "prompt_id": "OEII-TOPIC-DISCOVERY", + "prompt_version": "2.0", + "workflow_status": "candidate", + "machine_review_status": "machine_drafted", + "human_review_status": "pending", + "reviewed_by": null, + "reviewed_at": null, + "provenance": [ + { + "source_url": "https://github.com/OpenFutureForum/executive-intelligence-index", + "accessed_at": "2026-08-15", + "retrieval_method": "Repository methodology, roadmap, schemas, and controlled vocabularies inspected before discovery", + "exact_locator": "operations/research-roadmap.yml priority 1 and OEII-TOPIC-DISCOVERY version 2.0", + "content_hash": null, + "batch_id": "BATCH-2026-001", + "prompt_id": "OEII-TOPIC-DISCOVERY", + "prompt_version": "2.0", + "notes": "The user-supplied prompt left placeholders unfilled; the repository's priority-one roadmap supplied the topic and research question." + } + ], + "revision_history": [] +} diff --git a/operations/batch-registry.yml b/operations/batch-registry.yml index 59d941c..cd30512 100644 --- a/operations/batch-registry.yml +++ b/operations/batch-registry.yml @@ -7,3 +7,12 @@ batches: prompt_version: "2.0" human_review_status: pending publication_status: local_only + - batch_id: BATCH-2026-001 + branch: research/discovery-governed-agent-identities-BATCH-2026-001 + type: topic_discovery + protocol_id: protocol-BATCH-2026-001 + prompt_id: OEII-TOPIC-DISCOVERY + prompt_version: "2.0" + candidate_counts: {considered: 120, accepted: 91, held: 19, rejected: 10} + human_review_status: pending + publication_status: staging_only diff --git a/operations/research-roadmap.yml b/operations/research-roadmap.yml index b568468..f86dfe8 100644 --- a/operations/research-roadmap.yml +++ b/operations/research-roadmap.yml @@ -3,6 +3,8 @@ status: proposed_for_human_review protocols: - priority: 1 protocol_slug: governed-identities-for-ai-agents + discovery_batch: BATCH-2026-001 + discovery_status: complete_pending_human_selection question: How do public executive and institutional sources define governance requirements for AI-agent identities? reason: Tests the statement/proposition model across security, architecture, legal, and board roles. - priority: 2 diff --git a/package.json b/package.json index 26abfe6..f00d0e2 100644 --- a/package.json +++ b/package.json @@ -24,6 +24,7 @@ "validate:review-status": "tsx scripts/cli.ts validate review-status", "validate:publication": "tsx scripts/cli.ts validate publication", "validate:content": "tsx scripts/cli.ts validate content", + "validate:discovery": "tsx scripts/validate-discovery-batch.ts", "audit:duplicates": "tsx scripts/cli.ts audit duplicates", "audit:concentration": "tsx scripts/cli.ts audit concentration", "audit:coverage": "tsx scripts/cli.ts audit coverage", diff --git a/scripts/cli.ts b/scripts/cli.ts index ae57f35..2c0810d 100644 --- a/scripts/cli.ts +++ b/scripts/cli.ts @@ -9,6 +9,7 @@ import { publicationIssues } from './lib/publication.js'; const root = process.cwd(); const args = process.argv.slice(2); const records = loadCanonical(root); +const currentUtcDate = new Date().toISOString().slice(0, 10); function result(name: string, details: string): void { process.stdout.write(`PASS ${name}: ${details}\n`); } function getSchemaValidator() { @@ -51,7 +52,7 @@ function validateData(): void { else if (isbn) isbns.set(isbn, item.file); } for (const [key, value] of Object.entries(item.record)) { - if ((key.endsWith('_date') || key.endsWith('_at') || key === 'accessed_at') && typeof value === 'string' && value.slice(0, 10) > '2026-08-14') errors.push(`${item.file}: future-date anomaly in ${key}`); + if ((key.endsWith('_date') || key.endsWith('_at') || key === 'accessed_at') && typeof value === 'string' && value.slice(0, 10) > currentUtcDate) errors.push(`${item.file}: future-date anomaly in ${key}`); } if (item.record.doi && !/^10\.\d{4,9}\/[\S]+$/i.test(item.record.doi)) errors.push(`${item.file}: invalid DOI`); if (item.schema === 'organization-reference' && item.record.canonical_cxo_ecosystem_id) { diff --git a/scripts/validate-discovery-batch.ts b/scripts/validate-discovery-batch.ts new file mode 100644 index 0000000..485408f --- /dev/null +++ b/scripts/validate-discovery-batch.ts @@ -0,0 +1,128 @@ +import fs from 'node:fs'; +import path from 'node:path'; +import process from 'node:process'; +import Ajv2020 from 'ajv/dist/2020.js'; +import addFormats from 'ajv-formats'; +import YAML from 'yaml'; + +const batchId = process.argv[2]; +if (!batchId) throw new Error('Usage: validate-discovery-batch.ts '); + +const root = process.cwd(); +const batchDir = path.join(root, 'staging', 'batches', batchId); +const readJson = (name: string) => JSON.parse(fs.readFileSync(path.join(batchDir, name), 'utf8')); +const candidates = readJson('candidate-sources.json'); +const accepted = readJson('accepted-candidates.json'); +const held = readJson('hold-queue.json'); +const rejected = readJson('rejected-sources.json'); +const duplicates = readJson('duplicate-review.json'); +const candidateSchema = readJson('candidate-source.schema.json'); +const searchLog = YAML.parse(fs.readFileSync(path.join(batchDir, 'search-log.yml'), 'utf8')); + +const failures: string[] = []; +const warnings: string[] = []; +const passes: string[] = []; +const fail = (message: string) => failures.push(message); +const pass = (message: string) => passes.push(message); +const warn = (message: string) => warnings.push(message); + +const ajv = new Ajv2020({ allErrors: true, strict: false }); +addFormats(ajv); +const validateCandidate = ajv.compile(candidateSchema); +for (const candidate of candidates) { + if (!validateCandidate(candidate)) fail(`Candidate schema: ${candidate.candidate_id}: ${ajv.errorsText(validateCandidate.errors)}`); +} +if (!failures.length) pass(`Candidate schema: ${candidates.length} records conform to the batch-local schema.`); + +const ids = candidates.map((item: any) => item.candidate_id); +const uniqueIds = new Set(ids); +if (uniqueIds.size !== ids.length) fail('Candidate identity: duplicate candidate_id values found.'); +else pass('Candidate identity: all candidate IDs are unique.'); + +const expectedIds = new Set(candidates.map((item: any) => item.candidate_id)); +const partitions = [...accepted, ...held, ...rejected]; +if (partitions.length !== candidates.length || new Set(partitions.map((item: any) => item.candidate_id)).size !== candidates.length || partitions.some((item: any) => !expectedIds.has(item.candidate_id))) { + fail('Decision partition: accepted, held, and rejected files do not partition the candidate slate exactly.'); +} else pass(`Decision partition: ${accepted.length} accepted, ${held.length} held, ${rejected.length} rejected.`); + +const expectedDecision = new Map([['accept', accepted], ['hold', held], ['reject', rejected]]); +for (const [decision, items] of expectedDecision) if ((items as any[]).some((item: any) => item.decision !== decision)) fail(`Decision partition: ${decision} file contains another decision.`); + +const normalizeTitle = (value: string) => value.toLowerCase().normalize('NFKD').replace(/[^a-z0-9]+/g, ' ').trim(); +const normalizedTitles = new Map(); +for (const item of candidates) { + const key = normalizeTitle(item.title); + normalizedTitles.set(key, [...(normalizedTitles.get(key) ?? []), item.candidate_id]); +} +const titleCollisions = [...normalizedTitles.values()].filter((items) => items.length > 1); +if (titleCollisions.length) warn(`Normalized-title review: ${titleCollisions.length} exact normalized collision(s) require duplicate review.`); +else pass('Normalized-title review: no unexpected exact collisions.'); + +const urls = candidates.map((item: any) => item.original_url); +if (new Set(urls).size !== urls.length) fail('URL validation: duplicate original_url values found.'); +else pass('URL validation: all original URLs are unique.'); +for (const item of candidates) { + try { new URL(item.original_url); new URL(item.canonical_url); } catch { fail(`URL validation: invalid URL on ${item.candidate_id}.`); } +} + +const unresolvedAccepted = accepted.filter((item: any) => /unresolved|unknown|speaker$/i.test(item.author_or_speaker)); +if (unresolvedAccepted.length) fail(`Source identity: accepted candidates have unresolved author/speaker identity: ${unresolvedAccepted.map((item: any) => item.candidate_id).join(', ')}`); +else pass('Source identity: accepted candidates have non-empty work, author/speaker, publisher, and URL identities.'); + +const missingRights = candidates.filter((item: any) => !item.rights_status || !item.analysis_access_status); +if (missingRights.length) fail(`Rights validation: ${missingRights.length} candidates lack rights or access status.`); +else pass('Rights validation: every candidate has explicit access and conservative rights status.'); + +const missingOwnership = candidates.filter((item: any) => !item.ownership_status || !item.OFF_relationship); +if (missingOwnership.length) fail(`Ownership validation: ${missingOwnership.length} candidates lack ownership or OFF-relationship status.`); +else pass('Ownership validation: every candidate has ownership and OFF-relationship status.'); + +const duplicateIds = new Set(duplicates.groups.flatMap((group: any) => group.rejected_candidate_ids)); +const duplicateRejects = rejected.filter((item: any) => item.likely_duplicate).map((item: any) => item.candidate_id); +if (duplicateRejects.some((id: string) => !duplicateIds.has(id)) || duplicateIds.size !== duplicateRejects.length) fail('Duplicate validation: duplicate rejects and duplicate-review groups do not match.'); +else pass(`Duplicate validation: ${duplicates.groups.length} work/rendition groups resolve ${duplicateRejects.length} duplicate rejects.`); + +const queryIds = new Set(searchLog.queries.map((query: any) => query.id)); +const unknownQueries = candidates.flatMap((item: any) => item.search_query_ids.filter((id: string) => !queryIds.has(id)).map((id: string) => `${item.candidate_id}:${id}`)); +if (unknownQueries.length) fail(`Search log: unknown query references: ${unknownQueries.join(', ')}`); +else pass(`Search log: ${queryIds.size} query families plus supplementary failures are documented.`); + +const targetRoles = ['role-ciso','role-cio','role-cto','role-general-counsel','role-board-director','role-ceo']; +const acceptedRoles = new Set(accepted.flatMap((item: any) => item.relevant_roles)); +const missingRoles = targetRoles.filter((role) => !acceptedRoles.has(role)); +if (missingRoles.length) fail(`Coverage: no accepted candidate covers ${missingRoles.join(', ')}.`); +else pass('Coverage: every pre-registered executive role appears in the accepted set.'); + +const acceptedGeographies = new Set(accepted.flatMap((item: any) => item.relevant_geographies)); +for (const geography of ['India','Japan']) if (!acceptedGeographies.has(geography)) warn(`Coverage gap: ${geography} has no accepted candidate.`); +if (new Set(candidates.map((item: any) => item.language)).size === 1) warn('Coverage gap: all candidates are English-language due to the active controlled vocabulary.'); + +const publisherCounts = new Map(); +for (const item of accepted) publisherCounts.set(item.publisher, (publisherCounts.get(item.publisher) ?? 0) + 1); +const topEntry = [...publisherCounts.entries()].sort((a, b) => b[1] - a[1])[0]; +if (!topEntry) throw new Error('Concentration validation requires at least one accepted candidate.'); +const [topPublisher, topCount] = topEntry; +const topShare = topCount / accepted.length; +if (topShare > 0.2) fail(`Concentration: ${topPublisher} is ${(topShare * 100).toFixed(1)}% of accepted candidates.`); +else pass(`Concentration: largest publisher label is ${topPublisher} at ${(topShare * 100).toFixed(1)}%.`); + +const forbiddenRoots = ['content', 'docs', 'exports']; +const walk = (dir: string): string[] => fs.existsSync(dir) ? fs.readdirSync(dir, { withFileTypes: true }).flatMap((entry) => entry.isDirectory() ? walk(path.join(dir, entry.name)) : [path.join(dir, entry.name)]) : []; +const leaks: string[] = []; +for (const top of forbiddenRoots) { + for (const file of walk(path.join(root, top))) { + if (!/\.(json|md|html|csv|ndjson|xml|txt)$/i.test(file)) continue; + const text = fs.readFileSync(file, 'utf8'); + if (text.includes(`candidate-${batchId}-`)) leaks.push(path.relative(root, file)); + } +} +if (leaks.length) fail(`Staging leak: candidate IDs found outside staging in ${leaks.join(', ')}.`); +else pass('Staging leak: no candidate IDs appear in content, docs, or exports.'); + +if (candidates.length < 100 || candidates.length > 150) fail(`Batch size: ${candidates.length} is outside the pre-registered 100–150 range.`); +else pass(`Batch size: ${candidates.length} candidates satisfies the pre-registered range.`); + +for (const message of passes) console.log(`PASS ${message}`); +for (const message of warnings) console.warn(`WARN ${message}`); +for (const message of failures) console.error(`FAIL ${message}`); +if (failures.length) process.exit(1); diff --git a/staging/batches/BATCH-2026-001/accepted-candidates.json b/staging/batches/BATCH-2026-001/accepted-candidates.json new file mode 100644 index 0000000..ab71139 --- /dev/null +++ b/staging/batches/BATCH-2026-001/accepted-candidates.json @@ -0,0 +1,5493 @@ +[ + { + "candidate_id": "candidate-BATCH-2026-001-001", + "title": "NIST concept paper: Accelerating the Adoption of Software and AI Agent Identity and Authorization", + "source_type": "public_policy_document", + "work_or_episode_identity": "NIST concept paper: Accelerating the Adoption of Software and AI Agent Identity and Authorization", + "author_or_speaker": "NIST NCCoE", + "publisher": "NIST", + "publication_date": "2026-02-05", + "event_date": null, + "original_url": "https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd", + "canonical_url": "https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Directly frames software-agent identity and authorization adoption.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Directly frames software-agent identity and authorization adoption.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-002", + "title": "NIST AI Agent Standards Initiative", + "source_type": "public_policy_document", + "work_or_episode_identity": "NIST AI Agent Standards Initiative", + "author_or_speaker": "NIST", + "publisher": "NIST", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative", + "canonical_url": "https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Primary standards-program source with security and interoperability scope.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary standards-program source with security and interoperability scope.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-004", + "title": "CAISI request for information about securing AI agent systems", + "source_type": "public_policy_document", + "work_or_episode_identity": "CAISI request for information about securing AI agent systems", + "author_or_speaker": "NIST CAISI", + "publisher": "NIST", + "publication_date": "2026-01", + "event_date": null, + "original_url": "https://www.nist.gov/news-events/news/2026/01/caisi-issues-request-information-about-securing-ai-agent-systems", + "canonical_url": "https://www.nist.gov/news-events/news/2026/01/caisi-issues-request-information-about-securing-ai-agent-systems", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Primary public consultation source useful for requirement and dissent mapping.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary public consultation source useful for requirement and dissent mapping.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-005", + "title": "Summary analysis of responses regarding security considerations for AI agent systems", + "source_type": "research_report", + "work_or_episode_identity": "Summary analysis of responses regarding security considerations for AI agent systems", + "author_or_speaker": "NIST CAISI", + "publisher": "NIST", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.nist.gov/publications/summary-analysis-responses-request-information-regarding-security-considerations-ai", + "canonical_url": "https://www.nist.gov/publications/summary-analysis-responses-request-information-regarding-security-considerations-ai", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Synthesizes public responses and exposes areas of agreement and disagreement.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Synthesizes public responses and exposes areas of agreement and disagreement.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-006", + "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0)", + "source_type": "public_policy_document", + "work_or_episode_identity": "Artificial Intelligence Risk Management Framework (AI RMF 1.0)", + "author_or_speaker": "NIST", + "publisher": "NIST", + "publication_date": "2023-01-26", + "event_date": null, + "original_url": "https://www.nist.gov/itl/ai-risk-management-framework", + "canonical_url": "https://www.nist.gov/itl/ai-risk-management-framework", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Foundational governance framework applicable to ownership, monitoring, and accountability.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Foundational governance framework applicable to ownership, monitoring, and accountability.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-007", + "title": "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile", + "source_type": "public_policy_document", + "work_or_episode_identity": "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile", + "author_or_speaker": "NIST", + "publisher": "NIST", + "publication_date": "2024-07", + "event_date": null, + "original_url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf", + "canonical_url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Official risk profile with governance controls relevant to agent deployments.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Official risk profile with governance controls relevant to agent deployments.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-009", + "title": "AI Agent Authentication and Authorization", + "source_type": "working_paper", + "work_or_episode_identity": "AI Agent Authentication and Authorization", + "author_or_speaker": "IETF Internet-Draft authors", + "publisher": "IETF", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-02.html", + "canonical_url": "https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-02.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Direct protocol proposal for agent authentication and authorization; draft status retained.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Direct protocol proposal for agent authentication and authorization; draft status retained.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-010", + "title": "Agent Auditing Architecture", + "source_type": "working_paper", + "work_or_episode_identity": "Agent Auditing Architecture", + "author_or_speaker": "IETF Internet-Draft authors", + "publisher": "IETF", + "publication_date": "2026", + "event_date": null, + "original_url": "https://datatracker.ietf.org/doc/draft-kuehlewind-audit-architecture/", + "canonical_url": "https://datatracker.ietf.org/doc/draft-kuehlewind-audit-architecture/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Directly addresses traceability and audit architecture for agents.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Directly addresses traceability and audit architecture for agents.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-011", + "title": "Agent Operation Authorization", + "source_type": "working_paper", + "work_or_episode_identity": "Agent Operation Authorization", + "author_or_speaker": "IETF Internet-Draft authors", + "publisher": "IETF", + "publication_date": "2026", + "event_date": null, + "original_url": "https://datatracker.ietf.org/doc/draft-liu-agent-operation-authorization/", + "canonical_url": "https://datatracker.ietf.org/doc/draft-liu-agent-operation-authorization/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Directly addresses authorization of specific agent operations.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Directly addresses authorization of specific agent operations.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-012", + "title": "OAuth Actor Profile", + "source_type": "working_paper", + "work_or_episode_identity": "OAuth Actor Profile", + "author_or_speaker": "IETF Internet-Draft authors", + "publisher": "IETF", + "publication_date": "2025", + "event_date": null, + "original_url": "https://datatracker.ietf.org/doc/html/draft-mcguinness-oauth-actor-profile-00", + "canonical_url": "https://datatracker.ietf.org/doc/html/draft-mcguinness-oauth-actor-profile-00", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Provides an actor/delegation model relevant to agents acting for users.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Provides an actor/delegation model relevant to agents acting for users.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-013", + "title": "Workload Identity in Multi System Environments (WIMSE) session materials", + "source_type": "other_approved", + "work_or_episode_identity": "Workload Identity in Multi System Environments (WIMSE) session materials", + "author_or_speaker": "IETF WIMSE participants", + "publisher": "IETF", + "publication_date": "2024-03", + "event_date": null, + "original_url": "https://datatracker.ietf.org/meeting/119/session/wimse", + "canonical_url": "https://datatracker.ietf.org/meeting/119/session/wimse", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Foundational multi-system workload identity material with official meeting provenance.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Foundational multi-system workload identity material with official meeting provenance.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-014", + "title": "SPIFFE standards index", + "source_type": "other_approved", + "work_or_episode_identity": "SPIFFE standards index", + "author_or_speaker": "SPIFFE Project", + "publisher": "SPIFFE Project", + "publication_date": null, + "event_date": null, + "original_url": "https://spiffe.io/docs/latest/spiffe-specs/", + "canonical_url": "https://spiffe.io/docs/latest/spiffe-specs/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Canonical index for workload identity standards directly applicable to agent runtimes.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Canonical index for workload identity standards directly applicable to agent runtimes.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-015", + "title": "SPIFFE Workload API", + "source_type": "other_approved", + "work_or_episode_identity": "SPIFFE Workload API", + "author_or_speaker": "SPIFFE Project", + "publisher": "SPIFFE Project", + "publication_date": null, + "event_date": null, + "original_url": "https://spiffe.io/docs/latest/spiffe-specs/spiffe_workload_api/", + "canonical_url": "https://spiffe.io/docs/latest/spiffe-specs/spiffe_workload_api/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Defines issuance and rotation interfaces for workload credentials.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Defines issuance and rotation interfaces for workload credentials.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-016", + "title": "SPIFFE ID specification", + "source_type": "other_approved", + "work_or_episode_identity": "SPIFFE ID specification", + "author_or_speaker": "SPIFFE Project", + "publisher": "SPIFFE Project", + "publication_date": null, + "event_date": null, + "original_url": "https://spiffe.io/docs/latest/spiffe-specs/spiffe-id/", + "canonical_url": "https://spiffe.io/docs/latest/spiffe-specs/spiffe-id/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Defines stable workload identity names and trust domains.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Defines stable workload identity names and trust domains.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-017", + "title": "SPIFFE Federation specification", + "source_type": "other_approved", + "work_or_episode_identity": "SPIFFE Federation specification", + "author_or_speaker": "SPIFFE Project", + "publisher": "SPIFFE Project", + "publication_date": null, + "event_date": null, + "original_url": "https://spiffe.io/docs/latest/spiffe-specs/spiffe_federation/", + "canonical_url": "https://spiffe.io/docs/latest/spiffe-specs/spiffe_federation/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Supports cross-domain trust relevant to agent-to-agent interactions.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Supports cross-domain trust relevant to agent-to-agent interactions.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-019", + "title": "Agentic AI: Threats and Mitigations", + "source_type": "research_report", + "work_or_episode_identity": "Agentic AI: Threats and Mitigations", + "author_or_speaker": "OWASP Agentic Security Initiative", + "publisher": "OWASP GenAI Security Project", + "publication_date": "2025-02-17", + "event_date": null, + "original_url": "https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/", + "canonical_url": "https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Community-reviewed threat taxonomy includes privilege and identity risks.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Community-reviewed threat taxonomy includes privilege and identity risks.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-020", + "title": "Multi-Agentic System Threat Modeling Guide v1.0", + "source_type": "research_report", + "work_or_episode_identity": "Multi-Agentic System Threat Modeling Guide v1.0", + "author_or_speaker": "OWASP Agentic Security Initiative", + "publisher": "OWASP GenAI Security Project", + "publication_date": "2025-04-23", + "event_date": null, + "original_url": "https://genai.owasp.org/resource/multi-agentic-system-threat-modeling-guide-v1-0/", + "canonical_url": "https://genai.owasp.org/resource/multi-agentic-system-threat-modeling-guide-v1-0/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Applies threat modeling to multi-agent authorization and trust boundaries.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Applies threat modeling to multi-agent authorization and trust boundaries.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-021", + "title": "OWASP Top 10 for Agentic Applications", + "source_type": "research_report", + "work_or_episode_identity": "OWASP Top 10 for Agentic Applications", + "author_or_speaker": "OWASP Agentic Security Initiative", + "publisher": "OWASP GenAI Security Project", + "publication_date": "2025-12-09", + "event_date": null, + "original_url": "https://genai.owasp.org/2025/12/09/owasp-top-10-for-agentic-applications-the-benchmark-for-agentic-security-in-the-age-of-autonomous-ai/", + "canonical_url": "https://genai.owasp.org/2025/12/09/owasp-top-10-for-agentic-applications-the-benchmark-for-agentic-security-in-the-age-of-autonomous-ai/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Prominent community consensus artifact covering identity and privilege abuse.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Prominent community consensus artifact covering identity and privilege abuse.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-022", + "title": "State of Agentic AI Security and Governance 2.01", + "source_type": "research_report", + "work_or_episode_identity": "State of Agentic AI Security and Governance 2.01", + "author_or_speaker": "OWASP GenAI Security Project", + "publisher": "OWASP GenAI Security Project", + "publication_date": "2026-06-01", + "event_date": null, + "original_url": "https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/", + "canonical_url": "https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Current incident-oriented synthesis connecting governance to deployment controls.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Current incident-oriented synthesis connecting governance to deployment controls.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-024", + "title": "The Non-Human Identity Governance Vacuum", + "source_type": "research_report", + "work_or_episode_identity": "The Non-Human Identity Governance Vacuum", + "author_or_speaker": "CSA AI Safety Initiative", + "publisher": "Cloud Security Alliance", + "publication_date": "2026-05-20", + "event_date": null, + "original_url": "https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/", + "canonical_url": "https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Direct governance analysis of agent identities and unmanaged ownership.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Direct governance analysis of agent identities and unmanaged ownership.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-025", + "title": "Agentic Identity Governance Framework", + "source_type": "research_report", + "work_or_episode_identity": "Agentic Identity Governance Framework", + "author_or_speaker": "Cloud Security Alliance", + "publisher": "Cloud Security Alliance", + "publication_date": "2026", + "event_date": null, + "original_url": "https://labs.cloudsecurityalliance.org/research/agentic-identity-governance-framework-v1/", + "canonical_url": "https://labs.cloudsecurityalliance.org/research/agentic-identity-governance-framework-v1/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Dedicated lifecycle and governance framework for agent identities.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Dedicated lifecycle and governance framework for agent identities.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-026", + "title": "Defining Non-Human Identity", + "source_type": "research_report", + "work_or_episode_identity": "Defining Non-Human Identity", + "author_or_speaker": "Cloud Security Alliance", + "publisher": "Cloud Security Alliance", + "publication_date": null, + "event_date": null, + "original_url": "https://cloudsecurityalliance.org/artifacts/defining-non-human-identity", + "canonical_url": "https://cloudsecurityalliance.org/artifacts/defining-non-human-identity", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Provides terminology needed to compare agent and workload identity models.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Provides terminology needed to compare agent and workload identity models.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-027", + "title": "Identity Management for Agentic AI", + "source_type": "research_report", + "work_or_episode_identity": "Identity Management for Agentic AI", + "author_or_speaker": "Tobin South and contributors", + "publisher": "OpenID Foundation", + "publication_date": "2025-10", + "event_date": null, + "original_url": "https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf", + "canonical_url": "https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Detailed multi-author identity, delegation, authentication, and authorization treatment.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Detailed multi-author identity, delegation, authentication, and authorization treatment.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-031", + "title": "Model AI Governance Framework for Agentic AI", + "source_type": "public_policy_document", + "work_or_episode_identity": "Model AI Governance Framework for Agentic AI", + "author_or_speaker": "IMDA Singapore", + "publisher": "IMDA Singapore", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/press-releases/2026/new-model-ai-governance-framework-for-agentic-ai", + "canonical_url": "https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/press-releases/2026/new-model-ai-governance-framework-for-agentic-ai", + "language": "lang-en", + "relevant_geographies": [ + "Singapore", + "geo-global" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Primary national framework covering bounded autonomy and accountable deployment.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary national framework covering bounded autonomy and accountable deployment.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-032", + "title": "AI Agents: Insights from the Singapore Government and Google Sandbox", + "source_type": "research_report", + "work_or_episode_identity": "AI Agents: Insights from the Singapore Government and Google Sandbox", + "author_or_speaker": "IMDA Singapore and Google", + "publisher": "IMDA Singapore", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/factsheets/2026/ai-agents-insights-from-the-singapore-government-and-google-sandbox", + "canonical_url": "https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/factsheets/2026/ai-agents-insights-from-the-singapore-government-and-google-sandbox", + "language": "lang-en", + "relevant_geographies": [ + "Singapore", + "geo-global" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Operational public-sector sandbox evidence from a non-US jurisdiction.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Operational public-sector sandbox evidence from a non-US jurisdiction.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-033", + "title": "Careful adoption of agentic AI services", + "source_type": "public_policy_document", + "work_or_episode_identity": "Careful adoption of agentic AI services", + "author_or_speaker": "Australian Government", + "publisher": "Australian Government", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services", + "canonical_url": "https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services", + "language": "lang-en", + "relevant_geographies": [ + "Australia" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Cross-agency security guidance covers credentials, access, monitoring, and responsibility.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Cross-agency security guidance covers credentials, access, monitoring, and responsibility.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-034", + "title": "Agentic AI addendum: background", + "source_type": "public_policy_document", + "work_or_episode_identity": "Agentic AI addendum: background", + "author_or_speaker": "Digital Transformation Agency", + "publisher": "Australian Government", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.digital.gov.au/policy/ai/agentic-ai-addendum-background", + "canonical_url": "https://www.digital.gov.au/policy/ai/agentic-ai-addendum-background", + "language": "lang-en", + "relevant_geographies": [ + "Australia" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Official policy rationale for governing public-sector agent deployments.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Official policy rationale for governing public-sector agent deployments.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-035", + "title": "Guide on the use of agentic artificial intelligence", + "source_type": "public_policy_document", + "work_or_episode_identity": "Guide on the use of agentic artificial intelligence", + "author_or_speaker": "Government of Canada", + "publisher": "Government of Canada", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/guide-use-agentic-artificial-intelligence.html", + "canonical_url": "https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/guide-use-agentic-artificial-intelligence.html", + "language": "lang-en", + "relevant_geographies": [ + "Canada" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Primary federal operational guidance with access and accountability implications.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary federal operational guidance with access and accountability implications.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-036", + "title": "Guide to using AI agents in NSW Government", + "source_type": "public_policy_document", + "work_or_episode_identity": "Guide to using AI agents in NSW Government", + "author_or_speaker": "Digital NSW", + "publisher": "NSW Government", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.digital.nsw.gov.au/policy/artificial-intelligence/guide-to-using-ai-agents-nsw-government", + "canonical_url": "https://www.digital.nsw.gov.au/policy/artificial-intelligence/guide-to-using-ai-agents-nsw-government", + "language": "lang-en", + "relevant_geographies": [ + "Australia" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Concrete subnational public-sector governance guidance.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Concrete subnational public-sector governance guidance.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-037", + "title": "Agentic AI and consumers", + "source_type": "public_policy_document", + "work_or_episode_identity": "Agentic AI and consumers", + "author_or_speaker": "UK Government", + "publisher": "UK Government", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.gov.uk/government/publications/agentic-ai-and-consumers/agentic-ai-and-consumers", + "canonical_url": "https://www.gov.uk/government/publications/agentic-ai-and-consumers/agentic-ai-and-consumers", + "language": "lang-en", + "relevant_geographies": [ + "United Kingdom" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Public-authority analysis of agency, consent, authentication, and accountability in consumer contexts.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Public-authority analysis of agency, consent, authentication, and accountability in consumer contexts.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-040", + "title": "AI Agents in Action: A Playbook for Trusted Adoption, Authorization and Scaling", + "source_type": "research_report", + "work_or_episode_identity": "AI Agents in Action: A Playbook for Trusted Adoption, Authorization and Scaling", + "author_or_speaker": "World Economic Forum and Capgemini", + "publisher": "World Economic Forum", + "publication_date": "2026-05-26", + "event_date": null, + "original_url": "https://www.weforum.org/publications/ai-agents-in-action-a-playbook-for-trusted-adoption-authorization-and-scaling/", + "canonical_url": "https://www.weforum.org/publications/ai-agents-in-action-a-playbook-for-trusted-adoption-authorization-and-scaling/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-board-director", + "role-ceo", + "role-ciso", + "role-general-counsel" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Introduces an explicit agent capability and authorization profile.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Introduces an explicit agent capability and authorization profile.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-041", + "title": "From systems of record to systems of trust: a board-level playbook for governing agentic AI", + "source_type": "essay", + "work_or_episode_identity": "From systems of record to systems of trust: a board-level playbook for governing agentic AI", + "author_or_speaker": "Rohan Sharma", + "publisher": "World Economic Forum", + "publication_date": "2026-04-28", + "event_date": null, + "original_url": "https://www.weforum.org/stories/artificial-intelligence/board-playbook-governing-agentic-ai/", + "canonical_url": "https://www.weforum.org/stories/artificial-intelligence/board-playbook-governing-agentic-ai/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-board-director", + "role-ceo", + "role-ciso", + "role-general-counsel" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Distinct board perspective on boundaries of delegation and human authorization.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Distinct board perspective on boundaries of delegation and human authorization.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-042", + "title": "From chatbots to personal assistants: how governance is key to harnessing AI agents", + "source_type": "essay", + "work_or_episode_identity": "From chatbots to personal assistants: how governance is key to harnessing AI agents", + "author_or_speaker": "Cathy Li and Benjamin Larsen", + "publisher": "World Economic Forum", + "publication_date": "2026-03-16", + "event_date": null, + "original_url": "https://www.weforum.org/stories/artificial-intelligence/ai-agent-autonomy-governance/", + "canonical_url": "https://www.weforum.org/stories/artificial-intelligence/ai-agent-autonomy-governance/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-board-director", + "role-ceo", + "role-ciso", + "role-general-counsel" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Frames autonomy and authority as adjustable governance variables.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Frames autonomy and authority as adjustable governance variables.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-043", + "title": "Three high-impact identity strategies for security leaders in the age of AI", + "source_type": "essay", + "work_or_episode_identity": "Three high-impact identity strategies for security leaders in the age of AI", + "author_or_speaker": "ISACA contributor", + "publisher": "ISACA", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2026/three-high-impact-identity-strategies-for-security-leaders-in-the-age-of-ai", + "canonical_url": "https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2026/three-high-impact-identity-strategies-for-security-leaders-in-the-age-of-ai", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Independent professional-association guidance on least privilege, short-lived credentials, and audit.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Independent professional-association guidance on least privilege, short-lived credentials, and audit.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-045", + "title": "Identity Management for Agentic AI: The New Frontier of Authorization, Authentication, and Security", + "source_type": "academic_paper", + "work_or_episode_identity": "Identity Management for Agentic AI: The New Frontier of Authorization, Authentication, and Security", + "author_or_speaker": "Tobin South et al.", + "publisher": "arXiv / OpenID Foundation authors", + "publication_date": "2025-10", + "event_date": null, + "original_url": "https://arxiv.org/abs/2510.25819", + "canonical_url": "https://arxiv.org/abs/2510.25819", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Research version of a central agent-identity framework; related-work linkage recorded.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [ + "candidate-BATCH-2026-001-027" + ], + "decision": "accept", + "reason": "Research version of a central agent-identity framework; related-work linkage recorded.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-046", + "title": "Authorization Propagation in Multi-Agent AI Systems", + "source_type": "working_paper", + "work_or_episode_identity": "Authorization Propagation in Multi-Agent AI Systems", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2026-05", + "event_date": null, + "original_url": "https://arxiv.org/abs/2605.05440", + "canonical_url": "https://arxiv.org/abs/2605.05440", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Direct formal treatment of authorization across delegated agent chains.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Direct formal treatment of authorization across delegated agent chains.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-047", + "title": "SAGA: A Security Architecture for Governing AI Agents", + "source_type": "working_paper", + "work_or_episode_identity": "SAGA: A Security Architecture for Governing AI Agents", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2025-04", + "event_date": null, + "original_url": "https://arxiv.org/abs/2504.21034", + "canonical_url": "https://arxiv.org/abs/2504.21034", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Proposes a governance architecture centered on agent identity and policy enforcement.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Proposes a governance architecture centered on agent identity and policy enforcement.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-048", + "title": "AgentGuardian: Runtime Security and Governance for AI Agents", + "source_type": "working_paper", + "work_or_episode_identity": "AgentGuardian: Runtime Security and Governance for AI Agents", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2026-01", + "event_date": null, + "original_url": "https://arxiv.org/abs/2601.10440", + "canonical_url": "https://arxiv.org/abs/2601.10440", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Runtime-control approach relevant to identity-aware enforcement and audit.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Runtime-control approach relevant to identity-aware enforcement and audit.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-049", + "title": "Personhood Credentials: Artificial Intelligence and the Value of Privacy-Preserving Tools to Distinguish Who Is Real Online", + "source_type": "academic_paper", + "work_or_episode_identity": "Personhood Credentials: Artificial Intelligence and the Value of Privacy-Preserving Tools to Distinguish Who Is Real Online", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-08", + "event_date": null, + "original_url": "https://arxiv.org/abs/2408.07892", + "canonical_url": "https://arxiv.org/abs/2408.07892", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Important counterpoint distinguishing human personhood from agent identity.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Important counterpoint distinguishing human personhood from agent identity.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-050", + "title": "AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents", + "source_type": "academic_paper", + "work_or_episode_identity": "AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-06", + "event_date": null, + "original_url": "https://arxiv.org/abs/2406.13352", + "canonical_url": "https://arxiv.org/abs/2406.13352", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Empirical benchmark for agent misuse under delegated tool access.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Empirical benchmark for agent misuse under delegated tool access.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-051", + "title": "AI Agents Under Threat: A Survey of Key Security Challenges and Future Pathways", + "source_type": "academic_paper", + "work_or_episode_identity": "AI Agents Under Threat: A Survey of Key Security Challenges and Future Pathways", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-06", + "event_date": null, + "original_url": "https://arxiv.org/abs/2406.02630", + "canonical_url": "https://arxiv.org/abs/2406.02630", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Broad security survey useful for mapping identity-related attack surfaces.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Broad security survey useful for mapping identity-related attack surfaces.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-054", + "title": "ASB: A Comprehensive Benchmark for Evaluating Security of LLM Agents", + "source_type": "academic_paper", + "work_or_episode_identity": "ASB: A Comprehensive Benchmark for Evaluating Security of LLM Agents", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-10", + "event_date": null, + "original_url": "https://arxiv.org/abs/2410.02644", + "canonical_url": "https://arxiv.org/abs/2410.02644", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Benchmark contributes evidence about unauthorized and unsafe agent actions.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Benchmark contributes evidence about unauthorized and unsafe agent actions.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-055", + "title": "InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents", + "source_type": "academic_paper", + "work_or_episode_identity": "InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-03", + "event_date": null, + "original_url": "https://arxiv.org/abs/2403.02691", + "canonical_url": "https://arxiv.org/abs/2403.02691", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Empirical evidence on agents misusing authorized tools after hostile input.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Empirical evidence on agents misusing authorized tools after hostile input.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-056", + "title": "ToolEmu: Identifying the Risks of LM Agents with an LM-Emulated Sandbox", + "source_type": "academic_paper", + "work_or_episode_identity": "ToolEmu: Identifying the Risks of LM Agents with an LM-Emulated Sandbox", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2023-09", + "event_date": null, + "original_url": "https://arxiv.org/abs/2309.15817", + "canonical_url": "https://arxiv.org/abs/2309.15817", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Empirical risk evaluation for agents acting through tools.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Empirical risk evaluation for agents acting through tools.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-057", + "title": "ToolSandbox: A Stateful, Conversational, Interactive Evaluation Benchmark for LLM Tool Use Capabilities", + "source_type": "academic_paper", + "work_or_episode_identity": "ToolSandbox: A Stateful, Conversational, Interactive Evaluation Benchmark for LLM Tool Use Capabilities", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-08", + "event_date": null, + "original_url": "https://arxiv.org/abs/2408.04682", + "canonical_url": "https://arxiv.org/abs/2408.04682", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Supports evaluation of permissions and stateful tool interactions.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Supports evaluation of permissions and stateful tool interactions.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-058", + "title": "Teams of LLM Agents Can Exploit Zero-Day Vulnerabilities", + "source_type": "academic_paper", + "work_or_episode_identity": "Teams of LLM Agents Can Exploit Zero-Day Vulnerabilities", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-06", + "event_date": null, + "original_url": "https://arxiv.org/abs/2406.01637", + "canonical_url": "https://arxiv.org/abs/2406.01637", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Adversarial evidence showing why bounded authority and monitoring matter.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Adversarial evidence showing why bounded authority and monitoring matter.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-059", + "title": "The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions", + "source_type": "academic_paper", + "work_or_episode_identity": "The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-04", + "event_date": null, + "original_url": "https://arxiv.org/abs/2404.13208", + "canonical_url": "https://arxiv.org/abs/2404.13208", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Evidence for enforcing authority boundaries among instruction sources.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Evidence for enforcing authority boundaries among instruction sources.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-060", + "title": "Secure Agent-to-Agent Application", + "source_type": "working_paper", + "work_or_episode_identity": "Secure Agent-to-Agent Application", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2025-04", + "event_date": null, + "original_url": "https://arxiv.org/abs/2504.16902", + "canonical_url": "https://arxiv.org/abs/2504.16902", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Directly addresses secure cross-agent communication and trust.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Directly addresses secure cross-agent communication and trust.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-061", + "title": "AAGATE: Authentication and Authorization for Agentic AI", + "source_type": "working_paper", + "work_or_episode_identity": "AAGATE: Authentication and Authorization for Agentic AI", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2025-10", + "event_date": null, + "original_url": "https://arxiv.org/abs/2510.25863", + "canonical_url": "https://arxiv.org/abs/2510.25863", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Direct agent authentication and authorization architecture.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Direct agent authentication and authorization architecture.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-062", + "title": "A Sensitive Data Protection Proposal for Agent2Agent Protocol", + "source_type": "working_paper", + "work_or_episode_identity": "A Sensitive Data Protection Proposal for Agent2Agent Protocol", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2025-05", + "event_date": null, + "original_url": "https://arxiv.org/abs/2505.12490", + "canonical_url": "https://arxiv.org/abs/2505.12490", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Connects agent identity and delegated exchange to data protection.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Connects agent identity and delegated exchange to data protection.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-064", + "title": "A Survey of Agent Interoperability Protocols: Model Context Protocol, Agent Communication Protocol, and Agent-to-Agent Protocol", + "source_type": "working_paper", + "work_or_episode_identity": "A Survey of Agent Interoperability Protocols: Model Context Protocol, Agent Communication Protocol, and Agent-to-Agent Protocol", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2025-05", + "event_date": null, + "original_url": "https://arxiv.org/abs/2505.02279", + "canonical_url": "https://arxiv.org/abs/2505.02279", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Maps protocol trust boundaries that shape identity portability.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Maps protocol trust boundaries that shape identity portability.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-065", + "title": "Identity and Access Gaps in the Age of Autonomous AI", + "source_type": "executive_survey", + "work_or_episode_identity": "Identity and Access Gaps in the Age of Autonomous AI", + "author_or_speaker": "Cloud Security Alliance research analysts", + "publisher": "Cloud Security Alliance / Aembit", + "publication_date": "2026-03-24", + "event_date": null, + "original_url": "https://cloudsecurityalliance.org/press-releases/2026/03/24/more-than-two-thirds-of-organizations-cannot-clearly-distinguish-ai-agent-from-human-actions", + "canonical_url": "https://cloudsecurityalliance.org/press-releases/2026/03/24/more-than-two-thirds-of-organizations-cannot-clearly-distinguish-ai-agent-from-human-actions", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-board-director", + "role-ceo" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "methods_and_sample_disclosed", + "source_identity_stability": "high", + "evidence_contribution": "Discloses sponsor, questionnaire role, field date, sample size, and identity findings.", + "diversity_contribution": [ + "empirical evidence", + "sponsor-disclosed research" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Discloses sponsor, questionnaire role, field date, sample size, and identity findings.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q036", + "Q037" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-066", + "title": "The State of Non-Human Identity and AI Security", + "source_type": "executive_survey", + "work_or_episode_identity": "The State of Non-Human Identity and AI Security", + "author_or_speaker": "Cloud Security Alliance", + "publisher": "Cloud Security Alliance / Oasis Security", + "publication_date": "2026-01-26", + "event_date": null, + "original_url": "https://cloudsecurityalliance.org/artifacts/state-of-nhi-and-ai-security-survey-report", + "canonical_url": "https://cloudsecurityalliance.org/artifacts/state-of-nhi-and-ai-security-survey-report", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-board-director", + "role-ceo" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "methods_and_sample_disclosed", + "source_identity_stability": "high", + "evidence_contribution": "Data-driven view of ownership, lifecycle, inventory, and legacy-IAM gaps; sponsorship is explicit.", + "diversity_contribution": [ + "empirical evidence", + "sponsor-disclosed research" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Data-driven view of ownership, lifecycle, inventory, and legacy-IAM gaps; sponsorship is explicit.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q036", + "Q037" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-067", + "title": "Securing Autonomous AI Agents", + "source_type": "executive_survey", + "work_or_episode_identity": "Securing Autonomous AI Agents", + "author_or_speaker": "Cloud Security Alliance", + "publisher": "Cloud Security Alliance / Strata Identity", + "publication_date": "2026-02-04", + "event_date": null, + "original_url": "https://cloudsecurityalliance.org/artifacts/securing-autonomous-ai-agents", + "canonical_url": "https://cloudsecurityalliance.org/artifacts/securing-autonomous-ai-agents", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-board-director", + "role-ceo" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "methods_and_sample_disclosed", + "source_identity_stability": "high", + "evidence_contribution": "Reports adoption, registry, credentials, traceability, and budget evidence with sponsor disclosure.", + "diversity_contribution": [ + "empirical evidence", + "sponsor-disclosed research" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Reports adoption, registry, credentials, traceability, and budget evidence with sponsor disclosure.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q036", + "Q037" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-068", + "title": "The State of Application Strategy in 2026", + "source_type": "executive_survey", + "work_or_episode_identity": "The State of Application Strategy in 2026", + "author_or_speaker": "F5 Research", + "publisher": "F5", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.f5.com/resources/reports/state-of-application-strategy-report", + "canonical_url": "https://www.f5.com/resources/reports/state-of-application-strategy-report", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-board-director", + "role-ceo" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "methods_and_sample_disclosed", + "source_identity_stability": "high", + "evidence_contribution": "More than 1,100 IT decision makers; includes agent identity growth, authentication, and audit concerns.", + "diversity_contribution": [ + "empirical evidence", + "sponsor-disclosed research" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "More than 1,100 IT decision makers; includes agent identity growth, authentication, and audit concerns.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q036", + "Q037" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-070", + "title": "Microsoft Entra Agent ID: agent identities", + "source_type": "other_approved", + "work_or_episode_identity": "Microsoft Entra Agent ID: agent identities", + "author_or_speaker": "Microsoft", + "publisher": "Microsoft", + "publication_date": "2026", + "event_date": null, + "original_url": "https://learn.microsoft.com/en-us/entra/agent-id/agent-identities", + "canonical_url": "https://learn.microsoft.com/en-us/entra/agent-id/agent-identities", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary product documentation illustrates current agent identity object models.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary product documentation illustrates current agent identity object models.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-071", + "title": "Manage agent identities as an administrator", + "source_type": "other_approved", + "work_or_episode_identity": "Manage agent identities as an administrator", + "author_or_speaker": "Microsoft", + "publisher": "Microsoft", + "publication_date": "2026", + "event_date": null, + "original_url": "https://learn.microsoft.com/en-us/entra/agent-id/manage-agent-identities-admin", + "canonical_url": "https://learn.microsoft.com/en-us/entra/agent-id/manage-agent-identities-admin", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Operational lifecycle, inventory, and administrative control guidance.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Operational lifecycle, inventory, and administrative control guidance.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-072", + "title": "What are agent identities?", + "source_type": "other_approved", + "work_or_episode_identity": "What are agent identities?", + "author_or_speaker": "Microsoft", + "publisher": "Microsoft", + "publication_date": "2026", + "event_date": null, + "original_url": "https://learn.microsoft.com/en-us/entra/agent-id/what-are-agent-identities", + "canonical_url": "https://learn.microsoft.com/en-us/entra/agent-id/what-are-agent-identities", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Defines Microsoft agent and blueprint identity semantics.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Defines Microsoft agent and blueprint identity semantics.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-073", + "title": "Autonomous agent authentication and authorization flow", + "source_type": "other_approved", + "work_or_episode_identity": "Autonomous agent authentication and authorization flow", + "author_or_speaker": "Microsoft", + "publisher": "Microsoft", + "publication_date": "2026", + "event_date": null, + "original_url": "https://learn.microsoft.com/en-us/entra/agent-id/autonomous-agent-authentication-authorization-flow", + "canonical_url": "https://learn.microsoft.com/en-us/entra/agent-id/autonomous-agent-authentication-authorization-flow", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Concrete authorization-flow implementation reference.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Concrete authorization-flow implementation reference.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-074", + "title": "Configure third-party agents with Microsoft Entra Agent ID", + "source_type": "other_approved", + "work_or_episode_identity": "Configure third-party agents with Microsoft Entra Agent ID", + "author_or_speaker": "Microsoft", + "publisher": "Microsoft", + "publication_date": "2026", + "event_date": null, + "original_url": "https://learn.microsoft.com/en-us/entra/agent-id/configure-third-party-agents", + "canonical_url": "https://learn.microsoft.com/en-us/entra/agent-id/configure-third-party-agents", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Cross-vendor onboarding and lifecycle example.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Cross-vendor onboarding and lifecycle example.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-075", + "title": "Agent identity overview", + "source_type": "other_approved", + "work_or_episode_identity": "Agent identity overview", + "author_or_speaker": "Google Cloud", + "publisher": "Google Cloud", + "publication_date": "2026", + "event_date": null, + "original_url": "https://docs.cloud.google.com/iam/docs/agent-identity-overview?hl=en", + "canonical_url": "https://docs.cloud.google.com/iam/docs/agent-identity-overview?hl=en", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary cloud documentation for managed agent identities and policy.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary cloud documentation for managed agent identities and policy.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-076", + "title": "What is new in IAM: security, governance, and runtime defense", + "source_type": "essay", + "work_or_episode_identity": "What is new in IAM: security, governance, and runtime defense", + "author_or_speaker": "Google Cloud", + "publisher": "Google Cloud", + "publication_date": "2026", + "event_date": null, + "original_url": "https://cloud.google.com/blog/products/identity-security/whats-new-in-iam-security-governance-and-runtime-defense", + "canonical_url": "https://cloud.google.com/blog/products/identity-security/whats-new-in-iam-security-governance-and-runtime-defense", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Operator view of governance and runtime controls for agents.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Operator view of governance and runtime controls for agents.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-077", + "title": "Multi-tenant agentic AI system architecture", + "source_type": "other_approved", + "work_or_episode_identity": "Multi-tenant agentic AI system architecture", + "author_or_speaker": "Google Cloud", + "publisher": "Google Cloud", + "publication_date": "2026", + "event_date": null, + "original_url": "https://docs.cloud.google.com/architecture/multi-tenant-agentic-ai-system", + "canonical_url": "https://docs.cloud.google.com/architecture/multi-tenant-agentic-ai-system", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Architectural evidence on tenant isolation and identity boundaries.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Architectural evidence on tenant isolation and identity boundaries.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-078", + "title": "AI agent security: how to protect digital sidekicks and your business", + "source_type": "essay", + "work_or_episode_identity": "AI agent security: how to protect digital sidekicks and your business", + "author_or_speaker": "Google Cloud", + "publisher": "Google Cloud", + "publication_date": "2025", + "event_date": null, + "original_url": "https://cloud.google.com/transform/ai-agent-security-how-to-protect-digital-sidekicks-and-your-business", + "canonical_url": "https://cloud.google.com/transform/ai-agent-security-how-to-protect-digital-sidekicks-and-your-business", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Executive-friendly operator perspective on agent access and trust.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Executive-friendly operator perspective on agent access and trust.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-079", + "title": "Agent2Agent protocol specification", + "source_type": "other_approved", + "work_or_episode_identity": "Agent2Agent protocol specification", + "author_or_speaker": "A2A Project", + "publisher": "A2A Project / Linux Foundation", + "publication_date": "2026", + "event_date": null, + "original_url": "https://google-a2a.github.io/A2A/specification/", + "canonical_url": "https://google-a2a.github.io/A2A/specification/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Canonical interoperability specification with authentication and authorization implications.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Canonical interoperability specification with authentication and authorization implications.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-080", + "title": "Amazon Bedrock AgentCore Identity", + "source_type": "other_approved", + "work_or_episode_identity": "Amazon Bedrock AgentCore Identity", + "author_or_speaker": "Amazon Web Services", + "publisher": "Amazon Web Services", + "publication_date": "2026", + "event_date": null, + "original_url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity.html", + "canonical_url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary operator documentation for agent credential and authorization flows.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary operator documentation for agent credential and authorization flows.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-081", + "title": "Four security principles for agentic AI systems", + "source_type": "essay", + "work_or_episode_identity": "Four security principles for agentic AI systems", + "author_or_speaker": "AWS Security", + "publisher": "Amazon Web Services", + "publication_date": "2025", + "event_date": null, + "original_url": "https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/", + "canonical_url": "https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Clear operator principles for unique identity, least privilege, and observability.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Clear operator principles for unique identity, least privilege, and observability.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-082", + "title": "AWS AI Security Framework", + "source_type": "research_report", + "work_or_episode_identity": "AWS AI Security Framework", + "author_or_speaker": "AWS Security", + "publisher": "Amazon Web Services", + "publication_date": "2025", + "event_date": null, + "original_url": "https://aws.amazon.com/blogs/security/the-aws-ai-security-framework-securing-ai-with-the-right-controls-at-the-right-layers-at-the-right-phases/", + "canonical_url": "https://aws.amazon.com/blogs/security/the-aws-ai-security-framework-securing-ai-with-the-right-controls-at-the-right-layers-at-the-right-phases/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Structured controls across lifecycle layers, with identity as a key control plane.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Structured controls across lifecycle layers, with identity as a key control plane.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-083", + "title": "AgentCore identity common use cases and authorization patterns", + "source_type": "other_approved", + "work_or_episode_identity": "AgentCore identity common use cases and authorization patterns", + "author_or_speaker": "Amazon Web Services", + "publisher": "Amazon Web Services", + "publication_date": "2026", + "event_date": null, + "original_url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/common-use-cases.html", + "canonical_url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/common-use-cases.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Concrete patterns for user delegation and outbound agent access.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Concrete patterns for user delegation and outbound agent access.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-084", + "title": "A Practical Guide to Building AI Agents", + "source_type": "essay", + "work_or_episode_identity": "A Practical Guide to Building AI Agents", + "author_or_speaker": "OpenAI", + "publisher": "OpenAI", + "publication_date": "2025", + "event_date": null, + "original_url": "https://openai.com/business/guides-and-resources/a-practical-guide-to-building-ai-agents/", + "canonical_url": "https://openai.com/business/guides-and-resources/a-practical-guide-to-building-ai-agents/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary builder perspective on guardrails and tool permissions.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary builder perspective on guardrails and tool permissions.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-085", + "title": "Practices for Governing Agentic AI Systems", + "source_type": "research_report", + "work_or_episode_identity": "Practices for Governing Agentic AI Systems", + "author_or_speaker": "OpenAI", + "publisher": "OpenAI", + "publication_date": "2023", + "event_date": null, + "original_url": "https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf", + "canonical_url": "https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Early governance paper focused on responsible parties and indirect controls.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Early governance paper focused on responsible parties and indirect controls.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-086", + "title": "Running Codex safely", + "source_type": "essay", + "work_or_episode_identity": "Running Codex safely", + "author_or_speaker": "OpenAI", + "publisher": "OpenAI", + "publication_date": "2026", + "event_date": null, + "original_url": "https://openai.com/index/running-codex-safely/", + "canonical_url": "https://openai.com/index/running-codex-safely/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Concrete deployment case on sandboxing, authorization boundaries, and human control.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Concrete deployment case on sandboxing, authorization boundaries, and human control.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-087", + "title": "Runtime identity for AI agents", + "source_type": "essay", + "work_or_episode_identity": "Runtime identity for AI agents", + "author_or_speaker": "Ping Identity", + "publisher": "Ping Identity", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.pingidentity.com/en/resources/blog/post/runtime-identity.html", + "canonical_url": "https://www.pingidentity.com/en/resources/blog/post/runtime-identity.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Specialist IAM view of contextual runtime identity.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Specialist IAM view of contextual runtime identity.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-088", + "title": "IAM best practices for AI agents", + "source_type": "essay", + "work_or_episode_identity": "IAM best practices for AI agents", + "author_or_speaker": "Ping Identity", + "publisher": "Ping Identity", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/iam-best-practices-ai-agents.html", + "canonical_url": "https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/iam-best-practices-ai-agents.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Practical identity lifecycle and least-privilege guidance.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Practical identity lifecycle and least-privilege guidance.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-089", + "title": "What is AI agent identity?", + "source_type": "essay", + "work_or_episode_identity": "What is AI agent identity?", + "author_or_speaker": "Okta", + "publisher": "Okta", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.okta.com/en-gb/identity-101/what-is-ai-agent-identity/", + "canonical_url": "https://www.okta.com/en-gb/identity-101/what-is-ai-agent-identity/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Specialist IAM taxonomy and executive orientation.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Specialist IAM taxonomy and executive orientation.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-091", + "title": "Agent Identity Security documentation", + "source_type": "other_approved", + "work_or_episode_identity": "Agent Identity Security documentation", + "author_or_speaker": "SailPoint", + "publisher": "SailPoint", + "publication_date": "2026", + "event_date": null, + "original_url": "https://documentation.sailpoint.com/saas/help/agent/index.html", + "canonical_url": "https://documentation.sailpoint.com/saas/help/agent/index.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary lifecycle and governance implementation documentation.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary lifecycle and governance implementation documentation.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-092", + "title": "Governing AI agents: an identity security strategy", + "source_type": "essay", + "work_or_episode_identity": "Governing AI agents: an identity security strategy", + "author_or_speaker": "SailPoint", + "publisher": "SailPoint", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.sailpoint.com/blog/governing-ai-agents-identity-security-strategy", + "canonical_url": "https://www.sailpoint.com/blog/governing-ai-agents-identity-security-strategy", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Specialist practitioner model for inventory, ownership, and access review.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Specialist practitioner model for inventory, ownership, and access review.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-094", + "title": "AI agents and identity risks: how security will shift in 2026", + "source_type": "essay", + "work_or_episode_identity": "AI agents and identity risks: how security will shift in 2026", + "author_or_speaker": "CyberArk", + "publisher": "CyberArk", + "publication_date": "2025", + "event_date": null, + "original_url": "https://www.cyberark.com/resources/identity-security/ai-agents-and-identity-risks-how-security-will-shift-in-2026", + "canonical_url": "https://www.cyberark.com/resources/identity-security/ai-agents-and-identity-risks-how-security-will-shift-in-2026", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Security-lab and practitioner perspective on agent privilege and attack paths.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Security-lab and practitioner perspective on agent privilege and attack paths.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-095", + "title": "Solving the Bottom Turtle: a SPIFFE Way to Establish Trust in Your Infrastructure via Universal Identity", + "source_type": "book", + "work_or_episode_identity": "Solving the Bottom Turtle: a SPIFFE Way to Establish Trust in Your Infrastructure via Universal Identity", + "author_or_speaker": "Evan Gilman and Doug Barth", + "publisher": "SPIFFE Project", + "publication_date": "2020", + "event_date": null, + "original_url": "https://spiffe.io/book/", + "canonical_url": "https://spiffe.io/book/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Openly available foundational workload-identity book directly applicable to agent infrastructure.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Openly available foundational workload-identity book directly applicable to agent infrastructure.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-096", + "title": "Zero Trust Networks, Second Edition", + "source_type": "book", + "work_or_episode_identity": "Zero Trust Networks, Second Edition", + "author_or_speaker": "Evan Gilman and Doug Barth", + "publisher": "O’Reilly Media", + "publication_date": "2021", + "event_date": null, + "original_url": "https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/titlepage01.html", + "canonical_url": "https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/titlepage01.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Foundational least-privilege, identity, and policy context.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Foundational least-privilege, identity, and policy context.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-097", + "title": "OAuth 2 in Action", + "source_type": "book", + "work_or_episode_identity": "OAuth 2 in Action", + "author_or_speaker": "Justin Richer and Antonio Sanso", + "publisher": "Manning", + "publication_date": "2017", + "event_date": null, + "original_url": "https://www.manning.com/books/oauth-2-in-action?query=OAuth+2+in+Action", + "canonical_url": "https://www.manning.com/books/oauth-2-in-action?query=OAuth+2+in+Action", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Foundational delegated-authorization reference retained under the earlier-work exception.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Foundational delegated-authorization reference retained under the earlier-work exception.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-098", + "title": "API Security in Action", + "source_type": "book", + "work_or_episode_identity": "API Security in Action", + "author_or_speaker": "Neil Madden", + "publisher": "Manning", + "publication_date": "2020", + "event_date": null, + "original_url": "https://www.manning.com/books/api-security-in-action?from=oreilly", + "canonical_url": "https://www.manning.com/books/api-security-in-action?from=oreilly", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Applied API authentication and authorization reference for agent tool access.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Applied API authentication and authorization reference for agent tool access.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-099", + "title": "Building Secure and Reliable Systems", + "source_type": "book", + "work_or_episode_identity": "Building Secure and Reliable Systems", + "author_or_speaker": "Heather Adkins et al.", + "publisher": "O’Reilly Media", + "publication_date": "2020", + "event_date": null, + "original_url": "https://www.oreilly.com/library/view/building-secure-and/9781492083115/", + "canonical_url": "https://www.oreilly.com/library/view/building-secure-and/9781492083115/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Operational governance, least privilege, and auditability foundation.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Operational governance, least privilege, and auditability foundation.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-100", + "title": "Identity in Modern Applications", + "source_type": "book", + "work_or_episode_identity": "Identity in Modern Applications", + "author_or_speaker": "Phillip J. Windley", + "publisher": "O’Reilly Media", + "publication_date": "2022", + "event_date": null, + "original_url": "https://www.oreilly.com/library/view/identity-in-modern/9781098107789/", + "canonical_url": "https://www.oreilly.com/library/view/identity-in-modern/9781098107789/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Modern identity architecture foundation for agent-specific comparison.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Modern identity architecture foundation for agent-specific comparison.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-101", + "title": "Solving Identity Management in Modern Applications", + "source_type": "book", + "work_or_episode_identity": "Solving Identity Management in Modern Applications", + "author_or_speaker": "Yvonne Wilson and Abhishek Hingnikar", + "publisher": "Apress", + "publication_date": "2019", + "event_date": null, + "original_url": "https://www.oreilly.com/library/view/solving-identity-management/9781484250952/", + "canonical_url": "https://www.oreilly.com/library/view/solving-identity-management/9781484250952/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Foundational identity lifecycle and protocol context under the earlier-work exception.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Foundational identity lifecycle and protocol context under the earlier-work exception.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-102", + "title": "Identity-Native Infrastructure Access Management", + "source_type": "book", + "work_or_episode_identity": "Identity-Native Infrastructure Access Management", + "author_or_speaker": "Ev Kontsevoy and Sakshyam Shah", + "publisher": "O’Reilly Media", + "publication_date": "2023", + "event_date": null, + "original_url": "https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/", + "canonical_url": "https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Direct infrastructure identity and access architecture relevant to agent runtimes.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Direct infrastructure identity and access architecture relevant to agent runtimes.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-104", + "title": "Identity at the Center #390: Identity Management for Agentic AI with Tobin South", + "source_type": "podcast_episode", + "work_or_episode_identity": "Identity at the Center #390: Identity Management for Agentic AI with Tobin South", + "author_or_speaker": "Tobin South; Jim McDonald; Jeff Steadman", + "publisher": "Identity at the Center", + "publication_date": "2025-12-08", + "event_date": null, + "original_url": "https://podfollow.com/1564331550/episode/e536a09c789954de12ec0ac798872a6c9933df2d/view", + "canonical_url": "https://podfollow.com/1564331550/episode/e536a09c789954de12ec0ac798872a6c9933df2d/view", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-board-director" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_media_or_event_metadata", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary long-form interview covers impersonation, delegation, liability, and oversight.", + "diversity_contribution": [ + "primary spoken perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary long-form interview covers impersonation, delegation, liability, and oversight.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q034", + "Q035" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-106", + "title": "Identity Management for Agentic AI — OpenID pre-IIW workshop", + "source_type": "conference_talk", + "work_or_episode_identity": "Identity Management for Agentic AI — OpenID pre-IIW workshop", + "author_or_speaker": "Tobin South", + "publisher": "OpenID Foundation", + "publication_date": "2025-10-20", + "event_date": "2025-10-20", + "original_url": "https://openid.net/wp-content/uploads/2025/10/Pre-IIW-Workshop-October-2025-1.pdf", + "canonical_url": "https://openid.net/wp-content/uploads/2025/10/Pre-IIW-Workshop-October-2025-1.pdf", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-board-director" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_media_or_event_metadata", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Official event agenda identifies a 30-minute primary presentation by the report lead.", + "diversity_contribution": [ + "primary spoken perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Official event agenda identifies a 30-minute primary presentation by the report lead.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q034", + "Q035" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-107", + "title": "Securing Non-Human Identities in the Age of AI Agents — CSA Summit at RSAC 2025", + "source_type": "conference_talk", + "work_or_episode_identity": "Securing Non-Human Identities in the Age of AI Agents — CSA Summit at RSAC 2025", + "author_or_speaker": "Alon Jackson and Albert Attias", + "publisher": "Cloud Security Alliance", + "publication_date": "2025-04-29", + "event_date": "2025-04-29", + "original_url": "https://cloudsecurityalliance.org/artifacts/securing-non-human-identities-in-the-age-of-ai-agents-rsac-2025", + "canonical_url": "https://cloudsecurityalliance.org/artifacts/securing-non-human-identities-in-the-age-of-ai-agents-rsac-2025", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-board-director" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_media_or_event_metadata", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Official event-hosted presentation focused directly on NHI growth and AI agents.", + "diversity_contribution": [ + "primary spoken perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Official event-hosted presentation focused directly on NHI growth and AI agents.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q034", + "Q035" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-109", + "title": "Governing AI Agents with Agent Identity Security", + "source_type": "video", + "work_or_episode_identity": "Governing AI Agents with Agent Identity Security", + "author_or_speaker": "Rachel Leighter / SailPoint video presenter", + "publisher": "SailPoint Developer Community", + "publication_date": "2025-11-20", + "event_date": null, + "original_url": "https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944", + "canonical_url": "https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-board-director" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_media_or_event_metadata", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary vendor-hosted practitioner demonstration and discussion.", + "diversity_contribution": [ + "primary spoken perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary vendor-hosted practitioner demonstration and discussion.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q034", + "Q035" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-110", + "title": "What Makes Agentic AI Identity So Different?", + "source_type": "conference_talk", + "work_or_episode_identity": "What Makes Agentic AI Identity So Different?", + "author_or_speaker": "John Kemp", + "publisher": "Identiverse", + "publication_date": "2026-06-16", + "event_date": "2026-06-16", + "original_url": "https://identiverse.com/idv26/session/?idvid=3931776", + "canonical_url": "https://identiverse.com/idv26/session/?idvid=3931776", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-board-director" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_media_or_event_metadata", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary financial-services identity practitioner session with explicit dissent from static identity models.", + "diversity_contribution": [ + "primary spoken perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary financial-services identity practitioner session with explicit dissent from static identity models.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q034", + "Q035" + ] + } +] diff --git a/staging/batches/BATCH-2026-001/candidate-source.schema.json b/staging/batches/BATCH-2026-001/candidate-source.schema.json new file mode 100644 index 0000000..b6f8981 --- /dev/null +++ b/staging/batches/BATCH-2026-001/candidate-source.schema.json @@ -0,0 +1,173 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "title": "OEII topic-discovery candidate", + "type": "object", + "additionalProperties": true, + "required": [ + "candidate_id", + "title", + "source_type", + "work_or_episode_identity", + "author_or_speaker", + "publisher", + "publication_date", + "event_date", + "original_url", + "canonical_url", + "language", + "relevant_geographies", + "relevant_roles", + "relevant_industries", + "relevant_topics", + "primary_or_secondary", + "analysis_access_status", + "rights_status", + "ownership_status", + "OFF_relationship", + "methodological_transparency", + "source_identity_stability", + "evidence_contribution", + "diversity_contribution", + "likely_duplicate", + "existing_related_records", + "decision", + "reason", + "next_research_action" + ], + "properties": { + "candidate_id": { + "type": "string", + "pattern": "^candidate-BATCH-2026-001-[0-9]{3}$" + }, + "title": { + "type": "string", + "minLength": 3 + }, + "source_type": { + "type": "string", + "minLength": 2 + }, + "work_or_episode_identity": { + "type": "string", + "minLength": 3 + }, + "author_or_speaker": { + "type": "string", + "minLength": 2 + }, + "publisher": { + "type": "string", + "minLength": 2 + }, + "publication_date": { + "type": [ + "string", + "null" + ] + }, + "event_date": { + "type": [ + "string", + "null" + ] + }, + "original_url": { + "type": "string", + "format": "uri" + }, + "canonical_url": { + "type": "string", + "format": "uri" + }, + "language": { + "const": "lang-en" + }, + "relevant_geographies": { + "type": "array", + "items": { + "type": "string" + }, + "uniqueItems": true + }, + "relevant_roles": { + "type": "array", + "items": { + "type": "string" + }, + "uniqueItems": true + }, + "relevant_industries": { + "type": "array", + "items": { + "type": "string" + }, + "uniqueItems": true + }, + "relevant_topics": { + "type": "array", + "items": { + "type": "string" + }, + "uniqueItems": true + }, + "primary_or_secondary": { + "type": "string" + }, + "analysis_access_status": { + "type": "string" + }, + "rights_status": { + "type": "string" + }, + "ownership_status": { + "type": "string" + }, + "OFF_relationship": { + "type": "string" + }, + "methodological_transparency": { + "type": "string" + }, + "source_identity_stability": { + "enum": [ + "high", + "moderate", + "low" + ] + }, + "evidence_contribution": { + "type": "string" + }, + "diversity_contribution": { + "type": "array", + "items": { + "type": "string" + }, + "uniqueItems": true + }, + "likely_duplicate": { + "type": "boolean" + }, + "existing_related_records": { + "type": "array", + "items": { + "type": "string" + } + }, + "decision": { + "enum": [ + "accept", + "hold", + "reject" + ] + }, + "reason": { + "type": "string", + "minLength": 10 + }, + "next_research_action": { + "type": "string", + "minLength": 10 + } + } +} diff --git a/staging/batches/BATCH-2026-001/candidate-sources.json b/staging/batches/BATCH-2026-001/candidate-sources.json new file mode 100644 index 0000000..ec28f44 --- /dev/null +++ b/staging/batches/BATCH-2026-001/candidate-sources.json @@ -0,0 +1,7246 @@ +[ + { + "candidate_id": "candidate-BATCH-2026-001-001", + "title": "NIST concept paper: Accelerating the Adoption of Software and AI Agent Identity and Authorization", + "source_type": "public_policy_document", + "work_or_episode_identity": "NIST concept paper: Accelerating the Adoption of Software and AI Agent Identity and Authorization", + "author_or_speaker": "NIST NCCoE", + "publisher": "NIST", + "publication_date": "2026-02-05", + "event_date": null, + "original_url": "https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd", + "canonical_url": "https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Directly frames software-agent identity and authorization adoption.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Directly frames software-agent identity and authorization adoption.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-002", + "title": "NIST AI Agent Standards Initiative", + "source_type": "public_policy_document", + "work_or_episode_identity": "NIST AI Agent Standards Initiative", + "author_or_speaker": "NIST", + "publisher": "NIST", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative", + "canonical_url": "https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Primary standards-program source with security and interoperability scope.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary standards-program source with security and interoperability scope.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-003", + "title": "Announcing the AI Agent Standards Initiative", + "source_type": "essay", + "work_or_episode_identity": "Announcing the AI Agent Standards Initiative", + "author_or_speaker": "NIST", + "publisher": "NIST", + "publication_date": "2026-02", + "event_date": null, + "original_url": "https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure", + "canonical_url": "https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Official announcement overlaps the initiative page and may add little distinct evidence.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Official announcement overlaps the initiative page and may add little distinct evidence.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-004", + "title": "CAISI request for information about securing AI agent systems", + "source_type": "public_policy_document", + "work_or_episode_identity": "CAISI request for information about securing AI agent systems", + "author_or_speaker": "NIST CAISI", + "publisher": "NIST", + "publication_date": "2026-01", + "event_date": null, + "original_url": "https://www.nist.gov/news-events/news/2026/01/caisi-issues-request-information-about-securing-ai-agent-systems", + "canonical_url": "https://www.nist.gov/news-events/news/2026/01/caisi-issues-request-information-about-securing-ai-agent-systems", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Primary public consultation source useful for requirement and dissent mapping.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary public consultation source useful for requirement and dissent mapping.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-005", + "title": "Summary analysis of responses regarding security considerations for AI agent systems", + "source_type": "research_report", + "work_or_episode_identity": "Summary analysis of responses regarding security considerations for AI agent systems", + "author_or_speaker": "NIST CAISI", + "publisher": "NIST", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.nist.gov/publications/summary-analysis-responses-request-information-regarding-security-considerations-ai", + "canonical_url": "https://www.nist.gov/publications/summary-analysis-responses-request-information-regarding-security-considerations-ai", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Synthesizes public responses and exposes areas of agreement and disagreement.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Synthesizes public responses and exposes areas of agreement and disagreement.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-006", + "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0)", + "source_type": "public_policy_document", + "work_or_episode_identity": "Artificial Intelligence Risk Management Framework (AI RMF 1.0)", + "author_or_speaker": "NIST", + "publisher": "NIST", + "publication_date": "2023-01-26", + "event_date": null, + "original_url": "https://www.nist.gov/itl/ai-risk-management-framework", + "canonical_url": "https://www.nist.gov/itl/ai-risk-management-framework", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Foundational governance framework applicable to ownership, monitoring, and accountability.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Foundational governance framework applicable to ownership, monitoring, and accountability.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-007", + "title": "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile", + "source_type": "public_policy_document", + "work_or_episode_identity": "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile", + "author_or_speaker": "NIST", + "publisher": "NIST", + "publication_date": "2024-07", + "event_date": null, + "original_url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf", + "canonical_url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Official risk profile with governance controls relevant to agent deployments.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Official risk profile with governance controls relevant to agent deployments.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-008", + "title": "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations", + "source_type": "research_report", + "work_or_episode_identity": "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations", + "author_or_speaker": "NIST", + "publisher": "NIST", + "publication_date": "2025", + "event_date": null, + "original_url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2025.pdf", + "canonical_url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2025.pdf", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Strong security taxonomy but agent-identity contribution is indirect.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Strong security taxonomy but agent-identity contribution is indirect.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-009", + "title": "AI Agent Authentication and Authorization", + "source_type": "working_paper", + "work_or_episode_identity": "AI Agent Authentication and Authorization", + "author_or_speaker": "IETF Internet-Draft authors", + "publisher": "IETF", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-02.html", + "canonical_url": "https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-02.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Direct protocol proposal for agent authentication and authorization; draft status retained.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Direct protocol proposal for agent authentication and authorization; draft status retained.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-010", + "title": "Agent Auditing Architecture", + "source_type": "working_paper", + "work_or_episode_identity": "Agent Auditing Architecture", + "author_or_speaker": "IETF Internet-Draft authors", + "publisher": "IETF", + "publication_date": "2026", + "event_date": null, + "original_url": "https://datatracker.ietf.org/doc/draft-kuehlewind-audit-architecture/", + "canonical_url": "https://datatracker.ietf.org/doc/draft-kuehlewind-audit-architecture/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Directly addresses traceability and audit architecture for agents.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Directly addresses traceability and audit architecture for agents.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-011", + "title": "Agent Operation Authorization", + "source_type": "working_paper", + "work_or_episode_identity": "Agent Operation Authorization", + "author_or_speaker": "IETF Internet-Draft authors", + "publisher": "IETF", + "publication_date": "2026", + "event_date": null, + "original_url": "https://datatracker.ietf.org/doc/draft-liu-agent-operation-authorization/", + "canonical_url": "https://datatracker.ietf.org/doc/draft-liu-agent-operation-authorization/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Directly addresses authorization of specific agent operations.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Directly addresses authorization of specific agent operations.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-012", + "title": "OAuth Actor Profile", + "source_type": "working_paper", + "work_or_episode_identity": "OAuth Actor Profile", + "author_or_speaker": "IETF Internet-Draft authors", + "publisher": "IETF", + "publication_date": "2025", + "event_date": null, + "original_url": "https://datatracker.ietf.org/doc/html/draft-mcguinness-oauth-actor-profile-00", + "canonical_url": "https://datatracker.ietf.org/doc/html/draft-mcguinness-oauth-actor-profile-00", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Provides an actor/delegation model relevant to agents acting for users.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Provides an actor/delegation model relevant to agents acting for users.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-013", + "title": "Workload Identity in Multi System Environments (WIMSE) session materials", + "source_type": "other_approved", + "work_or_episode_identity": "Workload Identity in Multi System Environments (WIMSE) session materials", + "author_or_speaker": "IETF WIMSE participants", + "publisher": "IETF", + "publication_date": "2024-03", + "event_date": null, + "original_url": "https://datatracker.ietf.org/meeting/119/session/wimse", + "canonical_url": "https://datatracker.ietf.org/meeting/119/session/wimse", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Foundational multi-system workload identity material with official meeting provenance.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Foundational multi-system workload identity material with official meeting provenance.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-014", + "title": "SPIFFE standards index", + "source_type": "other_approved", + "work_or_episode_identity": "SPIFFE standards index", + "author_or_speaker": "SPIFFE Project", + "publisher": "SPIFFE Project", + "publication_date": null, + "event_date": null, + "original_url": "https://spiffe.io/docs/latest/spiffe-specs/", + "canonical_url": "https://spiffe.io/docs/latest/spiffe-specs/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Canonical index for workload identity standards directly applicable to agent runtimes.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Canonical index for workload identity standards directly applicable to agent runtimes.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-015", + "title": "SPIFFE Workload API", + "source_type": "other_approved", + "work_or_episode_identity": "SPIFFE Workload API", + "author_or_speaker": "SPIFFE Project", + "publisher": "SPIFFE Project", + "publication_date": null, + "event_date": null, + "original_url": "https://spiffe.io/docs/latest/spiffe-specs/spiffe_workload_api/", + "canonical_url": "https://spiffe.io/docs/latest/spiffe-specs/spiffe_workload_api/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Defines issuance and rotation interfaces for workload credentials.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Defines issuance and rotation interfaces for workload credentials.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-016", + "title": "SPIFFE ID specification", + "source_type": "other_approved", + "work_or_episode_identity": "SPIFFE ID specification", + "author_or_speaker": "SPIFFE Project", + "publisher": "SPIFFE Project", + "publication_date": null, + "event_date": null, + "original_url": "https://spiffe.io/docs/latest/spiffe-specs/spiffe-id/", + "canonical_url": "https://spiffe.io/docs/latest/spiffe-specs/spiffe-id/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Defines stable workload identity names and trust domains.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Defines stable workload identity names and trust domains.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-017", + "title": "SPIFFE Federation specification", + "source_type": "other_approved", + "work_or_episode_identity": "SPIFFE Federation specification", + "author_or_speaker": "SPIFFE Project", + "publisher": "SPIFFE Project", + "publication_date": null, + "event_date": null, + "original_url": "https://spiffe.io/docs/latest/spiffe-specs/spiffe_federation/", + "canonical_url": "https://spiffe.io/docs/latest/spiffe-specs/spiffe_federation/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Supports cross-domain trust relevant to agent-to-agent interactions.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Supports cross-domain trust relevant to agent-to-agent interactions.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-018", + "title": "SPIFFE concepts overview", + "source_type": "other_approved", + "work_or_episode_identity": "SPIFFE concepts overview", + "author_or_speaker": "SPIFFE Project", + "publisher": "SPIFFE Project", + "publication_date": null, + "event_date": null, + "original_url": "https://spiffe.io/docs/latest/spiffe/concepts/", + "canonical_url": "https://spiffe.io/docs/latest/spiffe/concepts/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Useful orientation but largely duplicates individual specifications.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Useful orientation but largely duplicates individual specifications.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-019", + "title": "Agentic AI: Threats and Mitigations", + "source_type": "research_report", + "work_or_episode_identity": "Agentic AI: Threats and Mitigations", + "author_or_speaker": "OWASP Agentic Security Initiative", + "publisher": "OWASP GenAI Security Project", + "publication_date": "2025-02-17", + "event_date": null, + "original_url": "https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/", + "canonical_url": "https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Community-reviewed threat taxonomy includes privilege and identity risks.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Community-reviewed threat taxonomy includes privilege and identity risks.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-020", + "title": "Multi-Agentic System Threat Modeling Guide v1.0", + "source_type": "research_report", + "work_or_episode_identity": "Multi-Agentic System Threat Modeling Guide v1.0", + "author_or_speaker": "OWASP Agentic Security Initiative", + "publisher": "OWASP GenAI Security Project", + "publication_date": "2025-04-23", + "event_date": null, + "original_url": "https://genai.owasp.org/resource/multi-agentic-system-threat-modeling-guide-v1-0/", + "canonical_url": "https://genai.owasp.org/resource/multi-agentic-system-threat-modeling-guide-v1-0/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Applies threat modeling to multi-agent authorization and trust boundaries.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Applies threat modeling to multi-agent authorization and trust boundaries.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-021", + "title": "OWASP Top 10 for Agentic Applications", + "source_type": "research_report", + "work_or_episode_identity": "OWASP Top 10 for Agentic Applications", + "author_or_speaker": "OWASP Agentic Security Initiative", + "publisher": "OWASP GenAI Security Project", + "publication_date": "2025-12-09", + "event_date": null, + "original_url": "https://genai.owasp.org/2025/12/09/owasp-top-10-for-agentic-applications-the-benchmark-for-agentic-security-in-the-age-of-autonomous-ai/", + "canonical_url": "https://genai.owasp.org/2025/12/09/owasp-top-10-for-agentic-applications-the-benchmark-for-agentic-security-in-the-age-of-autonomous-ai/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Prominent community consensus artifact covering identity and privilege abuse.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Prominent community consensus artifact covering identity and privilege abuse.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-022", + "title": "State of Agentic AI Security and Governance 2.01", + "source_type": "research_report", + "work_or_episode_identity": "State of Agentic AI Security and Governance 2.01", + "author_or_speaker": "OWASP GenAI Security Project", + "publisher": "OWASP GenAI Security Project", + "publication_date": "2026-06-01", + "event_date": null, + "original_url": "https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/", + "canonical_url": "https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Current incident-oriented synthesis connecting governance to deployment controls.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Current incident-oriented synthesis connecting governance to deployment controls.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-023", + "title": "OWASP Cornucopia companion edition: Agentic AI", + "source_type": "other_approved", + "work_or_episode_identity": "OWASP Cornucopia companion edition: Agentic AI", + "author_or_speaker": "OWASP", + "publisher": "OWASP", + "publication_date": "2026", + "event_date": null, + "original_url": "https://cornucopia.owasp.org/cards/AAIJ", + "canonical_url": "https://cornucopia.owasp.org/cards/AAIJ", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Useful threat-elicitation tool, but evidentiary and identity depth are limited.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Useful threat-elicitation tool, but evidentiary and identity depth are limited.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-024", + "title": "The Non-Human Identity Governance Vacuum", + "source_type": "research_report", + "work_or_episode_identity": "The Non-Human Identity Governance Vacuum", + "author_or_speaker": "CSA AI Safety Initiative", + "publisher": "Cloud Security Alliance", + "publication_date": "2026-05-20", + "event_date": null, + "original_url": "https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/", + "canonical_url": "https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Direct governance analysis of agent identities and unmanaged ownership.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Direct governance analysis of agent identities and unmanaged ownership.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-025", + "title": "Agentic Identity Governance Framework", + "source_type": "research_report", + "work_or_episode_identity": "Agentic Identity Governance Framework", + "author_or_speaker": "Cloud Security Alliance", + "publisher": "Cloud Security Alliance", + "publication_date": "2026", + "event_date": null, + "original_url": "https://labs.cloudsecurityalliance.org/research/agentic-identity-governance-framework-v1/", + "canonical_url": "https://labs.cloudsecurityalliance.org/research/agentic-identity-governance-framework-v1/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Dedicated lifecycle and governance framework for agent identities.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Dedicated lifecycle and governance framework for agent identities.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-026", + "title": "Defining Non-Human Identity", + "source_type": "research_report", + "work_or_episode_identity": "Defining Non-Human Identity", + "author_or_speaker": "Cloud Security Alliance", + "publisher": "Cloud Security Alliance", + "publication_date": null, + "event_date": null, + "original_url": "https://cloudsecurityalliance.org/artifacts/defining-non-human-identity", + "canonical_url": "https://cloudsecurityalliance.org/artifacts/defining-non-human-identity", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Provides terminology needed to compare agent and workload identity models.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Provides terminology needed to compare agent and workload identity models.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-027", + "title": "Identity Management for Agentic AI", + "source_type": "research_report", + "work_or_episode_identity": "Identity Management for Agentic AI", + "author_or_speaker": "Tobin South and contributors", + "publisher": "OpenID Foundation", + "publication_date": "2025-10", + "event_date": null, + "original_url": "https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf", + "canonical_url": "https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Detailed multi-author identity, delegation, authentication, and authorization treatment.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Detailed multi-author identity, delegation, authentication, and authorization treatment.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-028", + "title": "EU AI Act Service Desk FAQ: applicability to AI agents", + "source_type": "public_policy_document", + "work_or_episode_identity": "EU AI Act Service Desk FAQ: applicability to AI agents", + "author_or_speaker": "European Commission", + "publisher": "European Commission", + "publication_date": "2026", + "event_date": null, + "original_url": "https://ai-act-service-desk.ec.europa.eu/en/faq?faq_category_id=69", + "canonical_url": "https://ai-act-service-desk.ec.europa.eu/en/faq?faq_category_id=69", + "language": "lang-en", + "relevant_geographies": [ + "European Union" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Authoritative legal context, but identity-specific guidance is limited.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Authoritative legal context, but identity-specific guidance is limited.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-029", + "title": "Guidelines for general-purpose AI providers: FAQ", + "source_type": "public_policy_document", + "work_or_episode_identity": "Guidelines for general-purpose AI providers: FAQ", + "author_or_speaker": "European Commission", + "publisher": "European Commission", + "publication_date": "2025", + "event_date": null, + "original_url": "https://digital-strategy.ec.europa.eu/en/faqs/guidelines-obligations-general-purpose-ai-providers", + "canonical_url": "https://digital-strategy.ec.europa.eu/en/faqs/guidelines-obligations-general-purpose-ai-providers", + "language": "lang-en", + "relevant_geographies": [ + "European Union" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Useful provider-duty context with only indirect agent-identity relevance.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Useful provider-duty context with only indirect agent-identity relevance.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-030", + "title": "Artificial Intelligence Act policy overview", + "source_type": "public_policy_document", + "work_or_episode_identity": "Artificial Intelligence Act policy overview", + "author_or_speaker": "Council of the European Union", + "publisher": "Council of the European Union", + "publication_date": "2024", + "event_date": null, + "original_url": "https://www.consilium.europa.eu/en/policies/artificial-intelligence-act/", + "canonical_url": "https://www.consilium.europa.eu/en/policies/artificial-intelligence-act/", + "language": "lang-en", + "relevant_geographies": [ + "European Union" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Authoritative but too general for identity-specific extraction without a legal mapping pass.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Authoritative but too general for identity-specific extraction without a legal mapping pass.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-031", + "title": "Model AI Governance Framework for Agentic AI", + "source_type": "public_policy_document", + "work_or_episode_identity": "Model AI Governance Framework for Agentic AI", + "author_or_speaker": "IMDA Singapore", + "publisher": "IMDA Singapore", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/press-releases/2026/new-model-ai-governance-framework-for-agentic-ai", + "canonical_url": "https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/press-releases/2026/new-model-ai-governance-framework-for-agentic-ai", + "language": "lang-en", + "relevant_geographies": [ + "Singapore", + "geo-global" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Primary national framework covering bounded autonomy and accountable deployment.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary national framework covering bounded autonomy and accountable deployment.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-032", + "title": "AI Agents: Insights from the Singapore Government and Google Sandbox", + "source_type": "research_report", + "work_or_episode_identity": "AI Agents: Insights from the Singapore Government and Google Sandbox", + "author_or_speaker": "IMDA Singapore and Google", + "publisher": "IMDA Singapore", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/factsheets/2026/ai-agents-insights-from-the-singapore-government-and-google-sandbox", + "canonical_url": "https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/factsheets/2026/ai-agents-insights-from-the-singapore-government-and-google-sandbox", + "language": "lang-en", + "relevant_geographies": [ + "Singapore", + "geo-global" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Operational public-sector sandbox evidence from a non-US jurisdiction.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Operational public-sector sandbox evidence from a non-US jurisdiction.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-033", + "title": "Careful adoption of agentic AI services", + "source_type": "public_policy_document", + "work_or_episode_identity": "Careful adoption of agentic AI services", + "author_or_speaker": "Australian Government", + "publisher": "Australian Government", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services", + "canonical_url": "https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services", + "language": "lang-en", + "relevant_geographies": [ + "Australia" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Cross-agency security guidance covers credentials, access, monitoring, and responsibility.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Cross-agency security guidance covers credentials, access, monitoring, and responsibility.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-034", + "title": "Agentic AI addendum: background", + "source_type": "public_policy_document", + "work_or_episode_identity": "Agentic AI addendum: background", + "author_or_speaker": "Digital Transformation Agency", + "publisher": "Australian Government", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.digital.gov.au/policy/ai/agentic-ai-addendum-background", + "canonical_url": "https://www.digital.gov.au/policy/ai/agentic-ai-addendum-background", + "language": "lang-en", + "relevant_geographies": [ + "Australia" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Official policy rationale for governing public-sector agent deployments.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Official policy rationale for governing public-sector agent deployments.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-035", + "title": "Guide on the use of agentic artificial intelligence", + "source_type": "public_policy_document", + "work_or_episode_identity": "Guide on the use of agentic artificial intelligence", + "author_or_speaker": "Government of Canada", + "publisher": "Government of Canada", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/guide-use-agentic-artificial-intelligence.html", + "canonical_url": "https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/guide-use-agentic-artificial-intelligence.html", + "language": "lang-en", + "relevant_geographies": [ + "Canada" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Primary federal operational guidance with access and accountability implications.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary federal operational guidance with access and accountability implications.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-036", + "title": "Guide to using AI agents in NSW Government", + "source_type": "public_policy_document", + "work_or_episode_identity": "Guide to using AI agents in NSW Government", + "author_or_speaker": "Digital NSW", + "publisher": "NSW Government", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.digital.nsw.gov.au/policy/artificial-intelligence/guide-to-using-ai-agents-nsw-government", + "canonical_url": "https://www.digital.nsw.gov.au/policy/artificial-intelligence/guide-to-using-ai-agents-nsw-government", + "language": "lang-en", + "relevant_geographies": [ + "Australia" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Concrete subnational public-sector governance guidance.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Concrete subnational public-sector governance guidance.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-037", + "title": "Agentic AI and consumers", + "source_type": "public_policy_document", + "work_or_episode_identity": "Agentic AI and consumers", + "author_or_speaker": "UK Government", + "publisher": "UK Government", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.gov.uk/government/publications/agentic-ai-and-consumers/agentic-ai-and-consumers", + "canonical_url": "https://www.gov.uk/government/publications/agentic-ai-and-consumers/agentic-ai-and-consumers", + "language": "lang-en", + "relevant_geographies": [ + "United Kingdom" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Public-authority analysis of agency, consent, authentication, and accountability in consumer contexts.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Public-authority analysis of agency, consent, authentication, and accountability in consumer contexts.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-038", + "title": "Considerations in Autonomous Agents", + "source_type": "research_report", + "work_or_episode_identity": "Considerations in Autonomous Agents", + "author_or_speaker": "ENISA", + "publisher": "ENISA", + "publication_date": "2019", + "event_date": null, + "original_url": "https://www.enisa.europa.eu/publications/considerations-in-autonomous-agents", + "canonical_url": "https://www.enisa.europa.eu/publications/considerations-in-autonomous-agents", + "language": "lang-en", + "relevant_geographies": [ + "European Union" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Foundational European security view but outside the primary time window and predates current agent architectures.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Foundational European security view but outside the primary time window and predates current agent architectures.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-039", + "title": "ENISA view on cybersecurity in the frontier AI era", + "source_type": "research_report", + "work_or_episode_identity": "ENISA view on cybersecurity in the frontier AI era", + "author_or_speaker": "ENISA", + "publisher": "ENISA", + "publication_date": "2026-07", + "event_date": null, + "original_url": "https://www.enisa.europa.eu/sites/default/files/2026-07/ENISA%20view%20on%20cybersecurity%20in%20the%20frontier%20AI%20era_en_0.pdf", + "canonical_url": "https://www.enisa.europa.eu/sites/default/files/2026-07/ENISA%20view%20on%20cybersecurity%20in%20the%20frontier%20AI%20era_en_0.pdf", + "language": "lang-en", + "relevant_geographies": [ + "European Union" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Current and authoritative, but agent identity requires targeted full-text review.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Current and authoritative, but agent identity requires targeted full-text review.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-040", + "title": "AI Agents in Action: A Playbook for Trusted Adoption, Authorization and Scaling", + "source_type": "research_report", + "work_or_episode_identity": "AI Agents in Action: A Playbook for Trusted Adoption, Authorization and Scaling", + "author_or_speaker": "World Economic Forum and Capgemini", + "publisher": "World Economic Forum", + "publication_date": "2026-05-26", + "event_date": null, + "original_url": "https://www.weforum.org/publications/ai-agents-in-action-a-playbook-for-trusted-adoption-authorization-and-scaling/", + "canonical_url": "https://www.weforum.org/publications/ai-agents-in-action-a-playbook-for-trusted-adoption-authorization-and-scaling/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-board-director", + "role-ceo", + "role-ciso", + "role-general-counsel" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Introduces an explicit agent capability and authorization profile.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Introduces an explicit agent capability and authorization profile.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-041", + "title": "From systems of record to systems of trust: a board-level playbook for governing agentic AI", + "source_type": "essay", + "work_or_episode_identity": "From systems of record to systems of trust: a board-level playbook for governing agentic AI", + "author_or_speaker": "Rohan Sharma", + "publisher": "World Economic Forum", + "publication_date": "2026-04-28", + "event_date": null, + "original_url": "https://www.weforum.org/stories/artificial-intelligence/board-playbook-governing-agentic-ai/", + "canonical_url": "https://www.weforum.org/stories/artificial-intelligence/board-playbook-governing-agentic-ai/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-board-director", + "role-ceo", + "role-ciso", + "role-general-counsel" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Distinct board perspective on boundaries of delegation and human authorization.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Distinct board perspective on boundaries of delegation and human authorization.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-042", + "title": "From chatbots to personal assistants: how governance is key to harnessing AI agents", + "source_type": "essay", + "work_or_episode_identity": "From chatbots to personal assistants: how governance is key to harnessing AI agents", + "author_or_speaker": "Cathy Li and Benjamin Larsen", + "publisher": "World Economic Forum", + "publication_date": "2026-03-16", + "event_date": null, + "original_url": "https://www.weforum.org/stories/artificial-intelligence/ai-agent-autonomy-governance/", + "canonical_url": "https://www.weforum.org/stories/artificial-intelligence/ai-agent-autonomy-governance/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-board-director", + "role-ceo", + "role-ciso", + "role-general-counsel" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Frames autonomy and authority as adjustable governance variables.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Frames autonomy and authority as adjustable governance variables.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-043", + "title": "Three high-impact identity strategies for security leaders in the age of AI", + "source_type": "essay", + "work_or_episode_identity": "Three high-impact identity strategies for security leaders in the age of AI", + "author_or_speaker": "ISACA contributor", + "publisher": "ISACA", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2026/three-high-impact-identity-strategies-for-security-leaders-in-the-age-of-ai", + "canonical_url": "https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2026/three-high-impact-identity-strategies-for-security-leaders-in-the-age-of-ai", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Independent professional-association guidance on least privilege, short-lived credentials, and audit.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Independent professional-association guidance on least privilege, short-lived credentials, and audit.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-044", + "title": "AI governance discussion paper for social implementation", + "source_type": "public_policy_document", + "work_or_episode_identity": "AI governance discussion paper for social implementation", + "author_or_speaker": "METI Japan", + "publisher": "METI Japan", + "publication_date": "2026-03-31", + "event_date": null, + "original_url": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_14.pdf", + "canonical_url": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_14.pdf", + "language": "lang-en", + "relevant_geographies": [ + "Japan" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Geographically valuable official source; English-language and agent-identity coverage need human verification.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Geographically valuable official source; English-language and agent-identity coverage need human verification.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-045", + "title": "Identity Management for Agentic AI: The New Frontier of Authorization, Authentication, and Security", + "source_type": "academic_paper", + "work_or_episode_identity": "Identity Management for Agentic AI: The New Frontier of Authorization, Authentication, and Security", + "author_or_speaker": "Tobin South et al.", + "publisher": "arXiv / OpenID Foundation authors", + "publication_date": "2025-10", + "event_date": null, + "original_url": "https://arxiv.org/abs/2510.25819", + "canonical_url": "https://arxiv.org/abs/2510.25819", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Research version of a central agent-identity framework; related-work linkage recorded.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [ + "candidate-BATCH-2026-001-027" + ], + "decision": "accept", + "reason": "Research version of a central agent-identity framework; related-work linkage recorded.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-046", + "title": "Authorization Propagation in Multi-Agent AI Systems", + "source_type": "working_paper", + "work_or_episode_identity": "Authorization Propagation in Multi-Agent AI Systems", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2026-05", + "event_date": null, + "original_url": "https://arxiv.org/abs/2605.05440", + "canonical_url": "https://arxiv.org/abs/2605.05440", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Direct formal treatment of authorization across delegated agent chains.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Direct formal treatment of authorization across delegated agent chains.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-047", + "title": "SAGA: A Security Architecture for Governing AI Agents", + "source_type": "working_paper", + "work_or_episode_identity": "SAGA: A Security Architecture for Governing AI Agents", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2025-04", + "event_date": null, + "original_url": "https://arxiv.org/abs/2504.21034", + "canonical_url": "https://arxiv.org/abs/2504.21034", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Proposes a governance architecture centered on agent identity and policy enforcement.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Proposes a governance architecture centered on agent identity and policy enforcement.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-048", + "title": "AgentGuardian: Runtime Security and Governance for AI Agents", + "source_type": "working_paper", + "work_or_episode_identity": "AgentGuardian: Runtime Security and Governance for AI Agents", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2026-01", + "event_date": null, + "original_url": "https://arxiv.org/abs/2601.10440", + "canonical_url": "https://arxiv.org/abs/2601.10440", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Runtime-control approach relevant to identity-aware enforcement and audit.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Runtime-control approach relevant to identity-aware enforcement and audit.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-049", + "title": "Personhood Credentials: Artificial Intelligence and the Value of Privacy-Preserving Tools to Distinguish Who Is Real Online", + "source_type": "academic_paper", + "work_or_episode_identity": "Personhood Credentials: Artificial Intelligence and the Value of Privacy-Preserving Tools to Distinguish Who Is Real Online", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-08", + "event_date": null, + "original_url": "https://arxiv.org/abs/2408.07892", + "canonical_url": "https://arxiv.org/abs/2408.07892", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Important counterpoint distinguishing human personhood from agent identity.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Important counterpoint distinguishing human personhood from agent identity.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-050", + "title": "AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents", + "source_type": "academic_paper", + "work_or_episode_identity": "AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-06", + "event_date": null, + "original_url": "https://arxiv.org/abs/2406.13352", + "canonical_url": "https://arxiv.org/abs/2406.13352", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Empirical benchmark for agent misuse under delegated tool access.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Empirical benchmark for agent misuse under delegated tool access.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-051", + "title": "AI Agents Under Threat: A Survey of Key Security Challenges and Future Pathways", + "source_type": "academic_paper", + "work_or_episode_identity": "AI Agents Under Threat: A Survey of Key Security Challenges and Future Pathways", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-06", + "event_date": null, + "original_url": "https://arxiv.org/abs/2406.02630", + "canonical_url": "https://arxiv.org/abs/2406.02630", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Broad security survey useful for mapping identity-related attack surfaces.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Broad security survey useful for mapping identity-related attack surfaces.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-052", + "title": "AgentSecBench: Benchmarking Security of LLM Agents", + "source_type": "working_paper", + "work_or_episode_identity": "AgentSecBench: Benchmarking Security of LLM Agents", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2026-05", + "event_date": null, + "original_url": "https://arxiv.org/abs/2605.26269", + "canonical_url": "https://arxiv.org/abs/2605.26269", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Potentially valuable new benchmark; peer-review and identity-specific results need verification.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Potentially valuable new benchmark; peer-review and identity-specific results need verification.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-053", + "title": "The Layered Attack Surface of LLM-Based Agent Systems: A Survey", + "source_type": "working_paper", + "work_or_episode_identity": "The Layered Attack Surface of LLM-Based Agent Systems: A Survey", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2026-04", + "event_date": null, + "original_url": "https://arxiv.org/abs/2604.23338", + "canonical_url": "https://arxiv.org/abs/2604.23338", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Current synthesis but very new and not specifically centered on identity.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Current synthesis but very new and not specifically centered on identity.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-054", + "title": "ASB: A Comprehensive Benchmark for Evaluating Security of LLM Agents", + "source_type": "academic_paper", + "work_or_episode_identity": "ASB: A Comprehensive Benchmark for Evaluating Security of LLM Agents", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-10", + "event_date": null, + "original_url": "https://arxiv.org/abs/2410.02644", + "canonical_url": "https://arxiv.org/abs/2410.02644", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Benchmark contributes evidence about unauthorized and unsafe agent actions.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Benchmark contributes evidence about unauthorized and unsafe agent actions.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-055", + "title": "InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents", + "source_type": "academic_paper", + "work_or_episode_identity": "InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-03", + "event_date": null, + "original_url": "https://arxiv.org/abs/2403.02691", + "canonical_url": "https://arxiv.org/abs/2403.02691", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Empirical evidence on agents misusing authorized tools after hostile input.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Empirical evidence on agents misusing authorized tools after hostile input.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-056", + "title": "ToolEmu: Identifying the Risks of LM Agents with an LM-Emulated Sandbox", + "source_type": "academic_paper", + "work_or_episode_identity": "ToolEmu: Identifying the Risks of LM Agents with an LM-Emulated Sandbox", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2023-09", + "event_date": null, + "original_url": "https://arxiv.org/abs/2309.15817", + "canonical_url": "https://arxiv.org/abs/2309.15817", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Empirical risk evaluation for agents acting through tools.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Empirical risk evaluation for agents acting through tools.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-057", + "title": "ToolSandbox: A Stateful, Conversational, Interactive Evaluation Benchmark for LLM Tool Use Capabilities", + "source_type": "academic_paper", + "work_or_episode_identity": "ToolSandbox: A Stateful, Conversational, Interactive Evaluation Benchmark for LLM Tool Use Capabilities", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-08", + "event_date": null, + "original_url": "https://arxiv.org/abs/2408.04682", + "canonical_url": "https://arxiv.org/abs/2408.04682", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Supports evaluation of permissions and stateful tool interactions.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Supports evaluation of permissions and stateful tool interactions.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-058", + "title": "Teams of LLM Agents Can Exploit Zero-Day Vulnerabilities", + "source_type": "academic_paper", + "work_or_episode_identity": "Teams of LLM Agents Can Exploit Zero-Day Vulnerabilities", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-06", + "event_date": null, + "original_url": "https://arxiv.org/abs/2406.01637", + "canonical_url": "https://arxiv.org/abs/2406.01637", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Adversarial evidence showing why bounded authority and monitoring matter.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Adversarial evidence showing why bounded authority and monitoring matter.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-059", + "title": "The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions", + "source_type": "academic_paper", + "work_or_episode_identity": "The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2024-04", + "event_date": null, + "original_url": "https://arxiv.org/abs/2404.13208", + "canonical_url": "https://arxiv.org/abs/2404.13208", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Evidence for enforcing authority boundaries among instruction sources.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Evidence for enforcing authority boundaries among instruction sources.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-060", + "title": "Secure Agent-to-Agent Application", + "source_type": "working_paper", + "work_or_episode_identity": "Secure Agent-to-Agent Application", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2025-04", + "event_date": null, + "original_url": "https://arxiv.org/abs/2504.16902", + "canonical_url": "https://arxiv.org/abs/2504.16902", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Directly addresses secure cross-agent communication and trust.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Directly addresses secure cross-agent communication and trust.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-061", + "title": "AAGATE: Authentication and Authorization for Agentic AI", + "source_type": "working_paper", + "work_or_episode_identity": "AAGATE: Authentication and Authorization for Agentic AI", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2025-10", + "event_date": null, + "original_url": "https://arxiv.org/abs/2510.25863", + "canonical_url": "https://arxiv.org/abs/2510.25863", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Direct agent authentication and authorization architecture.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Direct agent authentication and authorization architecture.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-062", + "title": "A Sensitive Data Protection Proposal for Agent2Agent Protocol", + "source_type": "working_paper", + "work_or_episode_identity": "A Sensitive Data Protection Proposal for Agent2Agent Protocol", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2025-05", + "event_date": null, + "original_url": "https://arxiv.org/abs/2505.12490", + "canonical_url": "https://arxiv.org/abs/2505.12490", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Connects agent identity and delegated exchange to data protection.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Connects agent identity and delegated exchange to data protection.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-063", + "title": "LanG: A Capability-Based Authorization Model for LLM Agents", + "source_type": "working_paper", + "work_or_episode_identity": "LanG: A Capability-Based Authorization Model for LLM Agents", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2026-04", + "event_date": null, + "original_url": "https://arxiv.org/abs/2604.05440", + "canonical_url": "https://arxiv.org/abs/2604.05440", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Promising capability model; recent preprint requires deeper technical review.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Promising capability model; recent preprint requires deeper technical review.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-064", + "title": "A Survey of Agent Interoperability Protocols: Model Context Protocol, Agent Communication Protocol, and Agent-to-Agent Protocol", + "source_type": "working_paper", + "work_or_episode_identity": "A Survey of Agent Interoperability Protocols: Model Context Protocol, Agent Communication Protocol, and Agent-to-Agent Protocol", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2025-05", + "event_date": null, + "original_url": "https://arxiv.org/abs/2505.02279", + "canonical_url": "https://arxiv.org/abs/2505.02279", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Maps protocol trust boundaries that shape identity portability.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Maps protocol trust boundaries that shape identity portability.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-065", + "title": "Identity and Access Gaps in the Age of Autonomous AI", + "source_type": "executive_survey", + "work_or_episode_identity": "Identity and Access Gaps in the Age of Autonomous AI", + "author_or_speaker": "Cloud Security Alliance research analysts", + "publisher": "Cloud Security Alliance / Aembit", + "publication_date": "2026-03-24", + "event_date": null, + "original_url": "https://cloudsecurityalliance.org/press-releases/2026/03/24/more-than-two-thirds-of-organizations-cannot-clearly-distinguish-ai-agent-from-human-actions", + "canonical_url": "https://cloudsecurityalliance.org/press-releases/2026/03/24/more-than-two-thirds-of-organizations-cannot-clearly-distinguish-ai-agent-from-human-actions", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-board-director", + "role-ceo" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "methods_and_sample_disclosed", + "source_identity_stability": "high", + "evidence_contribution": "Discloses sponsor, questionnaire role, field date, sample size, and identity findings.", + "diversity_contribution": [ + "empirical evidence", + "sponsor-disclosed research" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Discloses sponsor, questionnaire role, field date, sample size, and identity findings.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q036", + "Q037" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-066", + "title": "The State of Non-Human Identity and AI Security", + "source_type": "executive_survey", + "work_or_episode_identity": "The State of Non-Human Identity and AI Security", + "author_or_speaker": "Cloud Security Alliance", + "publisher": "Cloud Security Alliance / Oasis Security", + "publication_date": "2026-01-26", + "event_date": null, + "original_url": "https://cloudsecurityalliance.org/artifacts/state-of-nhi-and-ai-security-survey-report", + "canonical_url": "https://cloudsecurityalliance.org/artifacts/state-of-nhi-and-ai-security-survey-report", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-board-director", + "role-ceo" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "methods_and_sample_disclosed", + "source_identity_stability": "high", + "evidence_contribution": "Data-driven view of ownership, lifecycle, inventory, and legacy-IAM gaps; sponsorship is explicit.", + "diversity_contribution": [ + "empirical evidence", + "sponsor-disclosed research" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Data-driven view of ownership, lifecycle, inventory, and legacy-IAM gaps; sponsorship is explicit.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q036", + "Q037" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-067", + "title": "Securing Autonomous AI Agents", + "source_type": "executive_survey", + "work_or_episode_identity": "Securing Autonomous AI Agents", + "author_or_speaker": "Cloud Security Alliance", + "publisher": "Cloud Security Alliance / Strata Identity", + "publication_date": "2026-02-04", + "event_date": null, + "original_url": "https://cloudsecurityalliance.org/artifacts/securing-autonomous-ai-agents", + "canonical_url": "https://cloudsecurityalliance.org/artifacts/securing-autonomous-ai-agents", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-board-director", + "role-ceo" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "methods_and_sample_disclosed", + "source_identity_stability": "high", + "evidence_contribution": "Reports adoption, registry, credentials, traceability, and budget evidence with sponsor disclosure.", + "diversity_contribution": [ + "empirical evidence", + "sponsor-disclosed research" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Reports adoption, registry, credentials, traceability, and budget evidence with sponsor disclosure.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q036", + "Q037" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-068", + "title": "The State of Application Strategy in 2026", + "source_type": "executive_survey", + "work_or_episode_identity": "The State of Application Strategy in 2026", + "author_or_speaker": "F5 Research", + "publisher": "F5", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.f5.com/resources/reports/state-of-application-strategy-report", + "canonical_url": "https://www.f5.com/resources/reports/state-of-application-strategy-report", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-board-director", + "role-ceo" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "methods_and_sample_disclosed", + "source_identity_stability": "high", + "evidence_contribution": "More than 1,100 IT decision makers; includes agent identity growth, authentication, and audit concerns.", + "diversity_contribution": [ + "empirical evidence", + "sponsor-disclosed research" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "More than 1,100 IT decision makers; includes agent identity growth, authentication, and audit concerns.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q036", + "Q037" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-069", + "title": "The Rise and Risks of Agentic AI", + "source_type": "executive_survey", + "work_or_episode_identity": "The Rise and Risks of Agentic AI", + "author_or_speaker": "PwC", + "publisher": "PwC", + "publication_date": "2025-07-17", + "event_date": null, + "original_url": "https://www.pwc.com/us/en/industries/tmt/library/trust-and-safety-outlook/rise-and-risks-of-agentic-ai.html", + "canonical_url": "https://www.pwc.com/us/en/industries/tmt/library/trust-and-safety-outlook/rise-and-risks-of-agentic-ai.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-board-director", + "role-ceo" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "partially_disclosed", + "source_identity_stability": "high", + "evidence_contribution": "Useful executive trust data, but sample and methods require confirmation in the linked report.", + "diversity_contribution": [ + "empirical evidence", + "sponsor-disclosed research" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Useful executive trust data, but sample and methods require confirmation in the linked report.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q036", + "Q037" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-070", + "title": "Microsoft Entra Agent ID: agent identities", + "source_type": "other_approved", + "work_or_episode_identity": "Microsoft Entra Agent ID: agent identities", + "author_or_speaker": "Microsoft", + "publisher": "Microsoft", + "publication_date": "2026", + "event_date": null, + "original_url": "https://learn.microsoft.com/en-us/entra/agent-id/agent-identities", + "canonical_url": "https://learn.microsoft.com/en-us/entra/agent-id/agent-identities", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary product documentation illustrates current agent identity object models.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary product documentation illustrates current agent identity object models.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-071", + "title": "Manage agent identities as an administrator", + "source_type": "other_approved", + "work_or_episode_identity": "Manage agent identities as an administrator", + "author_or_speaker": "Microsoft", + "publisher": "Microsoft", + "publication_date": "2026", + "event_date": null, + "original_url": "https://learn.microsoft.com/en-us/entra/agent-id/manage-agent-identities-admin", + "canonical_url": "https://learn.microsoft.com/en-us/entra/agent-id/manage-agent-identities-admin", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Operational lifecycle, inventory, and administrative control guidance.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Operational lifecycle, inventory, and administrative control guidance.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-072", + "title": "What are agent identities?", + "source_type": "other_approved", + "work_or_episode_identity": "What are agent identities?", + "author_or_speaker": "Microsoft", + "publisher": "Microsoft", + "publication_date": "2026", + "event_date": null, + "original_url": "https://learn.microsoft.com/en-us/entra/agent-id/what-are-agent-identities", + "canonical_url": "https://learn.microsoft.com/en-us/entra/agent-id/what-are-agent-identities", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Defines Microsoft agent and blueprint identity semantics.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Defines Microsoft agent and blueprint identity semantics.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-073", + "title": "Autonomous agent authentication and authorization flow", + "source_type": "other_approved", + "work_or_episode_identity": "Autonomous agent authentication and authorization flow", + "author_or_speaker": "Microsoft", + "publisher": "Microsoft", + "publication_date": "2026", + "event_date": null, + "original_url": "https://learn.microsoft.com/en-us/entra/agent-id/autonomous-agent-authentication-authorization-flow", + "canonical_url": "https://learn.microsoft.com/en-us/entra/agent-id/autonomous-agent-authentication-authorization-flow", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Concrete authorization-flow implementation reference.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Concrete authorization-flow implementation reference.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-074", + "title": "Configure third-party agents with Microsoft Entra Agent ID", + "source_type": "other_approved", + "work_or_episode_identity": "Configure third-party agents with Microsoft Entra Agent ID", + "author_or_speaker": "Microsoft", + "publisher": "Microsoft", + "publication_date": "2026", + "event_date": null, + "original_url": "https://learn.microsoft.com/en-us/entra/agent-id/configure-third-party-agents", + "canonical_url": "https://learn.microsoft.com/en-us/entra/agent-id/configure-third-party-agents", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Cross-vendor onboarding and lifecycle example.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Cross-vendor onboarding and lifecycle example.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-075", + "title": "Agent identity overview", + "source_type": "other_approved", + "work_or_episode_identity": "Agent identity overview", + "author_or_speaker": "Google Cloud", + "publisher": "Google Cloud", + "publication_date": "2026", + "event_date": null, + "original_url": "https://docs.cloud.google.com/iam/docs/agent-identity-overview?hl=en", + "canonical_url": "https://docs.cloud.google.com/iam/docs/agent-identity-overview?hl=en", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary cloud documentation for managed agent identities and policy.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary cloud documentation for managed agent identities and policy.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-076", + "title": "What is new in IAM: security, governance, and runtime defense", + "source_type": "essay", + "work_or_episode_identity": "What is new in IAM: security, governance, and runtime defense", + "author_or_speaker": "Google Cloud", + "publisher": "Google Cloud", + "publication_date": "2026", + "event_date": null, + "original_url": "https://cloud.google.com/blog/products/identity-security/whats-new-in-iam-security-governance-and-runtime-defense", + "canonical_url": "https://cloud.google.com/blog/products/identity-security/whats-new-in-iam-security-governance-and-runtime-defense", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Operator view of governance and runtime controls for agents.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Operator view of governance and runtime controls for agents.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-077", + "title": "Multi-tenant agentic AI system architecture", + "source_type": "other_approved", + "work_or_episode_identity": "Multi-tenant agentic AI system architecture", + "author_or_speaker": "Google Cloud", + "publisher": "Google Cloud", + "publication_date": "2026", + "event_date": null, + "original_url": "https://docs.cloud.google.com/architecture/multi-tenant-agentic-ai-system", + "canonical_url": "https://docs.cloud.google.com/architecture/multi-tenant-agentic-ai-system", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Architectural evidence on tenant isolation and identity boundaries.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Architectural evidence on tenant isolation and identity boundaries.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-078", + "title": "AI agent security: how to protect digital sidekicks and your business", + "source_type": "essay", + "work_or_episode_identity": "AI agent security: how to protect digital sidekicks and your business", + "author_or_speaker": "Google Cloud", + "publisher": "Google Cloud", + "publication_date": "2025", + "event_date": null, + "original_url": "https://cloud.google.com/transform/ai-agent-security-how-to-protect-digital-sidekicks-and-your-business", + "canonical_url": "https://cloud.google.com/transform/ai-agent-security-how-to-protect-digital-sidekicks-and-your-business", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Executive-friendly operator perspective on agent access and trust.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Executive-friendly operator perspective on agent access and trust.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-079", + "title": "Agent2Agent protocol specification", + "source_type": "other_approved", + "work_or_episode_identity": "Agent2Agent protocol specification", + "author_or_speaker": "A2A Project", + "publisher": "A2A Project / Linux Foundation", + "publication_date": "2026", + "event_date": null, + "original_url": "https://google-a2a.github.io/A2A/specification/", + "canonical_url": "https://google-a2a.github.io/A2A/specification/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Canonical interoperability specification with authentication and authorization implications.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Canonical interoperability specification with authentication and authorization implications.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-080", + "title": "Amazon Bedrock AgentCore Identity", + "source_type": "other_approved", + "work_or_episode_identity": "Amazon Bedrock AgentCore Identity", + "author_or_speaker": "Amazon Web Services", + "publisher": "Amazon Web Services", + "publication_date": "2026", + "event_date": null, + "original_url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity.html", + "canonical_url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary operator documentation for agent credential and authorization flows.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary operator documentation for agent credential and authorization flows.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-081", + "title": "Four security principles for agentic AI systems", + "source_type": "essay", + "work_or_episode_identity": "Four security principles for agentic AI systems", + "author_or_speaker": "AWS Security", + "publisher": "Amazon Web Services", + "publication_date": "2025", + "event_date": null, + "original_url": "https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/", + "canonical_url": "https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Clear operator principles for unique identity, least privilege, and observability.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Clear operator principles for unique identity, least privilege, and observability.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-082", + "title": "AWS AI Security Framework", + "source_type": "research_report", + "work_or_episode_identity": "AWS AI Security Framework", + "author_or_speaker": "AWS Security", + "publisher": "Amazon Web Services", + "publication_date": "2025", + "event_date": null, + "original_url": "https://aws.amazon.com/blogs/security/the-aws-ai-security-framework-securing-ai-with-the-right-controls-at-the-right-layers-at-the-right-phases/", + "canonical_url": "https://aws.amazon.com/blogs/security/the-aws-ai-security-framework-securing-ai-with-the-right-controls-at-the-right-layers-at-the-right-phases/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Structured controls across lifecycle layers, with identity as a key control plane.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Structured controls across lifecycle layers, with identity as a key control plane.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-083", + "title": "AgentCore identity common use cases and authorization patterns", + "source_type": "other_approved", + "work_or_episode_identity": "AgentCore identity common use cases and authorization patterns", + "author_or_speaker": "Amazon Web Services", + "publisher": "Amazon Web Services", + "publication_date": "2026", + "event_date": null, + "original_url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/common-use-cases.html", + "canonical_url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/common-use-cases.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Concrete patterns for user delegation and outbound agent access.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Concrete patterns for user delegation and outbound agent access.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-084", + "title": "A Practical Guide to Building AI Agents", + "source_type": "essay", + "work_or_episode_identity": "A Practical Guide to Building AI Agents", + "author_or_speaker": "OpenAI", + "publisher": "OpenAI", + "publication_date": "2025", + "event_date": null, + "original_url": "https://openai.com/business/guides-and-resources/a-practical-guide-to-building-ai-agents/", + "canonical_url": "https://openai.com/business/guides-and-resources/a-practical-guide-to-building-ai-agents/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary builder perspective on guardrails and tool permissions.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary builder perspective on guardrails and tool permissions.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-085", + "title": "Practices for Governing Agentic AI Systems", + "source_type": "research_report", + "work_or_episode_identity": "Practices for Governing Agentic AI Systems", + "author_or_speaker": "OpenAI", + "publisher": "OpenAI", + "publication_date": "2023", + "event_date": null, + "original_url": "https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf", + "canonical_url": "https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Early governance paper focused on responsible parties and indirect controls.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Early governance paper focused on responsible parties and indirect controls.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-086", + "title": "Running Codex safely", + "source_type": "essay", + "work_or_episode_identity": "Running Codex safely", + "author_or_speaker": "OpenAI", + "publisher": "OpenAI", + "publication_date": "2026", + "event_date": null, + "original_url": "https://openai.com/index/running-codex-safely/", + "canonical_url": "https://openai.com/index/running-codex-safely/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Concrete deployment case on sandboxing, authorization boundaries, and human control.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Concrete deployment case on sandboxing, authorization boundaries, and human control.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-087", + "title": "Runtime identity for AI agents", + "source_type": "essay", + "work_or_episode_identity": "Runtime identity for AI agents", + "author_or_speaker": "Ping Identity", + "publisher": "Ping Identity", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.pingidentity.com/en/resources/blog/post/runtime-identity.html", + "canonical_url": "https://www.pingidentity.com/en/resources/blog/post/runtime-identity.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Specialist IAM view of contextual runtime identity.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Specialist IAM view of contextual runtime identity.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-088", + "title": "IAM best practices for AI agents", + "source_type": "essay", + "work_or_episode_identity": "IAM best practices for AI agents", + "author_or_speaker": "Ping Identity", + "publisher": "Ping Identity", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/iam-best-practices-ai-agents.html", + "canonical_url": "https://www.pingidentity.com/en/resources/identity-fundamentals/agentic-ai/iam-best-practices-ai-agents.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Practical identity lifecycle and least-privilege guidance.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Practical identity lifecycle and least-privilege guidance.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-089", + "title": "What is AI agent identity?", + "source_type": "essay", + "work_or_episode_identity": "What is AI agent identity?", + "author_or_speaker": "Okta", + "publisher": "Okta", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.okta.com/en-gb/identity-101/what-is-ai-agent-identity/", + "canonical_url": "https://www.okta.com/en-gb/identity-101/what-is-ai-agent-identity/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Specialist IAM taxonomy and executive orientation.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Specialist IAM taxonomy and executive orientation.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-090", + "title": "AI identity security compliance checklist", + "source_type": "other_approved", + "work_or_episode_identity": "AI identity security compliance checklist", + "author_or_speaker": "Okta", + "publisher": "Okta", + "publication_date": "2026-03", + "event_date": null, + "original_url": "https://www.okta.com/sites/default/files/2026-03/AI-identity-security-compliance-checklist.pdf", + "canonical_url": "https://www.okta.com/sites/default/files/2026-03/AI-identity-security-compliance-checklist.pdf", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Potentially useful checklist but heavily product-adjacent and methodologically thin.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Potentially useful checklist but heavily product-adjacent and methodologically thin.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-091", + "title": "Agent Identity Security documentation", + "source_type": "other_approved", + "work_or_episode_identity": "Agent Identity Security documentation", + "author_or_speaker": "SailPoint", + "publisher": "SailPoint", + "publication_date": "2026", + "event_date": null, + "original_url": "https://documentation.sailpoint.com/saas/help/agent/index.html", + "canonical_url": "https://documentation.sailpoint.com/saas/help/agent/index.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary lifecycle and governance implementation documentation.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary lifecycle and governance implementation documentation.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-092", + "title": "Governing AI agents: an identity security strategy", + "source_type": "essay", + "work_or_episode_identity": "Governing AI agents: an identity security strategy", + "author_or_speaker": "SailPoint", + "publisher": "SailPoint", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.sailpoint.com/blog/governing-ai-agents-identity-security-strategy", + "canonical_url": "https://www.sailpoint.com/blog/governing-ai-agents-identity-security-strategy", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Specialist practitioner model for inventory, ownership, and access review.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Specialist practitioner model for inventory, ownership, and access review.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-093", + "title": "CyberArk Secure AI Agents", + "source_type": "other_approved", + "work_or_episode_identity": "CyberArk Secure AI Agents", + "author_or_speaker": "CyberArk", + "publisher": "CyberArk", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.cyberark.com/solutions/secure-agentic-ai/", + "canonical_url": "https://www.cyberark.com/solutions/secure-agentic-ai/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Relevant capabilities but solution page is promotional; retain for market-context review only.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Relevant capabilities but solution page is promotional; retain for market-context review only.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-094", + "title": "AI agents and identity risks: how security will shift in 2026", + "source_type": "essay", + "work_or_episode_identity": "AI agents and identity risks: how security will shift in 2026", + "author_or_speaker": "CyberArk", + "publisher": "CyberArk", + "publication_date": "2025", + "event_date": null, + "original_url": "https://www.cyberark.com/resources/identity-security/ai-agents-and-identity-risks-how-security-will-shift-in-2026", + "canonical_url": "https://www.cyberark.com/resources/identity-security/ai-agents-and-identity-risks-how-security-will-shift-in-2026", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Security-lab and practitioner perspective on agent privilege and attack paths.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Security-lab and practitioner perspective on agent privilege and attack paths.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-095", + "title": "Solving the Bottom Turtle: a SPIFFE Way to Establish Trust in Your Infrastructure via Universal Identity", + "source_type": "book", + "work_or_episode_identity": "Solving the Bottom Turtle: a SPIFFE Way to Establish Trust in Your Infrastructure via Universal Identity", + "author_or_speaker": "Evan Gilman and Doug Barth", + "publisher": "SPIFFE Project", + "publication_date": "2020", + "event_date": null, + "original_url": "https://spiffe.io/book/", + "canonical_url": "https://spiffe.io/book/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Openly available foundational workload-identity book directly applicable to agent infrastructure.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Openly available foundational workload-identity book directly applicable to agent infrastructure.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-096", + "title": "Zero Trust Networks, Second Edition", + "source_type": "book", + "work_or_episode_identity": "Zero Trust Networks, Second Edition", + "author_or_speaker": "Evan Gilman and Doug Barth", + "publisher": "O’Reilly Media", + "publication_date": "2021", + "event_date": null, + "original_url": "https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/titlepage01.html", + "canonical_url": "https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/titlepage01.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Foundational least-privilege, identity, and policy context.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Foundational least-privilege, identity, and policy context.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-097", + "title": "OAuth 2 in Action", + "source_type": "book", + "work_or_episode_identity": "OAuth 2 in Action", + "author_or_speaker": "Justin Richer and Antonio Sanso", + "publisher": "Manning", + "publication_date": "2017", + "event_date": null, + "original_url": "https://www.manning.com/books/oauth-2-in-action?query=OAuth+2+in+Action", + "canonical_url": "https://www.manning.com/books/oauth-2-in-action?query=OAuth+2+in+Action", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Foundational delegated-authorization reference retained under the earlier-work exception.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Foundational delegated-authorization reference retained under the earlier-work exception.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-098", + "title": "API Security in Action", + "source_type": "book", + "work_or_episode_identity": "API Security in Action", + "author_or_speaker": "Neil Madden", + "publisher": "Manning", + "publication_date": "2020", + "event_date": null, + "original_url": "https://www.manning.com/books/api-security-in-action?from=oreilly", + "canonical_url": "https://www.manning.com/books/api-security-in-action?from=oreilly", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Applied API authentication and authorization reference for agent tool access.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Applied API authentication and authorization reference for agent tool access.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-099", + "title": "Building Secure and Reliable Systems", + "source_type": "book", + "work_or_episode_identity": "Building Secure and Reliable Systems", + "author_or_speaker": "Heather Adkins et al.", + "publisher": "O’Reilly Media", + "publication_date": "2020", + "event_date": null, + "original_url": "https://www.oreilly.com/library/view/building-secure-and/9781492083115/", + "canonical_url": "https://www.oreilly.com/library/view/building-secure-and/9781492083115/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Operational governance, least privilege, and auditability foundation.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Operational governance, least privilege, and auditability foundation.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-100", + "title": "Identity in Modern Applications", + "source_type": "book", + "work_or_episode_identity": "Identity in Modern Applications", + "author_or_speaker": "Phillip J. Windley", + "publisher": "O’Reilly Media", + "publication_date": "2022", + "event_date": null, + "original_url": "https://www.oreilly.com/library/view/identity-in-modern/9781098107789/", + "canonical_url": "https://www.oreilly.com/library/view/identity-in-modern/9781098107789/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Modern identity architecture foundation for agent-specific comparison.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Modern identity architecture foundation for agent-specific comparison.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-101", + "title": "Solving Identity Management in Modern Applications", + "source_type": "book", + "work_or_episode_identity": "Solving Identity Management in Modern Applications", + "author_or_speaker": "Yvonne Wilson and Abhishek Hingnikar", + "publisher": "Apress", + "publication_date": "2019", + "event_date": null, + "original_url": "https://www.oreilly.com/library/view/solving-identity-management/9781484250952/", + "canonical_url": "https://www.oreilly.com/library/view/solving-identity-management/9781484250952/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Foundational identity lifecycle and protocol context under the earlier-work exception.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Foundational identity lifecycle and protocol context under the earlier-work exception.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-102", + "title": "Identity-Native Infrastructure Access Management", + "source_type": "book", + "work_or_episode_identity": "Identity-Native Infrastructure Access Management", + "author_or_speaker": "Ev Kontsevoy and Sakshyam Shah", + "publisher": "O’Reilly Media", + "publication_date": "2023", + "event_date": null, + "original_url": "https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/", + "canonical_url": "https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Direct infrastructure identity and access architecture relevant to agent runtimes.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Direct infrastructure identity and access architecture relevant to agent runtimes.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-103", + "title": "AI Engineering", + "source_type": "book", + "work_or_episode_identity": "AI Engineering", + "author_or_speaker": "Chip Huyen", + "publisher": "O’Reilly Media", + "publication_date": "2025", + "event_date": null, + "original_url": "https://www.oreilly.com/library/view/ai-engineering/9781098166298/", + "canonical_url": "https://www.oreilly.com/library/view/ai-engineering/9781098166298/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Important agent-building context, but identity contribution needs chapter-level access review.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Important agent-building context, but identity contribution needs chapter-level access review.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-104", + "title": "Identity at the Center #390: Identity Management for Agentic AI with Tobin South", + "source_type": "podcast_episode", + "work_or_episode_identity": "Identity at the Center #390: Identity Management for Agentic AI with Tobin South", + "author_or_speaker": "Tobin South; Jim McDonald; Jeff Steadman", + "publisher": "Identity at the Center", + "publication_date": "2025-12-08", + "event_date": null, + "original_url": "https://podfollow.com/1564331550/episode/e536a09c789954de12ec0ac798872a6c9933df2d/view", + "canonical_url": "https://podfollow.com/1564331550/episode/e536a09c789954de12ec0ac798872a6c9933df2d/view", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-board-director" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_media_or_event_metadata", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary long-form interview covers impersonation, delegation, liability, and oversight.", + "diversity_contribution": [ + "primary spoken perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary long-form interview covers impersonation, delegation, liability, and oversight.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q034", + "Q035" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-105", + "title": "When the Client Is a Mind", + "source_type": "podcast_episode", + "work_or_episode_identity": "When the Client Is a Mind", + "author_or_speaker": "OpenID Foundation speakers", + "publisher": "OpenID Foundation", + "publication_date": "2025-10", + "event_date": null, + "original_url": "https://openid.net/cg/artificial-intelligence-identity-management-community-group/", + "canonical_url": "https://openid.net/cg/artificial-intelligence-identity-management-community-group/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-board-director" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_media_or_event_metadata", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Official listing confirms the episode, but a stable episode-level canonical URL remains unresolved.", + "diversity_contribution": [ + "primary spoken perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Official listing confirms the episode, but a stable episode-level canonical URL remains unresolved.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q034", + "Q035" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-106", + "title": "Identity Management for Agentic AI — OpenID pre-IIW workshop", + "source_type": "conference_talk", + "work_or_episode_identity": "Identity Management for Agentic AI — OpenID pre-IIW workshop", + "author_or_speaker": "Tobin South", + "publisher": "OpenID Foundation", + "publication_date": "2025-10-20", + "event_date": "2025-10-20", + "original_url": "https://openid.net/wp-content/uploads/2025/10/Pre-IIW-Workshop-October-2025-1.pdf", + "canonical_url": "https://openid.net/wp-content/uploads/2025/10/Pre-IIW-Workshop-October-2025-1.pdf", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-board-director" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_media_or_event_metadata", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Official event agenda identifies a 30-minute primary presentation by the report lead.", + "diversity_contribution": [ + "primary spoken perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Official event agenda identifies a 30-minute primary presentation by the report lead.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q034", + "Q035" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-107", + "title": "Securing Non-Human Identities in the Age of AI Agents — CSA Summit at RSAC 2025", + "source_type": "conference_talk", + "work_or_episode_identity": "Securing Non-Human Identities in the Age of AI Agents — CSA Summit at RSAC 2025", + "author_or_speaker": "Alon Jackson and Albert Attias", + "publisher": "Cloud Security Alliance", + "publication_date": "2025-04-29", + "event_date": "2025-04-29", + "original_url": "https://cloudsecurityalliance.org/artifacts/securing-non-human-identities-in-the-age-of-ai-agents-rsac-2025", + "canonical_url": "https://cloudsecurityalliance.org/artifacts/securing-non-human-identities-in-the-age-of-ai-agents-rsac-2025", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-board-director" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_media_or_event_metadata", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Official event-hosted presentation focused directly on NHI growth and AI agents.", + "diversity_contribution": [ + "primary spoken perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Official event-hosted presentation focused directly on NHI growth and AI agents.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q034", + "Q035" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-108", + "title": "Finding Shadow AI Agents — and the Identities Behind Them", + "source_type": "event_recording", + "work_or_episode_identity": "Finding Shadow AI Agents — and the Identities Behind Them", + "author_or_speaker": "Cloud Security Alliance webinar speakers", + "publisher": "Cloud Security Alliance", + "publication_date": "2025-07-24", + "event_date": "2025-07-24", + "original_url": "https://cloudsecurityalliance.org/events/webinars?event_topic=zero-trust&page=3", + "canonical_url": "https://cloudsecurityalliance.org/events/webinars?event_topic=zero-trust&page=3", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-board-director" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_media_or_event_metadata", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Official webinar listing is relevant, but the episode-level recording URL and speaker metadata need resolution.", + "diversity_contribution": [ + "primary spoken perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Official webinar listing is relevant, but the episode-level recording URL and speaker metadata need resolution.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q034", + "Q035" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-109", + "title": "Governing AI Agents with Agent Identity Security", + "source_type": "video", + "work_or_episode_identity": "Governing AI Agents with Agent Identity Security", + "author_or_speaker": "Rachel Leighter / SailPoint video presenter", + "publisher": "SailPoint Developer Community", + "publication_date": "2025-11-20", + "event_date": null, + "original_url": "https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944", + "canonical_url": "https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-board-director" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_media_or_event_metadata", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary vendor-hosted practitioner demonstration and discussion.", + "diversity_contribution": [ + "primary spoken perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary vendor-hosted practitioner demonstration and discussion.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q034", + "Q035" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-110", + "title": "What Makes Agentic AI Identity So Different?", + "source_type": "conference_talk", + "work_or_episode_identity": "What Makes Agentic AI Identity So Different?", + "author_or_speaker": "John Kemp", + "publisher": "Identiverse", + "publication_date": "2026-06-16", + "event_date": "2026-06-16", + "original_url": "https://identiverse.com/idv26/session/?idvid=3931776", + "canonical_url": "https://identiverse.com/idv26/session/?idvid=3931776", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-board-director" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_media_or_event_metadata", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Primary financial-services identity practitioner session with explicit dissent from static identity models.", + "diversity_contribution": [ + "primary spoken perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "accept", + "reason": "Primary financial-services identity practitioner session with explicit dissent from static identity models.", + "next_research_action": "Human reviewer to confirm candidate selection before any extraction or production record.", + "search_query_ids": [ + "Q034", + "Q035" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-111", + "title": "Concept paper PDF rendition: Accelerating the Adoption of Software and AI Agent Identity and Authorization", + "source_type": "public_policy_document", + "work_or_episode_identity": "Concept paper PDF rendition: Accelerating the Adoption of Software and AI Agent Identity and Authorization", + "author_or_speaker": "NIST NCCoE", + "publisher": "NIST NCCoE", + "publication_date": "2026-02", + "event_date": null, + "original_url": "https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization-concept-paper.pdf", + "canonical_url": "https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization-concept-paper.pdf", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Exact rendition duplicate of the accepted NIST concept-paper work.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": true, + "existing_related_records": [ + "See duplicate-review.json for the retained candidate identity." + ], + "decision": "reject", + "reason": "Exact rendition duplicate of the accepted NIST concept-paper work.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-112", + "title": "State of Agentic AI Security and Governance direct download", + "source_type": "research_report", + "work_or_episode_identity": "State of Agentic AI Security and Governance direct download", + "author_or_speaker": "OWASP GenAI Security Project", + "publisher": "OWASP GenAI Security Project", + "publication_date": "2026-06", + "event_date": null, + "original_url": "https://genai.owasp.org/download/50592/?tmstv=1754459367", + "canonical_url": "https://genai.owasp.org/download/50592/?tmstv=1754459367", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "moderate", + "evidence_contribution": "Direct-download duplicate of the accepted canonical report landing page.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": true, + "existing_related_records": [ + "See duplicate-review.json for the retained candidate identity." + ], + "decision": "reject", + "reason": "Direct-download duplicate of the accepted canonical report landing page.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-113", + "title": "Multi-Agentic System Threat Modeling Guide direct download", + "source_type": "research_report", + "work_or_episode_identity": "Multi-Agentic System Threat Modeling Guide direct download", + "author_or_speaker": "OWASP Agentic Security Initiative", + "publisher": "OWASP GenAI Security Project", + "publication_date": "2025-04", + "event_date": null, + "original_url": "https://genai.owasp.org/download/46950/?tmstv=1745459605", + "canonical_url": "https://genai.owasp.org/download/46950/?tmstv=1745459605", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "moderate", + "evidence_contribution": "Direct-download duplicate of the accepted canonical guide landing page.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": true, + "existing_related_records": [ + "See duplicate-review.json for the retained candidate identity." + ], + "decision": "reject", + "reason": "Direct-download duplicate of the accepted canonical guide landing page.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-114", + "title": "Model AI Governance Framework for Agentic AI PDF rendition", + "source_type": "public_policy_document", + "work_or_episode_identity": "Model AI Governance Framework for Agentic AI PDF rendition", + "author_or_speaker": "IMDA Singapore", + "publisher": "IMDA Singapore", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf", + "canonical_url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf", + "language": "lang-en", + "relevant_geographies": [ + "Singapore", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "PDF rendition duplicate of the accepted official framework landing page.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": true, + "existing_related_records": [ + "See duplicate-review.json for the retained candidate identity." + ], + "decision": "reject", + "reason": "PDF rendition duplicate of the accepted official framework landing page.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-115", + "title": "Pre-IIW workshop slide deck as a whitepaper duplicate", + "source_type": "research_report", + "work_or_episode_identity": "Pre-IIW workshop slide deck as a whitepaper duplicate", + "author_or_speaker": "OpenID Foundation", + "publisher": "OpenID Foundation", + "publication_date": "2025-10-20", + "event_date": null, + "original_url": "https://openid.net/wp-content/uploads/2025/10/Pre-IIW-Workshop-October-2025-1.pdf#page=1", + "canonical_url": "https://openid.net/wp-content/uploads/2025/10/Pre-IIW-Workshop-October-2025-1.pdf#page=1", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "moderate", + "evidence_contribution": "Same event artifact as the accepted conference-talk candidate; not a separate research work.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": true, + "existing_related_records": [ + "See duplicate-review.json for the retained candidate identity." + ], + "decision": "reject", + "reason": "Same event artifact as the accepted conference-talk candidate; not a separate research work.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-116", + "title": "Generic passwordless authentication paper surfaced by agent-authentication search", + "source_type": "academic_paper", + "work_or_episode_identity": "Generic passwordless authentication paper surfaced by agent-authentication search", + "author_or_speaker": "Unresolved", + "publisher": "arXiv search", + "publication_date": null, + "event_date": null, + "original_url": "https://arxiv.org/search/?query=passwordless+authentication&searchtype=all", + "canonical_url": "https://arxiv.org/search/?query=passwordless+authentication&searchtype=all", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [], + "relevant_industries": [], + "relevant_topics": [ + "screened adjacent topic" + ], + "primary_or_secondary": "locator_only", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "low", + "evidence_contribution": "Search-result page and generic human authentication topic; no canonical agent-identity work.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "reject", + "reason": "Search-result page and generic human authentication topic; no canonical agent-identity work.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-117", + "title": "Blockchain autonomous-weapons identity paper surfaced by autonomous-agent search", + "source_type": "academic_paper", + "work_or_episode_identity": "Blockchain autonomous-weapons identity paper surfaced by autonomous-agent search", + "author_or_speaker": "Unresolved", + "publisher": "arXiv search", + "publication_date": null, + "event_date": null, + "original_url": "https://arxiv.org/search/?query=blockchain+autonomous+weapons+identity&searchtype=all", + "canonical_url": "https://arxiv.org/search/?query=blockchain+autonomous+weapons+identity&searchtype=all", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [], + "relevant_industries": [], + "relevant_topics": [ + "screened adjacent topic" + ], + "primary_or_secondary": "locator_only", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "low", + "evidence_contribution": "Outside enterprise-agent identity governance and lacks a canonically selected work.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "reject", + "reason": "Outside enterprise-agent identity governance and lacks a canonically selected work.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-118", + "title": "Privacy and security for humanoid robots search result", + "source_type": "academic_paper", + "work_or_episode_identity": "Privacy and security for humanoid robots search result", + "author_or_speaker": "Unresolved", + "publisher": "arXiv search", + "publication_date": null, + "event_date": null, + "original_url": "https://arxiv.org/search/?query=privacy+security+humanoid+robots&searchtype=all", + "canonical_url": "https://arxiv.org/search/?query=privacy+security+humanoid+robots&searchtype=all", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [], + "relevant_industries": [], + "relevant_topics": [ + "screened adjacent topic" + ], + "primary_or_secondary": "locator_only", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "low", + "evidence_contribution": "Robotics-hardware scope and search-page identity fail the protocol.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "reject", + "reason": "Robotics-hardware scope and search-page identity fail the protocol.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-119", + "title": "ARIA mobile DevOps agent result", + "source_type": "academic_paper", + "work_or_episode_identity": "ARIA mobile DevOps agent result", + "author_or_speaker": "Unresolved", + "publisher": "arXiv search", + "publication_date": null, + "event_date": null, + "original_url": "https://arxiv.org/search/?query=ARIA+mobile+DevOps+agent&searchtype=all", + "canonical_url": "https://arxiv.org/search/?query=ARIA+mobile+DevOps+agent&searchtype=all", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [], + "relevant_industries": [], + "relevant_topics": [ + "screened adjacent topic" + ], + "primary_or_secondary": "locator_only", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "low", + "evidence_contribution": "Name collision with agentic terminology; no relevant identity contribution.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "reject", + "reason": "Name collision with agentic terminology; no relevant identity contribution.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-120", + "title": "The Agentic AI Bible retail listing", + "source_type": "book", + "work_or_episode_identity": "The Agentic AI Bible retail listing", + "author_or_speaker": "Unresolved", + "publisher": "Retail marketplace", + "publication_date": null, + "event_date": null, + "original_url": "https://www.amazon.com/s?k=The+Agentic+AI+Bible", + "canonical_url": "https://www.amazon.com/s?k=The+Agentic+AI+Bible", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [], + "relevant_industries": [], + "relevant_topics": [ + "screened adjacent topic" + ], + "primary_or_secondary": "locator_only", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "low", + "evidence_contribution": "Retail search listing, unstable work identity, promotional positioning, and insufficient scholarly or practitioner authority.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "reject", + "reason": "Retail search listing, unstable work identity, promotional positioning, and insufficient scholarly or practitioner authority.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + } +] diff --git a/staging/batches/BATCH-2026-001/coverage-analysis.md b/staging/batches/BATCH-2026-001/coverage-analysis.md new file mode 100644 index 0000000..8f7978d --- /dev/null +++ b/staging/batches/BATCH-2026-001/coverage-analysis.md @@ -0,0 +1,36 @@ +# Coverage analysis — BATCH-2026-001 + +## Result + +The batch screened 120 candidates: 91 accepted for human selection review, 19 held, and 10 rejected. Five rejects are alternate renditions grouped in `duplicate-review.json`. No source, statement, proposition, or publication record was created. + +## Coverage before discovery + +The repository contained zero canonical sources, books, people, statements, propositions, or dossiers on governed identities for AI agents. The only prior research batch covered repository architecture, not the topic. Existing topic coverage was therefore zero across source type, role, geography, industry, language, and perspective. + +## Coverage after discovery + +The 120-candidate slate contains 20 standards or technical-reference items (`other_approved`), 19 research reports, 17 public-policy documents, 14 essays, 14 working papers, 14 academic papers, 10 books, five executive surveys, and seven primary-media items. The accepted set contains 91 candidates. + +Role coverage is strongest for CISOs, CIOs, and CTOs. Board and chief-executive coverage is present through the World Economic Forum, executive surveys, and public-policy sources, but it remains much thinner than technical and security coverage. General-counsel coverage comes mainly from regulators, accountability frameworks, and the OpenID discussion of delegation and liability; direct legal scholarship is a gap. + +Geographic coverage includes official sources from the United States, European Union, United Kingdom, Canada, Singapore, Australia, and Japan. India produced no qualifying source. Most academic, standards, vendor, and book candidates are tagged global, which indicates applicability rather than author or sample diversity. English is the only supported language and all 120 candidates are English-language records. + +Industry coverage is mostly cross-industry. Financial-services insight appears in the Identiverse Capital One session and global surveys. Public-sector coverage is comparatively strong. Healthcare and life sciences, critical infrastructure, and professional-services operator evidence remain weak; general standards should not be misrepresented as sector evidence. + +## Strongest candidate clusters + +- Public authority: NIST’s agent identity concept paper and RFI analysis; Singapore’s agentic governance framework and sandbox; Australian, Canadian, NSW, and UK guidance. +- Standards and community practice: IETF authorization and audit drafts, SPIFFE, OpenID Foundation, OWASP, and Cloud Security Alliance. +- Empirical evidence: three sponsor-disclosed CSA surveys and F5’s 1,100-plus decision-maker survey. +- Academic evidence: authorization propagation, SAGA, AAGATE, personhood credentials, AgentDojo, InjecAgent, ToolEmu, and related benchmarks. +- Books: *Solving the Bottom Turtle*, *Zero Trust Networks*, *OAuth 2 in Action*, *Identity-Native Infrastructure Access Management*, and modern identity/API-security works. +- Primary media: the Tobin South podcast, the OpenID workshop, the CSA Summit talk, the SailPoint practitioner video, and John Kemp’s Identiverse session. + +## Agreement, challenge, and uncertainty + +The dominant position is that agents need distinct, attributable identity; bounded and context-sensitive authority; short-lived credentials; lifecycle ownership; revocation; and action-level audit. Meaningful counterpositions are present: OpenID argues for incremental evolution of existing identity infrastructure rather than a wholly new stack; SPIFFE treats workload identity as a reusable foundation; personhood-credential research separates proof of humanity from agent identity; and the Identiverse session argues that nondeterministic agency makes identity more contextual and unstable than traditional service accounts. The evidence base does not yet establish a single settled architecture. + +## Decision boundary + +“Accepted” means only that a candidate appears strong enough for named-human selection review. It does not mean the source is approved, extracted, endorsed, or publishable. Holdings and rights are link-and-metadata only unless a later review records a lawful use basis. diff --git a/staging/batches/BATCH-2026-001/duplicate-review.json b/staging/batches/BATCH-2026-001/duplicate-review.json new file mode 100644 index 0000000..feedcb8 --- /dev/null +++ b/staging/batches/BATCH-2026-001/duplicate-review.json @@ -0,0 +1,56 @@ +{ + "batch_id": "BATCH-2026-001", + "generated_at": "2026-08-15", + "groups": [ + { + "duplicate_group_id": "dup-001", + "normalized_work_identity": "NIST agent identity concept paper", + "retained_candidate_id": "candidate-BATCH-2026-001-001", + "rejected_candidate_ids": [ + "candidate-BATCH-2026-001-111" + ], + "resolution": "Retain the most stable official landing page or distinct event identity; reject alternate rendition as a separate candidate.", + "human_review_status": "pending" + }, + { + "duplicate_group_id": "dup-002", + "normalized_work_identity": "OWASP State of Agentic AI Security and Governance", + "retained_candidate_id": "candidate-BATCH-2026-001-022", + "rejected_candidate_ids": [ + "candidate-BATCH-2026-001-112" + ], + "resolution": "Retain the most stable official landing page or distinct event identity; reject alternate rendition as a separate candidate.", + "human_review_status": "pending" + }, + { + "duplicate_group_id": "dup-003", + "normalized_work_identity": "OWASP Multi-Agentic System Threat Modeling Guide", + "retained_candidate_id": "candidate-BATCH-2026-001-020", + "rejected_candidate_ids": [ + "candidate-BATCH-2026-001-113" + ], + "resolution": "Retain the most stable official landing page or distinct event identity; reject alternate rendition as a separate candidate.", + "human_review_status": "pending" + }, + { + "duplicate_group_id": "dup-004", + "normalized_work_identity": "Singapore Model AI Governance Framework for Agentic AI", + "retained_candidate_id": "candidate-BATCH-2026-001-031", + "rejected_candidate_ids": [ + "candidate-BATCH-2026-001-114" + ], + "resolution": "Retain the most stable official landing page or distinct event identity; reject alternate rendition as a separate candidate.", + "human_review_status": "pending" + }, + { + "duplicate_group_id": "dup-005", + "normalized_work_identity": "OpenID pre-IIW event artifact", + "retained_candidate_id": "candidate-BATCH-2026-001-106", + "rejected_candidate_ids": [ + "candidate-BATCH-2026-001-115" + ], + "resolution": "Retain the most stable official landing page or distinct event identity; reject alternate rendition as a separate candidate.", + "human_review_status": "pending" + } + ] +} diff --git a/staging/batches/BATCH-2026-001/hold-queue.json b/staging/batches/BATCH-2026-001/hold-queue.json new file mode 100644 index 0000000..b0ce1bf --- /dev/null +++ b/staging/batches/BATCH-2026-001/hold-queue.json @@ -0,0 +1,1182 @@ +[ + { + "candidate_id": "candidate-BATCH-2026-001-003", + "title": "Announcing the AI Agent Standards Initiative", + "source_type": "essay", + "work_or_episode_identity": "Announcing the AI Agent Standards Initiative", + "author_or_speaker": "NIST", + "publisher": "NIST", + "publication_date": "2026-02", + "event_date": null, + "original_url": "https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure", + "canonical_url": "https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Official announcement overlaps the initiative page and may add little distinct evidence.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Official announcement overlaps the initiative page and may add little distinct evidence.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-008", + "title": "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations", + "source_type": "research_report", + "work_or_episode_identity": "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations", + "author_or_speaker": "NIST", + "publisher": "NIST", + "publication_date": "2025", + "event_date": null, + "original_url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2025.pdf", + "canonical_url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2025.pdf", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-general-counsel" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Strong security taxonomy but agent-identity contribution is indirect.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Strong security taxonomy but agent-identity contribution is indirect.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-018", + "title": "SPIFFE concepts overview", + "source_type": "other_approved", + "work_or_episode_identity": "SPIFFE concepts overview", + "author_or_speaker": "SPIFFE Project", + "publisher": "SPIFFE Project", + "publication_date": null, + "event_date": null, + "original_url": "https://spiffe.io/docs/latest/spiffe/concepts/", + "canonical_url": "https://spiffe.io/docs/latest/spiffe/concepts/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "critical infrastructure" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Useful orientation but largely duplicates individual specifications.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Useful orientation but largely duplicates individual specifications.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-023", + "title": "OWASP Cornucopia companion edition: Agentic AI", + "source_type": "other_approved", + "work_or_episode_identity": "OWASP Cornucopia companion edition: Agentic AI", + "author_or_speaker": "OWASP", + "publisher": "OWASP", + "publication_date": "2026", + "event_date": null, + "original_url": "https://cornucopia.owasp.org/cards/AAIJ", + "canonical_url": "https://cornucopia.owasp.org/cards/AAIJ", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Useful threat-elicitation tool, but evidentiary and identity depth are limited.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Useful threat-elicitation tool, but evidentiary and identity depth are limited.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-028", + "title": "EU AI Act Service Desk FAQ: applicability to AI agents", + "source_type": "public_policy_document", + "work_or_episode_identity": "EU AI Act Service Desk FAQ: applicability to AI agents", + "author_or_speaker": "European Commission", + "publisher": "European Commission", + "publication_date": "2026", + "event_date": null, + "original_url": "https://ai-act-service-desk.ec.europa.eu/en/faq?faq_category_id=69", + "canonical_url": "https://ai-act-service-desk.ec.europa.eu/en/faq?faq_category_id=69", + "language": "lang-en", + "relevant_geographies": [ + "European Union" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Authoritative legal context, but identity-specific guidance is limited.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Authoritative legal context, but identity-specific guidance is limited.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-029", + "title": "Guidelines for general-purpose AI providers: FAQ", + "source_type": "public_policy_document", + "work_or_episode_identity": "Guidelines for general-purpose AI providers: FAQ", + "author_or_speaker": "European Commission", + "publisher": "European Commission", + "publication_date": "2025", + "event_date": null, + "original_url": "https://digital-strategy.ec.europa.eu/en/faqs/guidelines-obligations-general-purpose-ai-providers", + "canonical_url": "https://digital-strategy.ec.europa.eu/en/faqs/guidelines-obligations-general-purpose-ai-providers", + "language": "lang-en", + "relevant_geographies": [ + "European Union" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Useful provider-duty context with only indirect agent-identity relevance.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Useful provider-duty context with only indirect agent-identity relevance.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-030", + "title": "Artificial Intelligence Act policy overview", + "source_type": "public_policy_document", + "work_or_episode_identity": "Artificial Intelligence Act policy overview", + "author_or_speaker": "Council of the European Union", + "publisher": "Council of the European Union", + "publication_date": "2024", + "event_date": null, + "original_url": "https://www.consilium.europa.eu/en/policies/artificial-intelligence-act/", + "canonical_url": "https://www.consilium.europa.eu/en/policies/artificial-intelligence-act/", + "language": "lang-en", + "relevant_geographies": [ + "European Union" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Authoritative but too general for identity-specific extraction without a legal mapping pass.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Authoritative but too general for identity-specific extraction without a legal mapping pass.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-038", + "title": "Considerations in Autonomous Agents", + "source_type": "research_report", + "work_or_episode_identity": "Considerations in Autonomous Agents", + "author_or_speaker": "ENISA", + "publisher": "ENISA", + "publication_date": "2019", + "event_date": null, + "original_url": "https://www.enisa.europa.eu/publications/considerations-in-autonomous-agents", + "canonical_url": "https://www.enisa.europa.eu/publications/considerations-in-autonomous-agents", + "language": "lang-en", + "relevant_geographies": [ + "European Union" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Foundational European security view but outside the primary time window and predates current agent architectures.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Foundational European security view but outside the primary time window and predates current agent architectures.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-039", + "title": "ENISA view on cybersecurity in the frontier AI era", + "source_type": "research_report", + "work_or_episode_identity": "ENISA view on cybersecurity in the frontier AI era", + "author_or_speaker": "ENISA", + "publisher": "ENISA", + "publication_date": "2026-07", + "event_date": null, + "original_url": "https://www.enisa.europa.eu/sites/default/files/2026-07/ENISA%20view%20on%20cybersecurity%20in%20the%20frontier%20AI%20era_en_0.pdf", + "canonical_url": "https://www.enisa.europa.eu/sites/default/files/2026-07/ENISA%20view%20on%20cybersecurity%20in%20the%20frontier%20AI%20era_en_0.pdf", + "language": "lang-en", + "relevant_geographies": [ + "European Union" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Current and authoritative, but agent identity requires targeted full-text review.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Current and authoritative, but agent identity requires targeted full-text review.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-044", + "title": "AI governance discussion paper for social implementation", + "source_type": "public_policy_document", + "work_or_episode_identity": "AI governance discussion paper for social implementation", + "author_or_speaker": "METI Japan", + "publisher": "METI Japan", + "publication_date": "2026-03-31", + "event_date": null, + "original_url": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_14.pdf", + "canonical_url": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_14.pdf", + "language": "lang-en", + "relevant_geographies": [ + "Japan" + ], + "relevant_roles": [ + "role-general-counsel", + "role-ciso", + "role-cio", + "role-board-director" + ], + "relevant_industries": [ + "public sector and defense", + "regulated industries" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Geographically valuable official source; English-language and agent-identity coverage need human verification.", + "diversity_contribution": [ + "public-sector perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Geographically valuable official source; English-language and agent-identity coverage need human verification.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-052", + "title": "AgentSecBench: Benchmarking Security of LLM Agents", + "source_type": "working_paper", + "work_or_episode_identity": "AgentSecBench: Benchmarking Security of LLM Agents", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2026-05", + "event_date": null, + "original_url": "https://arxiv.org/abs/2605.26269", + "canonical_url": "https://arxiv.org/abs/2605.26269", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Potentially valuable new benchmark; peer-review and identity-specific results need verification.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Potentially valuable new benchmark; peer-review and identity-specific results need verification.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-053", + "title": "The Layered Attack Surface of LLM-Based Agent Systems: A Survey", + "source_type": "working_paper", + "work_or_episode_identity": "The Layered Attack Surface of LLM-Based Agent Systems: A Survey", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2026-04", + "event_date": null, + "original_url": "https://arxiv.org/abs/2604.23338", + "canonical_url": "https://arxiv.org/abs/2604.23338", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Current synthesis but very new and not specifically centered on identity.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Current synthesis but very new and not specifically centered on identity.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-063", + "title": "LanG: A Capability-Based Authorization Model for LLM Agents", + "source_type": "working_paper", + "work_or_episode_identity": "LanG: A Capability-Based Authorization Model for LLM Agents", + "author_or_speaker": "Paper authors", + "publisher": "arXiv", + "publication_date": "2026-04", + "event_date": null, + "original_url": "https://arxiv.org/abs/2604.05440", + "canonical_url": "https://arxiv.org/abs/2604.05440", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-cto", + "role-ciso" + ], + "relevant_industries": [ + "cross-industry research" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "documented_or_reviewable", + "source_identity_stability": "high", + "evidence_contribution": "Promising capability model; recent preprint requires deeper technical review.", + "diversity_contribution": [ + "academic perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Promising capability model; recent preprint requires deeper technical review.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-069", + "title": "The Rise and Risks of Agentic AI", + "source_type": "executive_survey", + "work_or_episode_identity": "The Rise and Risks of Agentic AI", + "author_or_speaker": "PwC", + "publisher": "PwC", + "publication_date": "2025-07-17", + "event_date": null, + "original_url": "https://www.pwc.com/us/en/industries/tmt/library/trust-and-safety-outlook/rise-and-risks-of-agentic-ai.html", + "canonical_url": "https://www.pwc.com/us/en/industries/tmt/library/trust-and-safety-outlook/rise-and-risks-of-agentic-ai.html", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-board-director", + "role-ceo" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "partially_disclosed", + "source_identity_stability": "high", + "evidence_contribution": "Useful executive trust data, but sample and methods require confirmation in the linked report.", + "diversity_contribution": [ + "empirical evidence", + "sponsor-disclosed research" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Useful executive trust data, but sample and methods require confirmation in the linked report.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q036", + "Q037" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-090", + "title": "AI identity security compliance checklist", + "source_type": "other_approved", + "work_or_episode_identity": "AI identity security compliance checklist", + "author_or_speaker": "Okta", + "publisher": "Okta", + "publication_date": "2026-03", + "event_date": null, + "original_url": "https://www.okta.com/sites/default/files/2026-03/AI-identity-security-compliance-checklist.pdf", + "canonical_url": "https://www.okta.com/sites/default/files/2026-03/AI-identity-security-compliance-checklist.pdf", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Potentially useful checklist but heavily product-adjacent and methodologically thin.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Potentially useful checklist but heavily product-adjacent and methodologically thin.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-093", + "title": "CyberArk Secure AI Agents", + "source_type": "other_approved", + "work_or_episode_identity": "CyberArk Secure AI Agents", + "author_or_speaker": "CyberArk", + "publisher": "CyberArk", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.cyberark.com/solutions/secure-agentic-ai/", + "canonical_url": "https://www.cyberark.com/solutions/secure-agentic-ai/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Relevant capabilities but solution page is promotional; retain for market-context review only.", + "diversity_contribution": [ + "vendor perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Relevant capabilities but solution page is promotional; retain for market-context review only.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q025", + "Q026", + "Q027", + "Q028", + "Q029", + "Q030", + "Q031", + "Q032" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-103", + "title": "AI Engineering", + "source_type": "book", + "work_or_episode_identity": "AI Engineering", + "author_or_speaker": "Chip Huyen", + "publisher": "O’Reilly Media", + "publication_date": "2025", + "event_date": null, + "original_url": "https://www.oreilly.com/library/view/ai-engineering/9781098166298/", + "canonical_url": "https://www.oreilly.com/library/view/ai-engineering/9781098166298/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto", + "role-cio" + ], + "relevant_industries": [ + "technology and cloud", + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "high", + "evidence_contribution": "Important agent-building context, but identity contribution needs chapter-level access review.", + "diversity_contribution": [ + "long-form perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Important agent-building context, but identity contribution needs chapter-level access review.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q033" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-105", + "title": "When the Client Is a Mind", + "source_type": "podcast_episode", + "work_or_episode_identity": "When the Client Is a Mind", + "author_or_speaker": "OpenID Foundation speakers", + "publisher": "OpenID Foundation", + "publication_date": "2025-10", + "event_date": null, + "original_url": "https://openid.net/cg/artificial-intelligence-identity-management-community-group/", + "canonical_url": "https://openid.net/cg/artificial-intelligence-identity-management-community-group/", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-board-director" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_media_or_event_metadata", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Official listing confirms the episode, but a stable episode-level canonical URL remains unresolved.", + "diversity_contribution": [ + "primary spoken perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Official listing confirms the episode, but a stable episode-level canonical URL remains unresolved.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q034", + "Q035" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-108", + "title": "Finding Shadow AI Agents — and the Identities Behind Them", + "source_type": "event_recording", + "work_or_episode_identity": "Finding Shadow AI Agents — and the Identities Behind Them", + "author_or_speaker": "Cloud Security Alliance webinar speakers", + "publisher": "Cloud Security Alliance", + "publication_date": "2025-07-24", + "event_date": "2025-07-24", + "original_url": "https://cloudsecurityalliance.org/events/webinars?event_topic=zero-trust&page=3", + "canonical_url": "https://cloudsecurityalliance.org/events/webinars?event_topic=zero-trust&page=3", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cio", + "role-cto", + "role-board-director" + ], + "relevant_industries": [ + "cross-industry enterprise" + ], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_media_or_event_metadata", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Official webinar listing is relevant, but the episode-level recording URL and speaker metadata need resolution.", + "diversity_contribution": [ + "primary spoken perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "hold", + "reason": "Official webinar listing is relevant, but the episode-level recording URL and speaker metadata need resolution.", + "next_research_action": "Resolve the stated metadata, relevance, access, or methodological question before selection.", + "search_query_ids": [ + "Q034", + "Q035" + ] + } +] diff --git a/staging/batches/BATCH-2026-001/limitations.md b/staging/batches/BATCH-2026-001/limitations.md new file mode 100644 index 0000000..fb8eecf --- /dev/null +++ b/staging/batches/BATCH-2026-001/limitations.md @@ -0,0 +1,17 @@ +# Limitations — BATCH-2026-001 + +- This is a discovery batch, not a publication corpus. No candidate has named-human selection approval. +- Metadata were verified through public official pages where available, but not every date, author list, edition, media duration, or revision state has had a second-person check. +- Web search ranking and indexing create systematic visibility bias toward large institutions, current English content, vendors, and arXiv. +- English-only intake excluded non-English primary sources even where they may be central to national practice. +- Several 2026 items are drafts or newly published and have little independent scrutiny. +- Academic candidates include preprints. “Academic” or “working paper” does not imply peer review or empirical validation. +- Survey sponsors are disclosed, but questionnaires, sampling frames, response-rate information, weighting, and raw data were not always public. +- Official vendor documentation is strong evidence of product behavior and market direction, but weak evidence of universal effectiveness. +- Book candidates are mostly metadata-only. Chapter-level identity relevance and edition identity need later review. +- Seven media candidates are fewer than desired; two are held because stable episode-level identity or recording metadata are unresolved. +- Global geography tags indicate intended applicability, not contributor, sample, or jurisdictional diversity. +- Source rights are recorded conservatively as link-and-metadata only; no third-party source text, transcript, image, or complete document was copied. +- Search logs report qualitative yield, not exhaustive database result counts. +- Duplicate review is work-level and URL-level; semantic overlap among nonidentical frameworks remains for human review. +- The stopping rule was satisfied at the pre-registered target of 120, but saturation is provisional in a rapidly changing field. diff --git a/staging/batches/BATCH-2026-001/manifest.yml b/staging/batches/BATCH-2026-001/manifest.yml new file mode 100644 index 0000000..d4d0a11 --- /dev/null +++ b/staging/batches/BATCH-2026-001/manifest.yml @@ -0,0 +1,67 @@ +batch_id: BATCH-2026-001 +protocol_id: protocol-BATCH-2026-001 +prompt_id: OEII-TOPIC-DISCOVERY +prompt_version: "2.0" +branch: research/discovery-governed-agent-identities-BATCH-2026-001 +pull_request: https://github.com/OpenFutureForum/executive-intelligence-index/pull/2 +execution_started_at: 2026-08-15T10:34:21Z +execution_completed_at: 2026-08-15T10:53:35Z +agent_or_researcher: OpenAI Codex; machine-assisted discovery; human review pending +model_disclosure: AI-assisted discovery and metadata screening; no human selection approval and no publication approval occurred. +tools_used: [repository inspection, public web search, official source pages, Node.js, AJV, git] +research_question: How do public executive and institutional sources define governance requirements for AI-agent identities? +protocol_registered_before_external_search: true +protocol_changed_after_search: false +sources_considered: 120 +accepted_count: 91 +held_count: 19 +rejected_count: 10 +duplicate_groups: 5 +candidate_acceptance_is_publication_approval: false +production_records_created: 0 +statements_extracted: 0 +propositions_created: 0 +output_files: + - data/protocols/protocol-BATCH-2026-001.json + - operations/batch-registry.yml + - operations/research-roadmap.yml + - protocol.yml + - research-protocol.md + - search-log.yml + - candidate-source.schema.json + - candidate-sources.json + - accepted-candidates.json + - rejected-sources.json + - hold-queue.json + - duplicate-review.json + - coverage-analysis.md + - source-concentration.md + - research-gaps.md + - limitations.md + - next-batch-recommendations.yml + - validation-results.md +validation_commands: + - node --import tsx scripts/cli.ts validate data + - node --import tsx scripts/cli.ts validate provenance + - node --import tsx scripts/validate-discovery-batch.ts BATCH-2026-001 + - git diff --check +validation_results: + - PASS; canonical protocol schema and provenance validation. + - PASS; 120 candidates conform to the batch-local candidate schema and partition into 91 accepted, 19 held, and 10 rejected. + - PASS; candidate IDs, URLs, source identities, rights, ownership, duplicate groups, query references, roles, concentration, batch size, and staging isolation. + - WARN; no accepted India or Japan candidate and English-only language coverage; recorded as research gaps, not silently filled. + - PASS; repository attribution, statement, proposition, book-edition, locator, rights, review-status, publication, content, duplicate, concentration, and coverage gates. + - PASS; TypeScript and targeted ESLint checks; 24 unit tests across four files. + - NOTE; npm script wrappers that use tsx IPC cannot run inside the local seatbelt, so equivalent non-IPC node --import tsx commands were used. +workflow_status: candidate +machine_review_status: machine_drafted +human_review_status: pending +reviewed_by: null +reviewed_at: null +limitations: + - English-only discovery because the active controlled vocabulary currently contains only lang-en. + - Search visibility favors US standards bodies, hyperscalers, identity vendors, and English-language academic preprints. + - Candidate acceptance records discovery-screening judgment only; source, rights, identity, and selection review remain pending. + - Books were screened primarily through official metadata; chapter-level relevance usually remains unverified. + - Several 2026 working papers and policy sources are too new for independent evaluation. +next_action: Assign named reviewers to resolve the hold queue, verify candidate identities and dates, and select a balanced subset for source-record creation in a separate batch. diff --git a/staging/batches/BATCH-2026-001/next-batch-recommendations.yml b/staging/batches/BATCH-2026-001/next-batch-recommendations.yml new file mode 100644 index 0000000..6522903 --- /dev/null +++ b/staging/batches/BATCH-2026-001/next-batch-recommendations.yml @@ -0,0 +1,34 @@ +batch_id: BATCH-2026-001 +candidate_acceptance_is_publication_approval: false +recommended_sequence: + - priority: 1 + action: Resolve the 19-item hold queue with named human reviewers. + focus: dates, peer-review status, full-method access, episode identity, language, identity-specific relevance, and promotional dependence + - priority: 2 + action: Select a balanced source subset for canonical source-record creation in a separate batch. + constraints: [no single vendor family dominance, sponsor disclosure retained, public-authority or independent corroboration for vendor claims, separate work and rendition identity] + - priority: 3 + action: Run a legal and board-governance discovery batch. + queries: [agency and principal liability, delegated authority, evidentiary attribution, board oversight, audit committee controls, revocation and termination] + - priority: 4 + action: Run sector-specific operator batches. + sectors: [healthcare and life sciences, financial services, critical infrastructure, public sector and defense, professional services] + - priority: 5 + action: Extend geography and language coverage after controlled-vocabulary approval. + geographies: [India, Japan, South Korea, Brazil, Gulf states, continental Europe, Africa] + - priority: 6 + action: Commission or locate independent empirical evidence. + measures: [agent inventory completeness, unique identity adoption, credential lifetime, privilege reduction, deprovisioning latency, human attribution, incident rates] + - priority: 7 + action: Acquire primary OFF media only through a separately authorized interview or event workflow. + targets: [CISO operators, general counsel, board directors, regulators, standards authors, skeptical practitioners] +selection_questions: + - Which candidates have stable canonical identity and sufficient access for full analysis? + - Which claims can be corroborated outside vendor-sponsored ecosystems? + - Which works provide genuine challenge rather than repeating the dominant identity-first thesis? + - Which sources can support role-, industry-, and geography-specific statements without overgeneralization? +do_not_do: + - Do not treat candidate acceptance as source approval. + - Do not extract statements or create propositions in this batch. + - Do not copy full third-party text, transcripts, images, or book chapters. + - Do not suppress failed searches, sponsor relationships, draft status, or unresolved identity. diff --git a/staging/batches/BATCH-2026-001/protocol.yml b/staging/batches/BATCH-2026-001/protocol.yml new file mode 100644 index 0000000..c0b26d3 --- /dev/null +++ b/staging/batches/BATCH-2026-001/protocol.yml @@ -0,0 +1,46 @@ +protocol_id: protocol-BATCH-2026-001 +batch_id: BATCH-2026-001 +topic: governed identities for AI agents +topic_slug: governed-agent-identities +research_question: How do public executive and institutional sources define governance requirements for AI-agent identities? +why_it_matters: Agentic systems can initiate actions, use credentials, access data, delegate work, and cross system boundaries, creating executive requirements for bounded authority, traceable identity, revocation, auditability, and accountable human ownership. +included_topics: [AI-agent identity, non-human identity, directly applicable machine and workload identity, authentication, authorization, credential custody, delegation, least privilege, separation of duties, lifecycle and revocation, provenance, auditability, accountability, human oversight, agent-to-agent trust, policy enforcement] +excluded_adjacent_topics: [generic AI ethics without identity or authorization relevance, generic human IAM, consumer chatbot UX, model benchmarks, prompt engineering, robotics hardware, autonomous-vehicle identity, generic API-key guidance without agentic relevance] +time_period: 2020-08-15 through 2026-08-15; earlier directly foundational identity and zero-trust standards may be included. +target_roles: [role-ciso, role-cio, role-cto, role-general-counsel, role-board-director, role-ceo] +target_industries: [financial services, technology and cloud, healthcare and life sciences, public sector and defense, critical infrastructure, professional services] +target_geographies: [geo-global, United States, European Union, United Kingdom, Canada, Singapore, Australia, India, Japan] +target_languages: [lang-en] +included_source_types: [book, video, podcast_episode, keynote, panel, interview, conference_talk, essay, newsletter, public_letter, research_report, academic_paper, working_paper, executive_survey, event_recording, OFF_research, OFF_interview, OFF_video, public_policy_document, other_approved] +excluded_source_types: [private or confidential material, anonymous summaries, content farms, AI-generated summaries, scraped or unofficial transcripts, duplicate syndication, uncertain-rights third-party uploads, low-substance promotion] +inclusion_criteria: + - Publicly accessible or supported by stable public bibliographic metadata for metadata-only evaluation. + - Canonically identifiable work or episode, author or speaker, publisher, and date. + - Substantively relevant to identity, authorization, delegation, lifecycle, accountability, or oversight for AI agents or directly applicable non-human workloads. + - Original or official source where available. + - Distinct potential governance, technical, legal, operational, empirical, or dissenting contribution. + - Rights and ownership can be recorded without reproducing third-party text. +exclusion_criteria: + - Generic AI governance or IAM content without a meaningful agent-identity connection. + - Search snippets, inaccessible claims, ambiguous authorship, unverifiable dates, or unresolved source identity. + - Promotional reposts, uncertain-rights uploads, private events, off-the-record material, or full third-party transcripts. + - Search-visibility or quota-only selection. +quality_dimensions: [primary-source status, bibliographic stability, source-identity stability, analysis access, methodological transparency, independence, relevance, evidence contribution, rights clarity, ownership clarity, recency, diversity contribution] +source_priority: + - Original source + - Original publisher or event host + - Official author or institution + - Stable bibliographic or archival source + - Reliable independent contextual verification + - Secondary locator only +diversity_objectives: [executive roles, industries, geographies, languages, organization types, source types, established and emerging contributors, academic and practitioner perspectives, operator and investor perspectives, supporting and challenging positions, foundational and current sources, OFF-owned and external sources] +expected_limitations: [English-only controlled vocabulary, unsettled terminology, vendor and consulting visibility bias, metadata-only book access, underreported failures and internal controls, limited independent evaluation of new 2026 material] +planned_search_families: [cross-topic, standards bodies, laws and regulators, academic papers, executive and practitioner sources, books, primary media, priority industries, dissent and limitations, OFF-owned sources] +planned_stopping_rule: Stop between 100 and 150 credible candidates after all major families and roles are searched and two consecutive supplementary query families yield fewer than three new credible candidates each; document any lower saturation point. +planned_candidate_target: 120 +planned_review_method: Separate-dimension machine-assisted metadata and identity review followed by named-human selection review; no candidate acceptance equals publication approval. +created_at: 2026-08-15T10:34:21Z +created_by: OpenAI Codex; machine drafted; human review pending +prompt_id: OEII-TOPIC-DISCOVERY +prompt_version: "2.0" +protocol_changed_after_search: false diff --git a/staging/batches/BATCH-2026-001/rejected-sources.json b/staging/batches/BATCH-2026-001/rejected-sources.json new file mode 100644 index 0000000..466e88f --- /dev/null +++ b/staging/batches/BATCH-2026-001/rejected-sources.json @@ -0,0 +1,575 @@ +[ + { + "candidate_id": "candidate-BATCH-2026-001-111", + "title": "Concept paper PDF rendition: Accelerating the Adoption of Software and AI Agent Identity and Authorization", + "source_type": "public_policy_document", + "work_or_episode_identity": "Concept paper PDF rendition: Accelerating the Adoption of Software and AI Agent Identity and Authorization", + "author_or_speaker": "NIST NCCoE", + "publisher": "NIST NCCoE", + "publication_date": "2026-02", + "event_date": null, + "original_url": "https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization-concept-paper.pdf", + "canonical_url": "https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization-concept-paper.pdf", + "language": "lang-en", + "relevant_geographies": [ + "United States", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "Exact rendition duplicate of the accepted NIST concept-paper work.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": true, + "existing_related_records": [ + "See duplicate-review.json for the retained candidate identity." + ], + "decision": "reject", + "reason": "Exact rendition duplicate of the accepted NIST concept-paper work.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-112", + "title": "State of Agentic AI Security and Governance direct download", + "source_type": "research_report", + "work_or_episode_identity": "State of Agentic AI Security and Governance direct download", + "author_or_speaker": "OWASP GenAI Security Project", + "publisher": "OWASP GenAI Security Project", + "publication_date": "2026-06", + "event_date": null, + "original_url": "https://genai.owasp.org/download/50592/?tmstv=1754459367", + "canonical_url": "https://genai.owasp.org/download/50592/?tmstv=1754459367", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "moderate", + "evidence_contribution": "Direct-download duplicate of the accepted canonical report landing page.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": true, + "existing_related_records": [ + "See duplicate-review.json for the retained candidate identity." + ], + "decision": "reject", + "reason": "Direct-download duplicate of the accepted canonical report landing page.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-113", + "title": "Multi-Agentic System Threat Modeling Guide direct download", + "source_type": "research_report", + "work_or_episode_identity": "Multi-Agentic System Threat Modeling Guide direct download", + "author_or_speaker": "OWASP Agentic Security Initiative", + "publisher": "OWASP GenAI Security Project", + "publication_date": "2025-04", + "event_date": null, + "original_url": "https://genai.owasp.org/download/46950/?tmstv=1745459605", + "canonical_url": "https://genai.owasp.org/download/46950/?tmstv=1745459605", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "moderate", + "evidence_contribution": "Direct-download duplicate of the accepted canonical guide landing page.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": true, + "existing_related_records": [ + "See duplicate-review.json for the retained candidate identity." + ], + "decision": "reject", + "reason": "Direct-download duplicate of the accepted canonical guide landing page.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-114", + "title": "Model AI Governance Framework for Agentic AI PDF rendition", + "source_type": "public_policy_document", + "work_or_episode_identity": "Model AI Governance Framework for Agentic AI PDF rendition", + "author_or_speaker": "IMDA Singapore", + "publisher": "IMDA Singapore", + "publication_date": "2026", + "event_date": null, + "original_url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf", + "canonical_url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf", + "language": "lang-en", + "relevant_geographies": [ + "Singapore", + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "high", + "evidence_contribution": "PDF rendition duplicate of the accepted official framework landing page.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": true, + "existing_related_records": [ + "See duplicate-review.json for the retained candidate identity." + ], + "decision": "reject", + "reason": "PDF rendition duplicate of the accepted official framework landing page.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-115", + "title": "Pre-IIW workshop slide deck as a whitepaper duplicate", + "source_type": "research_report", + "work_or_episode_identity": "Pre-IIW workshop slide deck as a whitepaper duplicate", + "author_or_speaker": "OpenID Foundation", + "publisher": "OpenID Foundation", + "publication_date": "2025-10-20", + "event_date": null, + "original_url": "https://openid.net/wp-content/uploads/2025/10/Pre-IIW-Workshop-October-2025-1.pdf#page=1", + "canonical_url": "https://openid.net/wp-content/uploads/2025/10/Pre-IIW-Workshop-October-2025-1.pdf#page=1", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [ + "role-ciso", + "role-cto" + ], + "relevant_industries": [], + "relevant_topics": [ + "AI-agent identity", + "authorization", + "delegation", + "auditability", + "accountability" + ], + "primary_or_secondary": "primary_or_original_publisher", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "moderate", + "evidence_contribution": "Same event artifact as the accepted conference-talk candidate; not a separate research work.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": true, + "existing_related_records": [ + "See duplicate-review.json for the retained candidate identity." + ], + "decision": "reject", + "reason": "Same event artifact as the accepted conference-talk candidate; not a separate research work.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-116", + "title": "Generic passwordless authentication paper surfaced by agent-authentication search", + "source_type": "academic_paper", + "work_or_episode_identity": "Generic passwordless authentication paper surfaced by agent-authentication search", + "author_or_speaker": "Unresolved", + "publisher": "arXiv search", + "publication_date": null, + "event_date": null, + "original_url": "https://arxiv.org/search/?query=passwordless+authentication&searchtype=all", + "canonical_url": "https://arxiv.org/search/?query=passwordless+authentication&searchtype=all", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [], + "relevant_industries": [], + "relevant_topics": [ + "screened adjacent topic" + ], + "primary_or_secondary": "locator_only", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "low", + "evidence_contribution": "Search-result page and generic human authentication topic; no canonical agent-identity work.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "reject", + "reason": "Search-result page and generic human authentication topic; no canonical agent-identity work.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-117", + "title": "Blockchain autonomous-weapons identity paper surfaced by autonomous-agent search", + "source_type": "academic_paper", + "work_or_episode_identity": "Blockchain autonomous-weapons identity paper surfaced by autonomous-agent search", + "author_or_speaker": "Unresolved", + "publisher": "arXiv search", + "publication_date": null, + "event_date": null, + "original_url": "https://arxiv.org/search/?query=blockchain+autonomous+weapons+identity&searchtype=all", + "canonical_url": "https://arxiv.org/search/?query=blockchain+autonomous+weapons+identity&searchtype=all", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [], + "relevant_industries": [], + "relevant_topics": [ + "screened adjacent topic" + ], + "primary_or_secondary": "locator_only", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "low", + "evidence_contribution": "Outside enterprise-agent identity governance and lacks a canonically selected work.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "reject", + "reason": "Outside enterprise-agent identity governance and lacks a canonically selected work.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-118", + "title": "Privacy and security for humanoid robots search result", + "source_type": "academic_paper", + "work_or_episode_identity": "Privacy and security for humanoid robots search result", + "author_or_speaker": "Unresolved", + "publisher": "arXiv search", + "publication_date": null, + "event_date": null, + "original_url": "https://arxiv.org/search/?query=privacy+security+humanoid+robots&searchtype=all", + "canonical_url": "https://arxiv.org/search/?query=privacy+security+humanoid+robots&searchtype=all", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [], + "relevant_industries": [], + "relevant_topics": [ + "screened adjacent topic" + ], + "primary_or_secondary": "locator_only", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "low", + "evidence_contribution": "Robotics-hardware scope and search-page identity fail the protocol.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "reject", + "reason": "Robotics-hardware scope and search-page identity fail the protocol.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-119", + "title": "ARIA mobile DevOps agent result", + "source_type": "academic_paper", + "work_or_episode_identity": "ARIA mobile DevOps agent result", + "author_or_speaker": "Unresolved", + "publisher": "arXiv search", + "publication_date": null, + "event_date": null, + "original_url": "https://arxiv.org/search/?query=ARIA+mobile+DevOps+agent&searchtype=all", + "canonical_url": "https://arxiv.org/search/?query=ARIA+mobile+DevOps+agent&searchtype=all", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [], + "relevant_industries": [], + "relevant_topics": [ + "screened adjacent topic" + ], + "primary_or_secondary": "locator_only", + "analysis_access_status": "public_full_text_or_official_page", + "rights_status": "link_and_metadata_only_no_text_copied", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "perspective_not_empirical", + "source_identity_stability": "low", + "evidence_contribution": "Name collision with agentic terminology; no relevant identity contribution.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "reject", + "reason": "Name collision with agentic terminology; no relevant identity contribution.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q018", + "Q019", + "Q020", + "Q021", + "Q022", + "Q023", + "Q024" + ] + }, + { + "candidate_id": "candidate-BATCH-2026-001-120", + "title": "The Agentic AI Bible retail listing", + "source_type": "book", + "work_or_episode_identity": "The Agentic AI Bible retail listing", + "author_or_speaker": "Unresolved", + "publisher": "Retail marketplace", + "publication_date": null, + "event_date": null, + "original_url": "https://www.amazon.com/s?k=The+Agentic+AI+Bible", + "canonical_url": "https://www.amazon.com/s?k=The+Agentic+AI+Bible", + "language": "lang-en", + "relevant_geographies": [ + "geo-global" + ], + "relevant_roles": [], + "relevant_industries": [], + "relevant_topics": [ + "screened adjacent topic" + ], + "primary_or_secondary": "locator_only", + "analysis_access_status": "official_metadata_only", + "rights_status": "metadata_and_link_only", + "ownership_status": "external_not_OFF_owned", + "OFF_relationship": "none_identified", + "methodological_transparency": "not_applicable_metadata_only", + "source_identity_stability": "low", + "evidence_contribution": "Retail search listing, unstable work identity, promotional positioning, and insufficient scholarly or practitioner authority.", + "diversity_contribution": [ + "institutional or standards perspective" + ], + "likely_duplicate": false, + "existing_related_records": [], + "decision": "reject", + "reason": "Retail search listing, unstable work identity, promotional positioning, and insufficient scholarly or practitioner authority.", + "next_research_action": "Do not advance; retain this record as an auditable search and screening outcome.", + "search_query_ids": [ + "Q001", + "Q002", + "Q003", + "Q004", + "Q005", + "Q006", + "Q007", + "Q008", + "Q009", + "Q010", + "Q011", + "Q012", + "Q013", + "Q014", + "Q015", + "Q016", + "Q017", + "Q038" + ] + } +] diff --git a/staging/batches/BATCH-2026-001/research-gaps.md b/staging/batches/BATCH-2026-001/research-gaps.md new file mode 100644 index 0000000..096fcb0 --- /dev/null +++ b/staging/batches/BATCH-2026-001/research-gaps.md @@ -0,0 +1,27 @@ +# Research gaps — BATCH-2026-001 + +## Priority gaps + +1. Direct legal analysis of agency, delegation, liability, evidentiary attribution, and revocation for enterprise AI agents. +2. Board minutes, audit-committee practice, and named director perspectives on approving agent authority. +3. Independent empirical studies not commissioned by identity or security vendors. +4. Healthcare, life-sciences, critical-infrastructure, and defense operator evidence with concrete identity controls. +5. India-specific primary policy or practitioner material and broader non-US/non-European institutional evidence. +6. Non-English research; the active controlled vocabulary currently prevents responsible multilingual intake. +7. Longitudinal evidence on credential rotation, deprovisioning, orphaned agents, ownership changes, and incident response. +8. Comparative evaluation of distinct-agent identities, delegated human identities, workload identities, and capability credentials. +9. Stable media from regulators, boards, buyers, and operators rather than mainly standards and vendor speakers. +10. Negative results and failure reports, including controls that reduced agent usefulness or did not prevent misuse. + +## Unresolved research questions + +- Must every agent instance receive a persistent identity, or can task-scoped and ephemeral capability credentials provide better accountability? +- How should authority attenuate across recursive delegation and multi-agent chains? +- Which human sponsor, system owner, or legal principal remains accountable when an agent changes plans at runtime? +- How should identity evidence distinguish a model, agent blueprint, deployed agent, session, tool invocation, and the human or organization represented? +- What audit evidence is sufficient when actions are high-volume, nondeterministic, and cross organizational boundaries? +- Where do existing workload-identity standards suffice, and where do agent-specific semantics become necessary? + +## Sparse categories + +India, Japan-specific English analysis, healthcare, life sciences, critical infrastructure, professional-services operators, General Counsel, CEO, Board Director, independent podcasts, non-English books, and peer-reviewed empirical evaluations remain below desired depth. diff --git a/staging/batches/BATCH-2026-001/research-protocol.md b/staging/batches/BATCH-2026-001/research-protocol.md new file mode 100644 index 0000000..15db921 --- /dev/null +++ b/staging/batches/BATCH-2026-001/research-protocol.md @@ -0,0 +1,79 @@ +# Research protocol: governed identities for AI agents + +**Protocol ID:** `protocol-BATCH-2026-001` +**Batch ID:** `BATCH-2026-001` +**Prompt:** `OEII-TOPIC-DISCOVERY` version 2.0 +**Registered:** 2026-08-15T10:34:21Z, before external discovery +**Status:** Machine drafted; human review pending + +## Research question and importance + +How do public executive and institutional sources define governance requirements for AI-agent identities? + +Agentic systems can initiate actions, call tools, access data, delegate work, and cross system boundaries. Executives therefore need traceable answers about who or what an agent is, which human or organization authorized it, which credentials and permissions it may use, how delegation is constrained, how activity is audited, how access is revoked, and where accountability remains human or institutional. + +## Scope + +Included topics are AI-agent identity, non-human identity, machine and workload identity where directly applicable, authentication, authorization, credential issuance and custody, delegation, least privilege, separation of duties, lifecycle and revocation, provenance, auditability, accountability, human oversight, agent-to-agent trust, and policy enforcement. + +Excluded adjacent topics are generic AI ethics without an identity or authorization connection; generic human IAM; consumer chatbot UX; model benchmarking; prompt engineering; robotics hardware; autonomous-vehicle identity; and generic API-key or service-account guidance without a direct agentic-system application. + +The main period is 2020-08-15 through 2026-08-15. Earlier identity, authorization, workload-identity, and zero-trust standards may enter only when directly foundational to current AI-agent governance. + +Target roles are CISO, CIO, CTO, General Counsel/Chief Legal Officer, Board Director, and CEO, with risk, architecture, compliance, identity, and operations practitioners treated as supporting perspectives. Priority industries are financial services, technology and cloud, healthcare and life sciences, public sector and defense, critical infrastructure, and professional services. Priority regions are global, United States, European Union, United Kingdom, Canada, Singapore, Australia, India, and Japan. This batch searches English only because the current controlled vocabulary contains only `lang-en`. + +## Source eligibility + +Included source types are books; original video, podcasts, interviews, keynotes, panels, and conference talks; essays, newsletters, public letters, and testimony; academic and working papers; standards, policy documents, research reports, executive surveys, and methodologically transparent company research; and relevant OFF-owned sources. + +Excluded source types are private or confidential material, anonymous summaries, content farms, AI-generated summaries, scraped or unofficial transcripts, duplicate syndication, third-party uploads of uncertain rights, low-substance promotion, and sources with unresolved identity. + +Inclusion requires public or lawful research access; stable identity for work, author or speaker, publisher, and date; substantive relevance to agent identity governance; an original or official source where available; a distinct potential contribution; and a recordable rights and ownership basis. Search visibility alone is never sufficient. + +## Quality dimensions + +The review keeps these dimensions separate: primary-source status, bibliographic stability, source-identity stability, analysis access, methodological transparency, independence, relevance, evidence contribution, rights clarity, ownership clarity, recency, and diversity contribution. No composite authority score will be created. + +## Source priority + +1. Original standard, law, policy, paper, book, recording, report, or direct statement. +2. Original publisher or event host. +3. Official author, institution, regulator, standards body, or company research page. +4. Stable bibliographic or archival source. +5. Reliable independent source for contextual verification. +6. Secondary summaries only to locate originals. + +## Diversity objectives + +Seek meaningful coverage across executive roles, priority industries and regions, organization types, source types, established and emerging contributors, academic and practitioner perspectives, operator and investor views, supporting and challenging positions, and foundational and current work. Measure consulting, vendor, hyperscaler, and OFF-owned concentration separately. Weak sources will not be accepted to fill a category; unmet goals will be reported. + +## Planned search families + +1. Cross-topic discovery for AI-agent identity, authorization, delegation, lifecycle, accountability, and auditability. +2. Standards bodies and public frameworks: NIST, ISO/IEC, IETF, W3C, OpenID Foundation, OASIS, SPIFFE/CNCF, OWASP, Cloud Security Alliance, and related bodies. +3. Laws, regulators, and national policy from the priority regions. +4. Academic papers and working papers on identity, access control, delegation, multi-agent security, and governance. +5. Executive and practitioner sources from security, identity, cloud, legal, audit, risk, and board communities. +6. Books and stable bibliographic sources on agentic AI, machine identity, zero trust, and governance. +7. Primary media from official conference, university, standards-body, government, and publisher channels. +8. Industry searches for financial services, healthcare, public sector, defense, critical infrastructure, and technology/cloud. +9. Dissent and limitation searches: capability overstatement, identity theater, excessive autonomy, unaccountable delegation, privacy, surveillance, and concentration risk. +10. OFF-owned source search, with independence and concentration disclosed. + +Every meaningful query family, including searches yielding no acceptable candidate, will be logged with date, system, language, region, filters, reviewed count, generated candidate IDs, and notes. + +## Stopping rule and target + +The planned target is approximately 120 credible candidates within the prompt's 100–150 range. Discovery may stop between 100 and 150 once each major source family and priority role has been searched and two consecutive supplementary query families produce fewer than three new credible candidates each. Discovery may stop below 100 only if source saturation or a narrower-than-expected evidence base is documented. Traceability and quality take priority over volume. + +## Planned review method + +Each candidate receives separate metadata, access, rights, ownership, identity-stability, methodological-transparency, evidence, diversity, duplication, and decision fields. URLs and normalized titles are checked for duplicates. Original URLs are preferred over mirrors. Accepted candidates remain staging-only and do not imply publication approval. A named human must review selection judgments before any downstream source record enters production. + +## Expected limitations + +English-only discovery will underrepresent other languages. Terminology is unsettled and overlaps non-human, machine, and workload identity. Vendor and consulting sources are likely to be more visible than independent empirical work. Books may be metadata-only without lawful full-text access. Public evidence may underreport failures, internal control design, and board decisions. Newly published 2026 material may lack independent evaluation. + +## Protocol-change rule + +Criteria will not be altered after results are seen unless a material flaw is found. Any amendment must preserve the original rule, state the replacement, date the change, and explain the reason in the batch manifest. diff --git a/staging/batches/BATCH-2026-001/search-log.yml b/staging/batches/BATCH-2026-001/search-log.yml new file mode 100644 index 0000000..28a137d --- /dev/null +++ b/staging/batches/BATCH-2026-001/search-log.yml @@ -0,0 +1,53 @@ +batch_id: BATCH-2026-001 +executed_on: 2026-08-15 +searcher: OpenAI Codex; machine-assisted; human review pending +search_policy: Every meaningful family is logged, including low-yield and failed searches. Search snippets were locators only; candidate metadata uses original or official sources. +queries: + - {id: Q001, family: NIST agent identity, query: "site:nist.gov AI agent identity authorization governance", outcome: high-yield; official concept paper, initiative, RFI, and response analysis located} + - {id: Q002, family: OWASP, query: "site:owasp.org agentic AI identity privilege threat guide", outcome: high-yield; official threat taxonomy, multi-agent guide, Top 10, and governance report located} + - {id: Q003, family: Cloud Security Alliance, query: "site:cloudsecurityalliance.org AI agents non-human identity governance", outcome: high-yield; frameworks, surveys, and primary event material located} + - {id: Q004, family: IETF agent authorization, query: "site:ietf.org AI agent authentication authorization delegation draft", outcome: high-yield; four directly relevant Internet-Drafts located} + - {id: Q005, family: NIST general AI risk, query: "site:nist.gov AI RMF generative AI profile agent security", outcome: medium-yield; foundational risk documents located but identity specificity varies} + - {id: Q006, family: IETF workload identity, query: "site:datatracker.ietf.org WIMSE workload identity authorization", outcome: medium-yield; official meeting and draft materials located} + - {id: Q007, family: SPIFFE, query: "site:spiffe.io workload identity specification federation", outcome: high-yield; canonical specifications and open book located} + - {id: Q008, family: OpenID Foundation, query: "site:openid.net identity management agentic AI", outcome: high-yield; whitepaper, community page, slides, podcast, and workshop located} + - {id: Q009, family: European Union law, query: "site:europa.eu AI Act AI agents identity authorization", outcome: low-yield; authoritative AI Act context found, little identity-specific guidance} + - {id: Q010, family: United Kingdom policy, query: "site:gov.uk agentic AI identity authorization governance", outcome: medium-yield; consumer agent report located} + - {id: Q011, family: United States policy, query: "site:whitehouse.gov OR site:nist.gov AI agents security identity", outcome: medium-yield; NIST material strong, White House material screened as too general} + - {id: Q012, family: Singapore policy, query: "site:imda.gov.sg agentic AI governance identity", outcome: high-yield; national framework and sandbox insights located} + - {id: Q013, family: Australia policy, query: "site:gov.au agentic AI guidance identity access", outcome: high-yield; cross-agency guidance and policy addendum located} + - {id: Q014, family: Canada policy, query: "site:canada.ca agentic artificial intelligence guide identity", outcome: medium-yield; federal guide located} + - {id: Q015, family: Japan policy, query: "site:go.jp agentic AI governance identity English PDF", outcome: low-yield; one METI item held for language and relevance verification} + - {id: Q016, family: India policy, query: "site:gov.in agentic AI governance identity authorization", outcome: failed; no canonically identifiable, identity-specific English source met the protocol} + - {id: Q017, family: ENISA, query: "site:enisa.europa.eu autonomous agents frontier AI cybersecurity identity", outcome: low-yield; two contextual reports held rather than promoted} + - {id: Q018, family: academic identity, query: "site:arxiv.org AI agent identity authentication authorization", outcome: high-yield; direct identity and authorization preprints located} + - {id: Q019, family: academic governance, query: "site:arxiv.org agentic AI governance security architecture", outcome: high-yield; SAGA and runtime-governance work located} + - {id: Q020, family: ACM Digital Library, query: "site:dl.acm.org AI agent identity authorization", outcome: low-yield; discoverable items did not add a stronger canonical candidate than author preprints} + - {id: Q021, family: IEEE Xplore, query: "site:ieeexplore.ieee.org multi-agent authentication authorization AI", outcome: low-yield; results were paywalled, generic, or outside enterprise-agent scope} + - {id: Q022, family: agent security benchmarks, query: "LLM agent security benchmark prompt injection tools permissions", outcome: high-yield; AgentDojo, AgentSecBench, and related benchmarks located} + - {id: Q023, family: authorization benchmarks, query: "ASB comprehensive benchmark security LLM agents", outcome: medium-yield; canonical preprint located} + - {id: Q024, family: tool-use security, query: "ToolEmu ToolSandbox InjecAgent agent security", outcome: high-yield; primary papers located} + - {id: Q025, family: Google Cloud, query: "site:cloud.google.com AI agent identity IAM governance A2A", outcome: high-yield; documentation, architecture, and protocol sources located} + - {id: Q026, family: AWS, query: "site:aws.amazon.com agentic AI identity authorization AgentCore", outcome: high-yield; primary documentation and security guidance located} + - {id: Q027, family: Microsoft, query: "site:learn.microsoft.com Entra Agent ID agent identities", outcome: high-yield; five distinct documentation candidates located} + - {id: Q028, family: OpenAI, query: "site:openai.com agent governance safety permissions", outcome: medium-yield; governance and deployment-practice sources located} + - {id: Q029, family: Okta, query: "site:okta.com AI agent identity governance", outcome: medium-yield; one perspective accepted and one checklist held} + - {id: Q030, family: Ping Identity, query: "site:pingidentity.com agentic AI runtime identity", outcome: high-yield; specialist IAM perspectives located} + - {id: Q031, family: CyberArk, query: "site:cyberark.com AI agents identity security", outcome: medium-yield; one analytical perspective accepted and solution page held} + - {id: Q032, family: SailPoint, query: "site:sailpoint.com governing AI agent identity", outcome: high-yield; documentation, essay, and primary media located} + - {id: Q033, family: books, query: "books workload identity zero trust OAuth API security agentic AI governance", outcome: medium-yield; nine credible foundational or current books and one low-quality retail result screened} + - {id: Q034, family: primary media, query: "AI agent identity podcast conference talk webinar", outcome: medium-yield; seven primary media candidates located, two with unresolved episode-level metadata} + - {id: Q035, family: identity conferences, query: "OpenID Identiverse Authenticate RSA AI agent identity session", outcome: medium-yield; OpenID, Identiverse, CSA Summit, and SailPoint material located} + - {id: Q036, family: empirical surveys, query: "AI agent identity survey IAM registry credentials governance", outcome: high-yield; three CSA-sponsored surveys and one global F5 survey located} + - {id: Q037, family: executive and consulting research, query: "executive survey agentic AI trust least privilege identity", outcome: medium-yield; PwC item held pending method verification} + - {id: Q038, family: dissent and alternatives, query: "AI agents do not need new identity workload identity debate", outcome: low-yield; OpenID incremental-stack view, SPIFFE foundations, personhood credentials, and Identiverse identity-blur view retained as contrasting positions} +supplementary_searches: + - query: "official YouTube AI agent identity" + outcome: failed; generic channel and promotional results lacked stable episode identity, so none were used + - query: "India public agentic AI identity guidance English" + outcome: failed; no qualifying primary source found + - query: "healthcare AI agent identity governance primary source" + outcome: low-yield; general health-AI governance results lacked agent-identity specificity + - query: "critical infrastructure AI agent identity governance primary source" + outcome: low-yield; no sector-specific source improved on cross-sector standards and government guidance +stopping_rule_result: The pre-registered target of 120 was reached, every major family was searched, and the final sector-specific and country-specific supplementary searches produced fewer than three new credible candidates each. diff --git a/staging/batches/BATCH-2026-001/source-concentration.md b/staging/batches/BATCH-2026-001/source-concentration.md new file mode 100644 index 0000000..c65e3ac --- /dev/null +++ b/staging/batches/BATCH-2026-001/source-concentration.md @@ -0,0 +1,20 @@ +# Source concentration — BATCH-2026-001 + +## Measured concentration + +The full slate contains 120 candidates from 45 publisher labels. The largest labels are arXiv (19), NIST (8), SPIFFE Project (6), OWASP GenAI Security Project (6), IETF (5), Cloud Security Alliance (5), Microsoft (5), and O’Reilly Media (5). + +Within the 91 accepted candidates, the leading labels are arXiv (16; 17.6%), NIST (6; 6.6%), IETF (5; 5.5%), SPIFFE Project (5; 5.5%), Microsoft (5; 5.5%), and four each from OWASP GenAI, Cloud Security Alliance, Google Cloud, Amazon Web Services, and O’Reilly Media (4.4% each). No publisher exceeds 20% of accepted candidates, but publisher-label dispersion understates ecosystem concentration. + +## Structural concentration risks + +- Preprint concentration: 17 accepted candidates are arXiv-hosted or arXiv-linked. Hosting does not imply peer review, and several 2026 papers are held. +- Vendor concentration: Microsoft, Google Cloud, AWS, OpenAI, Ping Identity, Okta, SailPoint, CyberArk, and F5 collectively shape a large part of the implementation record. These sources are valuable for observable product semantics, not independent proof that a vendor’s preferred architecture is generally optimal. +- CSA sponsorship: the strongest empirical agent-identity surveys are CSA-hosted but vendor-commissioned. Sponsor identity and methods must remain visible in any later use. +- US and English visibility: NIST, US-based vendors, arXiv, and English-language standards bodies dominate discovery. Official Singaporean, Australian, Canadian, UK, EU, and Japanese candidates reduce but do not remove this imbalance. +- Book concentration: five of ten screened books are O’Reilly titles. This is a discoverability and catalog-access effect, not a quality ranking. +- OFF concentration: zero candidates are OFF-owned or OFF-affiliated. That avoids self-citation concentration but leaves the batch without original OFF interviews or event evidence. + +## Controls for the next stage + +Human selection should cap any single vendor family, retain sponsor disclosures, distinguish standards from product documentation, and require at least one independent or public-authority source alongside every vendor-derived proposition. Geographic tags should not be treated as author or sample diversity unless verified. diff --git a/staging/batches/BATCH-2026-001/validation-results.md b/staging/batches/BATCH-2026-001/validation-results.md new file mode 100644 index 0000000..4a561ba --- /dev/null +++ b/staging/batches/BATCH-2026-001/validation-results.md @@ -0,0 +1,34 @@ +# Validation results — BATCH-2026-001 + +Completed 2026-08-15. Candidate acceptance is not source or publication approval. + +## Passed + +- Canonical research-protocol schema and provenance: one protocol record. +- Batch-local candidate schema: 120 of 120 candidates. +- Decision partition: 91 accepted, 19 held, 10 rejected. +- Candidate identity and URL uniqueness. +- Source-identity completeness for accepted candidates. +- Rights/access and ownership/OFF-relationship fields for every candidate. +- Duplicate review: five alternate-rendition groups match five duplicate rejects. +- Search traceability: every candidate references logged query families; 38 main families and four supplementary low-yield or failed searches are documented. +- Coverage: all six pre-registered executive roles occur in the accepted set. +- Concentration: the largest accepted publisher label is arXiv at 17.6%, below the 20% failure threshold; structural vendor and preprint concentration remains disclosed. +- Staging isolation: no candidate IDs appear in production content, documentation, or exports. +- Batch size: 120, within the pre-registered 100–150 range. +- Repository gates: attribution, statements, propositions, book editions, locators, rights/privacy, review status, publication, content, duplicates, concentration, and coverage. +- Static checks: TypeScript and targeted ESLint. +- Tests: 24 passed across four test files. +- Whitespace: `git diff --check` passed. + +## Warnings retained as findings + +- India has no accepted candidate. +- Japan has no accepted candidate; one METI source remains held. +- All candidates are English-language because `lang-en` is the only active language vocabulary value. + +These warnings are not validation failures. The protocol explicitly prioritizes quality over quota filling, so gaps remain visible for a later batch. + +## Local runner note + +The local seatbelt blocks the IPC pipe used by the `tsx` command wrapper. Equivalent commands were run with `node --import tsx`, which exercises the same TypeScript entry points without the blocked IPC server. Hosted CI should run the normal package scripts.