17
DraftS05-CON-010v0.1Source imported
Section 86 of 102
85. Agent Identity, Authentication and Access Control
Stable section ID: S05-CON-010-SECTION-86 · 24 content blocks
Every participating agent shall possess a verifiable identity distinct from its provider, user, device, and current session.
Identity records may include:
- Agent identifier.
- Provider.
- Agent type.
- Manifest.
- Model and software version.
- Deployment location.
- Building assignment.
- Credential status.
- Qualification status.
- Active permissions.
- Revocation status.
- Authentication shall occur before access to protected System05 information or functions.
Access control shall follow:
- Least privilege.
- Deny by default.
- Role or attribute-based authorization.
- Context-sensitive evaluation.
- Time limitation.
- Credential rotation.
- Revocation.
- Auditability.
Shared or anonymous privileged agent accounts should not be used. Actions shall remain attributable to the responsible agent and initiating authority.