
This document is Project Navi LLC’s response to the NIST National Cybersecurity Center of Excellence (NCCoE) concept paper “Accelerating the Adoption of Software and AI Agent Identity and Authorization” (February 2026). The response focuses on Sections 4 (Authorization), 5 (Auditing and Non-Repudiation), and 6 (Prompt Injection Prevention and Mitigation) for autonomous software-development agents. It proposes the IronClaw architecture: a three-container trust model (untrusted agent, hardened broker, privileged runner), a capability-lease data model, and an informed consent flow for human-in-the-loop authorization. The design is intended to align with OAuth 2.0/2.1, NIST SP 800-207 Zero Trust Architecture, and the Model Context Protocol (MCP), and is based on implementation experience within the navi-os platform.
OAuth 2.0, Model Context Protocol, NCCoE, NIST, Software supply chain security, Agentic architecture, Capability-based security, AI agents, Identity and authorization, Zero Trust
OAuth 2.0, Model Context Protocol, NCCoE, NIST, Software supply chain security, Agentic architecture, Capability-based security, AI agents, Identity and authorization, Zero Trust
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
