Identify (ID) · Authorization
Authorization at the operator declared layer
·
What agents exist, what they touch, what threats they face?
What this cell does
Operator records authorized scope in registry, linked to RBAC manifest paths and IAM policy ARNs.
Cell notes
Inventory, Authorization / Operator-declared
What this cell records. The operator's intent for what each agent is authorized to do, linked back to source manifests.
Fields
- -
rbac_role_ref, name of the source-of-truth Role committed undermanifests/rbac/. - -
iam_policy_arns[] - -
mcp_servers_allowlist_ref, file path to the canonicalmcp-allowlist.json. - -
last_audited_at, when the operator last verified runtime matches intent.
Cross-layer
Should equal the agent charter's authorized_scope block. Should match discovered effective permissions. Either disagreement = audit.
Citation
NIST CSF 2.0 ID.AM-02, ID.AM-08. NIST AI RMF MAP 1.5, MAP 4.1.
Crosswalk
| NIST CSF 2 0 | ID.AM-02, ID.AM-08 |
|---|---|
| NIST AI RMF | MAP 1.5, MAP 4.1 |
| CSA MAESTRO | Layer 7 |
Cite this cell:
https://agenticcovenants.com/identify/authorization/operator-declared/