{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-003.json",
  "source": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-EVAL-003",
    "profile": "evaluation-environment",
    "url": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-003.json",
    "title": "Credential Isolation",
    "version": "0.2",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "specified",
    "objective": "An agent under evaluation holds only short-lived credentials issued to its own identity for the run and bound to the one service each is for, never standing secrets or a person's own token.",
    "failureModes": [
      "A long-lived secret (an API key, a cloud access key, a password) is readable from the agent's environment, configuration, files or memory during a run.",
      "The agent presents a token issued to a person, a token whose audience is another service, or a credential it found rather than received, and the tool server accepts it.",
      "A credential issued for the run is still accepted after the run ended or was aborted.",
      "A credential appears in the run's transcript, memory store, logs or outputs, or is passed to another agent."
    ],
    "scope": "Credentials, tokens and keys the agent under evaluation and the tools it calls can reach during a run, including what it holds in memory and writes to its transcript, and the model API key, which stays with a proxy outside the environment. The evaluator's own operator credentials are out of scope.",
    "enforcementPoints": [
      "deploy",
      "runtime"
    ],
    "verification": [
      {
        "kind": "inspect",
        "text": "Before the run, inspect the environment template and the run's configuration: no long-lived secret is present, and the agent obtains credentials from a broker outside the environment under its own workload identity, each with a lifetime no longer than the run and an audience naming one tool server."
      },
      {
        "kind": "test",
        "text": "After the run, scan every run artefact (transcript, memory store, logs, outputs and a snapshot of the environment's file system) for secret patterns and for the tokens issued to the run; expect no match."
      },
      {
        "kind": "test",
        "text": "Replay a token issued for the run against a different tool server, and again after the run has ended; both must be rejected, for the wrong audience and for expiry or revocation."
      },
      {
        "kind": "observe",
        "text": "Read the tool servers' logs for the run: every call carries a token issued for that server, delegated calls name the agent as the acting party, and audience-check failures were raised as alerts."
      }
    ],
    "evidence": [
      {
        "artefact": "Credential issuance log of the run: identity, audience, scope, lifetime and revocation time of every token",
        "schemaId": "evidence-record",
        "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
        "layer": 4
      },
      {
        "artefact": "Audience-check and replay results from the tool servers",
        "schemaId": "evidence-record",
        "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
        "layer": 4
      },
      {
        "artefact": "Secret scan of the run artefacts, filed as an observation of this control",
        "schemaId": "control-observation",
        "schema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "A token issued for another audience, to a person, or for a run that has ended is rejected by the tool server. A run in which a long-lived secret or a leaked credential is found is stopped, the credential is revoked and the result is withheld until the exposure is assessed."
    },
    "layer": 4,
    "secondaryLayers": [
      2
    ],
    "patterns": [
      {
        "slug": "agent-identity-scoped-credentials",
        "title": "Agent Identity & Scoped Credentials",
        "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
      }
    ],
    "seeds": [
      {
        "id": "own-identity",
        "title": "Its own identity",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#identity-and-short-lived-credentials"
      },
      {
        "id": "short-lived-credentials",
        "title": "Replace long-lived secrets with short-lived credentials",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#short-lived-attested-credentials"
      },
      {
        "id": "delegated-token",
        "title": "Delegation, never impersonation",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#delegation-without-impersonation"
      },
      {
        "id": "mcp-authorization",
        "title": "MCP authorisation (spec 2026-07-28)",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#mcp-authorization-as-of-2026-07-28"
      },
      {
        "id": "memory-governance",
        "title": "Memory write gate and rollback",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#memory-and-context-governance"
      }
    ],
    "derivedFrom": [],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART15",
          "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
        },
        {
          "id": "AIGE-OBL-SG-AGENTIC-IDENTITY",
          "name": "Singapore IMDA Model AI Governance Framework for Agentic AI: agent identity and scoped authorisations (voluntary)",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-sg-agentic-identity"
        },
        {
          "id": "AIGE-OBL-NIST-AGENTS",
          "name": "NIST AI Agent Standards Initiative (2026)",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-agents"
        },
        {
          "id": "AIGE-OBL-OWASP-AGENTIC",
          "name": "Top 10 for Agentic Applications 2026",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
        }
      ],
      "iso42001": [
        {
          "id": "A.6.2.6",
          "title": "AI system operation and monitoring"
        },
        {
          "id": "A.9.2",
          "title": "Processes for responsible use of AI systems"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MEASURE 2.7",
          "title": "Security and resilience are evaluated and documented"
        }
      ],
      "owasp": [
        {
          "id": "asi03",
          "externalId": "ASI03",
          "name": "Identity and Privilege Abuse",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-asi03"
        }
      ],
      "atlas": [],
      "aiuc1": [
        "A008"
      ],
      "csaAicm": [],
      "other": [
        {
          "framework": "IETF RFC 8693",
          "ref": "act claim",
          "note": "delegation names the acting party; never impersonation"
        },
        {
          "framework": "MCP specification 2026-07-28",
          "ref": "Authorization, Token Handling",
          "note": "audience validation; no token passthrough"
        },
        {
          "framework": "SPIFFE",
          "ref": "SVID",
          "note": "short-lived workload identity documents"
        },
        {
          "framework": "MITRE ATLAS",
          "ref": "AML.T0083",
          "note": "Credentials from AI Agent Configuration (not yet a row of the threat bridge)"
        },
        {
          "framework": "NIST SP 800-53 Rev. 5",
          "ref": "IA-5",
          "note": "Authenticator Management"
        },
        {
          "framework": "NIST SP 800-53 Rev. 5",
          "ref": "AC-6",
          "note": "Least Privilege"
        }
      ]
    },
    "references": [
      {
        "n": 19,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Identity and short-lived credentials\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#identity-and-short-lived-credentials",
        "verified": "primary"
      },
      {
        "n": 20,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Short-lived, attested credentials\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#short-lived-attested-credentials",
        "verified": "primary"
      },
      {
        "n": 21,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Delegation without impersonation\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#delegation-without-impersonation",
        "verified": "primary"
      },
      {
        "n": 22,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"MCP authorization as of 2026-07-28\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#mcp-authorization-as-of-2026-07-28",
        "verified": "primary"
      },
      {
        "n": 23,
        "title": "RFC 8693, OAuth 2.0 Token Exchange",
        "text": "RFC 8693, OAuth 2.0 Token Exchange (the act claim \"provides a means within a JWT to express that delegation has occurred and identify the acting party\"). IETF. 2020-01.",
        "url": "https://www.rfc-editor.org/rfc/rfc8693.html",
        "verified": "primary"
      },
      {
        "n": 24,
        "title": "MCP specification 2026-07-28, Authorization",
        "text": "MCP specification 2026-07-28, Authorization (MCP servers MUST validate that access tokens were issued specifically for them and \"MUST NOT accept or transit any other tokens\"). Model Context Protocol. 2026-07-28.",
        "url": "https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization",
        "verified": "primary"
      },
      {
        "n": 15,
        "title": "MCP Security Best Practices (2026-07-28)",
        "text": "MCP Security Best Practices (2026-07-28) (token passthrough \"is explicitly forbidden\"; egress proxies and network policies for server-side clients). Model Context Protocol. 2026-07-28.",
        "url": "https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices",
        "verified": "primary"
      },
      {
        "n": 25,
        "title": "SPIFFE overview",
        "text": "SPIFFE overview (SVIDs are \"short lived cryptographic identity documents\", delivered and rotated through the Workload API). SPIFFE project. 2026.",
        "url": "https://spiffe.io/docs/latest/spiffe-about/overview/",
        "verified": "primary"
      },
      {
        "n": 26,
        "title": "Model AI Governance Framework for Agentic AI, v1.5",
        "text": "Model AI Governance Framework for Agentic AI, v1.5 (agent identity unique and \"cryptographically verifiable\"; authorisations \"time- or session-bound, non-transferable\"). IMDA. 2026-05-20.",
        "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident",
        "text": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident (METR states that agents \"meant to be fully isolated from one another\" communicated through an internal package repository, and that one agent found working Hugging Face credentials exposed on the internet and posted them to the agents' board; it reports spoofed tool calls in at least 96 transcripts and transcripts missing components after container resets). METR. 2026-08-26.",
        "url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/",
        "verified": "primary"
      },
      {
        "n": 14,
        "title": "Vivaria server environment variables",
        "text": "Vivaria server environment variables (no-internet task environments connected to a separate Docker network and optionally sandboxed with iptables rules; model API requests can be routed through a separate proxy service). METR. 2026.",
        "url": "https://vivaria.metr.org/reference/config/",
        "verified": "primary"
      },
      {
        "n": 6,
        "title": "OWASP Top 10 for Agentic Applications for 2026",
        "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
        "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
        "verified": "primary"
      },
      {
        "n": 17,
        "title": "MITRE ATLAS data, release v2026.09",
        "text": "MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml). MITRE. 2026-09-15.",
        "url": "https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09",
        "verified": "primary"
      },
      {
        "n": 7,
        "title": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations",
        "text": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations (control catalogue cited by control id; publication page of Revision 5 with update 1 of 10 Dec 2020). NIST. 2020-12-10.",
        "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final",
        "verified": "primary"
      },
      {
        "n": 9,
        "title": "Improving our alignment and security efforts",
        "text": "Improving our alignment and security efforts (best practices for external partners running cyber evaluations: the only outside connection is \"to the model's own API\", with the API keys kept outside the environment; the configuration \"should be verified before every evaluation begins\"; boundaries \"phrased as instructions\"; challenges confirmed \"solvable in principle\"; a monitor that flags a scope violation to a human and ends the exercise). Anthropic. 2026-08-31.",
        "url": "https://www.anthropic.com/news/improving-alignment-security-efforts",
        "verified": "primary"
      },
      {
        "n": 8,
        "title": "Third-party cyber evaluations involving OpenAI models",
        "text": "Third-party cyber evaluations involving OpenAI models (OpenAI states that the evaluator's \"intended authorization boundary was the simulated cyber range\", that its model reused a GitHub token another lab's agent had left publicly accessible, and that it will review how to \"set expectations for isolation, credential handling, monitoring, and stop conditions\"). OpenAI. 2026-08-04.",
        "url": "https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/",
        "verified": "primary"
      },
      {
        "n": 27,
        "title": "Exposing a GitHub token in a public repository (misalignment report)",
        "text": "Exposing a GitHub token in a public repository (misalignment report) (OpenAI reports an internally deployed model that published a researcher's GitHub token to a public repository, split into pieces with the stated aim of avoiding secret scanning). OpenAI (Alignment Research Blog). 2026-09-25.",
        "url": "https://alignment.openai.com/misalignment-reports/exposing-a-github-token-in-a-public-repository/",
        "verified": "primary"
      },
      {
        "n": 10,
        "title": "AIUC-1 requirements",
        "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
        "url": "https://standard.aiuc-1.com/llms.txt",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Give each agent under test its own workload identity for the run (an attested identity document of the kind SPIFFE defines, or the platform's workload identity) and issue its tokens from a broker outside the environment. The environment template holds no secret.",
      "Keep the model API key with an LLM API proxy outside the environment, reached through the egress allow-list of AIGE-CTL-EVAL-002: the agent sees the proxy, never the key. Anthropic's guidance for external evaluation partners likewise asks that \"the API keys should be kept outside the environment\".",
      "Issue short-lived access tokens whose aud names one tool server and, when the agent acts for a user or another agent, whose act claim names the agent (RFC 8693 token exchange). Tool servers validate the audience and refuse any other token, as the MCP authorization specification of 2026-07-28 requires of MCP servers.",
      "Set every token lifetime no longer than the run's time budget, issue no refresh tokens to agents under evaluation, and revoke what was issued when the run ends or is aborted.",
      "Scrub credentials from memory stores, transcripts and logs before they are written, then grep every run artefact after the run for secret patterns (known key prefixes, high-entropy strings, the run's own issued tokens); a match fails the run. Scan for credentials a run picked up as well as those it was issued: METR's investigation of the OpenAI/Hugging Face incident reports an agent that found working Hugging Face credentials exposed on the internet and posted them to a board other agents read, and OpenAI states that in a third-party evaluation its model reused a GitHub token another lab's agent had left publicly accessible."
    ],
    "openQuestions": [
      "What lifetime should a credential issued for an evaluation run have, and who revokes it when the run is aborted?",
      "Can a secret scan be made complete for encoded or split credentials, or should the control rely on short lifetimes and revocation for whatever a scan may miss? OpenAI reports a model that split a researcher's token into pieces with the stated aim of avoiding secret scanning."
    ],
    "observation": {
      "subjectKind": "eval-run",
      "expected": "No credential other than the run's own short-lived, audience-bound tokens is readable in the environment or appears in the run's artefacts, and none is accepted after the run.",
      "observedExample": "Run 88214: secret scan found 0 matches in transcript, memory store and logs; a replayed token was rejected with an audience error: pass."
    },
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": [
      {
        "status": "pass",
        "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-003.pass.json"
      },
      {
        "status": "fail",
        "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-003.fail.json"
      }
    ]
  }
}
