{"entity_type":"book-edition","book_edition_id":"book-edition-BATCH-2026-002-001","book_work_id":"book-work-BATCH-2026-002-001","edition_title":"Solving the Bottom Turtle — First Edition","publisher":"SPIFFE Project","imprint":null,"publication_date":"2020-11-17","publication_country":"United States","language":"lang-en","translation_of":null,"translator":null,"format":"PDF","ISBN-10":"0578777371","ISBN-13":"9780578777375","audiobook_identifier":null,"audiobook_narrator":null,"edition_statement":"First edition","pagination":194,"electronic_location_system":"PDF page number matching the printed page number; cover is unnumbered","source_used_for_analysis":true,"access_basis":"Official complete first-edition PDF, unencrypted, CC BY 4.0","access_date":"2026-08-15","metadata_sources":["https://spiffe.io/book/","https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf","https://www.booksprints.net/book/hpe-spiffe-spire/"],"full_text_available_for_research":true,"publication_permission":"CC BY 4.0; attribution required","verification_status":"machine_verified_human_approved","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/book/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Edition-level publisher or catalogue metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"CC BY 4.0"},{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"PDF pages 1–194","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Exact edition read completely"}],"revision_history":[{"changed_at":"2026-08-15T00:00:00Z","changed_by":"OEII analysis agent","summary":"Verified pagination, date, locator system, content hash, and complete-edition access.","batch_id":"BATCH-2026-003"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"book-edition","book_edition_id":"book-edition-BATCH-2026-002-002","book_work_id":"book-work-BATCH-2026-002-002","edition_title":"Zero Trust Networks, 2nd Edition","publisher":"O’Reilly Media, Inc.","imprint":null,"publication_date":null,"publication_country":"United States","language":"lang-en","translation_of":null,"translator":null,"format":"O’Reilly Online Learning","ISBN-10":"149209658X","ISBN-13":"9781492096580","audiobook_identifier":null,"audiobook_narrator":null,"edition_statement":"Second edition","pagination":334,"electronic_location_system":"HTML chapters and stable page headings","source_used_for_analysis":true,"access_basis":"publisher_metadata_and_authorized_preview","access_date":"2026-08-15","metadata_sources":["https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/titlepage01.html"],"full_text_available_for_research":false,"publication_permission":"Metadata, link, and brief necessary quotation only","verification_status":"machine_verified_human_approved","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/titlepage01.html","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Edition-level publisher or catalogue metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Metadata, link, and brief necessary quotation only"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"book-edition","book_edition_id":"book-edition-BATCH-2026-002-003","book_work_id":"book-work-BATCH-2026-002-002","edition_title":"Zero Trust Networks — Audiobook","publisher":"Ascent Audio","imprint":null,"publication_date":null,"publication_country":"United States","language":"lang-en","translation_of":null,"translator":null,"format":"audiobook","ISBN-10":null,"ISBN-13":null,"audiobook_identifier":"9781663735591","audiobook_narrator":"Mike Chamberlain","edition_statement":"Second-edition audiobook","pagination":null,"electronic_location_system":"audio chapters and timestamps","source_used_for_analysis":false,"access_basis":"publisher_metadata_only","access_date":"2026-08-15","metadata_sources":["https://www.oreilly.com/library/view/zero-trust-networks/9781663735591/"],"full_text_available_for_research":false,"publication_permission":"Metadata and link only","verification_status":"machine_verified_human_approved","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/zero-trust-networks/9781663735591/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Edition-level publisher or catalogue metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Metadata and link only"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"book-edition","book_edition_id":"book-edition-BATCH-2026-002-005","book_work_id":"book-work-BATCH-2026-002-003","edition_title":"OAuth 2 in Action","publisher":"Manning Publications","imprint":null,"publication_date":null,"publication_country":"United States","language":"lang-en","translation_of":null,"translator":null,"format":"print with bundled ebook","ISBN-10":"161729327X","ISBN-13":"9781617293276","audiobook_identifier":null,"audiobook_narrator":null,"edition_statement":"First edition","pagination":360,"electronic_location_system":"print pages; ebook chapters","source_used_for_analysis":true,"access_basis":"publisher_metadata_and_authorized_preview","access_date":"2026-08-15","metadata_sources":["https://www.manning.com/books/oauth-2-in-action","https://www.manning.com/preview/oauth-2-in-action/chapter-1"],"full_text_available_for_research":false,"publication_permission":"Metadata, link, and authorized-preview use only","verification_status":"machine_verified_human_approved","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.manning.com/books/oauth-2-in-action","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Edition-level publisher or catalogue metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Metadata, link, and authorized-preview use only"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"book-edition","book_edition_id":"book-edition-BATCH-2026-002-006","book_work_id":"book-work-BATCH-2026-002-004","edition_title":"API Security in Action","publisher":"Manning Publications","imprint":null,"publication_date":null,"publication_country":"United States","language":"lang-en","translation_of":null,"translator":null,"format":"print with bundled ebook","ISBN-10":"1617296023","ISBN-13":"9781617296024","audiobook_identifier":null,"audiobook_narrator":null,"edition_statement":"First edition","pagination":576,"electronic_location_system":"print pages; ebook chapters","source_used_for_analysis":true,"access_basis":"publisher_metadata_and_authorized_preview","access_date":"2026-08-15","metadata_sources":["https://www.manning.com/books/api-security-in-action","https://livebook.manning.com/book/api-security-in-action/contents"],"full_text_available_for_research":false,"publication_permission":"Metadata, link, and authorized-preview use only","verification_status":"machine_verified_human_approved","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.manning.com/books/api-security-in-action","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Edition-level publisher or catalogue metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Metadata, link, and authorized-preview use only"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"book-edition","book_edition_id":"book-edition-BATCH-2026-002-007","book_work_id":"book-work-BATCH-2026-002-005","edition_title":"Building Secure and Reliable Systems — O’Reilly Online Learning","publisher":"O’Reilly Media, Inc.","imprint":null,"publication_date":"2020-04-08","publication_country":"United States","language":"lang-en","translation_of":null,"translator":null,"format":"online edition","ISBN-10":"1492083119","ISBN-13":"9781492083115","audiobook_identifier":null,"audiobook_narrator":null,"edition_statement":"First edition","pagination":555,"electronic_location_system":"Official HTML chapter files with stable heading anchors; human-readable locator is chapter plus section heading","source_used_for_analysis":true,"access_basis":"Official complete first-edition HTML hosted by Google; all 35 content files traversed","access_date":"2026-08-15","metadata_sources":["https://www.oreilly.com/library/view/building-secure-and/9781492083115/","https://google.github.io/building-secure-and-reliable-systems/"],"full_text_available_for_research":true,"publication_permission":"Research access verified; metadata, canonical links, original paraphrase, and brief necessary quotation only","verification_status":"machine_verified_human_approved","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Edition-level publisher or catalogue metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Complete official text accessible for research; no open republication license identified"},{"source_url":"https://google.github.io/building-secure-and-reliable-systems/","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"35 official HTML files with chapter/section anchors","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Manifest hash ae702b4e64364217f179317b4a46de6a5e7c51045a79efa67522245d76667e16; exact edition read completely"}],"revision_history":[{"changed_at":"2026-08-15T00:00:00Z","changed_by":"OEII analysis agent","summary":"Verified date, stable locator system, complete content manifest, and normalized text hash.","batch_id":"BATCH-2026-003"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"book-edition","book_edition_id":"book-edition-BATCH-2026-002-008","book_work_id":"book-work-BATCH-2026-002-005","edition_title":"Building Secure and Reliable Systems — Print","publisher":"O’Reilly Media, Inc.","imprint":null,"publication_date":null,"publication_country":"United States","language":"lang-en","translation_of":null,"translator":null,"format":"print","ISBN-10":"1492083127","ISBN-13":"9781492083122","audiobook_identifier":null,"audiobook_narrator":null,"edition_statement":"First edition","pagination":557,"electronic_location_system":"print pages","source_used_for_analysis":false,"access_basis":"publisher_and_library_metadata","access_date":"2026-08-15","metadata_sources":["https://www.oreilly.com/library/view/building-secure-and/9781492083115/","https://lccn.loc.gov/2021277046"],"full_text_available_for_research":false,"publication_permission":"Metadata and link only","verification_status":"machine_verified_human_approved","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Edition-level publisher or catalogue metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Metadata and link only"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"book-edition","book_edition_id":"book-edition-BATCH-2026-002-009","book_work_id":"book-work-BATCH-2026-002-005","edition_title":"Building Secure and Reliable Systems — Reflowable eText","publisher":"O’Reilly Media, Inc.","imprint":null,"publication_date":null,"publication_country":"United States","language":"lang-en","translation_of":null,"translator":null,"format":"reflowable ebook","ISBN-10":"1492083070","ISBN-13":"9781492083078","audiobook_identifier":null,"audiobook_narrator":null,"edition_statement":"First edition digital manifestation","pagination":null,"electronic_location_system":"reflowable electronic locations","source_used_for_analysis":false,"access_basis":"supplementary_bookseller_metadata","access_date":"2026-08-15","metadata_sources":["https://www.vitalsource.com/products/building-secure-and-reliable-systems-heather-adkins-betsy-beyer-v9781492083078"],"full_text_available_for_research":false,"publication_permission":"Metadata and link only; publisher confirmation desirable","verification_status":"machine_verified_human_approved","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.vitalsource.com/products/building-secure-and-reliable-systems-heather-adkins-betsy-beyer-v9781492083078","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Edition-level publisher or catalogue metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Metadata and link only; publisher confirmation desirable"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"book-edition","book_edition_id":"book-edition-BATCH-2026-002-010","book_work_id":"book-work-BATCH-2026-002-006","edition_title":"Identity in Modern Applications","publisher":"O’Reilly Media, Inc.","imprint":null,"publication_date":null,"publication_country":"United States","language":"lang-en","translation_of":null,"translator":null,"format":"online short report","ISBN-10":"1098107780","ISBN-13":"9781098107789","audiobook_identifier":null,"audiobook_narrator":null,"edition_statement":"First edition","pagination":35,"electronic_location_system":"HTML sections","source_used_for_analysis":true,"access_basis":"publisher_metadata_and_authorized_preview","access_date":"2026-08-15","metadata_sources":["https://www.oreilly.com/library/view/identity-in-modern/9781098107789/"],"full_text_available_for_research":false,"publication_permission":"Metadata, link, and authorized-preview use only","verification_status":"machine_verified_human_approved","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/identity-in-modern/9781098107789/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Edition-level publisher or catalogue metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Metadata, link, and authorized-preview use only"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"book-edition","book_edition_id":"book-edition-BATCH-2026-002-011","book_work_id":"book-work-BATCH-2026-002-007","edition_title":"Solving Identity Management in Modern Applications — First Edition eBook","publisher":"Apress","imprint":null,"publication_date":"2019-12-18","publication_country":"United States","language":"lang-en","translation_of":null,"translator":null,"format":"ebook","ISBN-10":"1484250958","ISBN-13":"9781484250952","audiobook_identifier":null,"audiobook_narrator":null,"edition_statement":"First edition","pagination":311,"electronic_location_system":"PDF pages and chapter page ranges","source_used_for_analysis":true,"access_basis":"official_publisher_metadata_and_toc","access_date":"2026-08-15","metadata_sources":["https://link.springer.com/book/10.1007/978-1-4842-5095-2"],"full_text_available_for_research":false,"publication_permission":"Metadata and table-of-contents use only","verification_status":"machine_verified_human_approved","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://link.springer.com/book/10.1007/978-1-4842-5095-2","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Edition-level publisher or catalogue metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Metadata and table-of-contents use only"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"book-edition","book_edition_id":"book-edition-BATCH-2026-002-014","book_work_id":"book-work-BATCH-2026-002-009","edition_title":"Identity-Native Infrastructure Access Management","publisher":"O’Reilly Media, Inc.","imprint":null,"publication_date":null,"publication_country":"United States","language":"lang-en","translation_of":null,"translator":null,"format":"O’Reilly Online Learning","ISBN-10":"1098131886","ISBN-13":"9781098131883","audiobook_identifier":null,"audiobook_narrator":null,"edition_statement":"First edition","pagination":154,"electronic_location_system":"HTML chapters and headings","source_used_for_analysis":true,"access_basis":"publisher_metadata_and_authorized_preview","access_date":"2026-08-15","metadata_sources":["https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/"],"full_text_available_for_research":false,"publication_permission":"Metadata, link, and authorized-preview use only","verification_status":"machine_verified_human_approved","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Edition-level publisher or catalogue metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Metadata, link, and authorized-preview use only"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"book-work","book_work_id":"book-work-BATCH-2026-002-001","title":"Solving the Bottom Turtle","subtitle":"A SPIFFE Way to Establish Trust in Your Infrastructure via Universal Identity","alternate_titles":["Solving the Bottom Turtle — a SPIFFE Way to Establish Trust in Your Infrastructure via Universal Identity"],"authors":["person-BATCH-2026-002-001","person-BATCH-2026-002-002","person-BATCH-2026-002-003","person-BATCH-2026-002-004","person-BATCH-2026-002-005","person-BATCH-2026-002-006","person-BATCH-2026-002-007","person-BATCH-2026-002-008","person-BATCH-2026-002-009","person-BATCH-2026-002-010","person-BATCH-2026-002-011","person-BATCH-2026-002-012"],"contributors":[],"original_language":"lang-en","first_publication_date":"2020-11-17","work_type":"collaborative_technical_book","topics":["governed-agent-identities","identity-and-access-management"],"central_subjects":["SPIFFE and SPIRE","workload identity","universal service identity","infrastructure trust"],"inclusion_rationale":"Officially published, openly licensed treatment of workload identity and trust establishment that can inform—but must not be assumed identical to—AI-agent identity design.","analysis_depth":"deeply_analyzed","analysis_basis":"Complete first-edition PDF reviewed page by page from the official SPIFFE Project distribution","central_thesis":"Modern distributed systems require automatically issued, short-lived workload identities rooted in attestation rather than network location or manually distributed secrets; SPIFFE defines the identity documents and SPIRE supplies the attestation and issuance machinery.","principal_propositions":["proposition-candidate-BATCH-2026-003-001","proposition-candidate-BATCH-2026-003-002","proposition-candidate-BATCH-2026-003-003","proposition-candidate-BATCH-2026-003-004","proposition-candidate-BATCH-2026-003-005","proposition-candidate-BATCH-2026-003-006","proposition-candidate-BATCH-2026-003-007","proposition-candidate-BATCH-2026-003-008"],"frameworks":[{"name":"Bottom-turtle trust bootstrap","description":"Begin trust from locally verifiable platform evidence rather than a pre-positioned long-lived credential."},{"name":"Node and workload attestation","description":"Separate validation of the hosting node from validation of the workload process before issuing an identity."},{"name":"Trust-domain architecture","description":"Bound issuance authority, naming, federation, and compromise impact within explicit administrative domains."},{"name":"Staged adoption","description":"Move from bridges and proxies toward native workload API integration while preserving rollback paths."}],"evidence_base":"Technical architecture, threat-model reasoning, operational experience, historical examples, and five self-reported organizational case stories. It is a practitioner/project publication, not a controlled comparative study.","executive_role_implications":{"CISO":"Own trust-domain policy, attestation assurance, authorization separation, compromise assumptions, and auditability.","CIO":"Fund the identity control plane, migration sequencing, platform coverage, and operating model.","CTO":"Set identity semantics, integration patterns, availability boundaries, and architectural constraints.","General Counsel":"Review credential and access-log retention, privacy, evidence custody, and licensing obligations.","CEO":"Align incentives and sponsorship for cross-functional migration rather than treating identity as a security-only project.","Board Director":"Oversee concentration risk in identity infrastructure and the residual consequences of control-plane compromise."},"strongest_documented_arguments":["Location-derived identity becomes brittle as workloads are scheduled dynamically across heterogeneous infrastructure.","Short-lived credentials and automated attestation reduce dependence on manually distributed, long-lived bootstrap secrets.","Authentication and authorization are distinct; a verified identity does not itself confer permission."],"limitations":["The case evidence is self-reported and does not isolate SPIFFE or SPIRE as the cause of the reported outcomes.","The book is written by project participants and sometimes moves from design argument to ecosystem advocacy.","Its workload identity model does not by itself encode an AI agent's sponsor, delegation chain, task purpose, model, session, or decision provenance.","The 2020 edition predates later token formats, wider platform support, current AI-agent systems, and subsequent identity standards work."],"counterpoints":["NIST zero-trust guidance requires dynamic, per-request policy and contextual telemetry in addition to identity.","NIST's 2026 software- and AI-agent concept work treats agent authority and authorization as distinct governance problems beyond workload authentication.","A centralized signing service can become a high-impact target even when trust domains reduce blast radius."],"later_author_interview_source_ids":["later-author-source-BATCH-2026-003-001","later-author-source-BATCH-2026-003-002","later-author-source-BATCH-2026-003-003"],"related_book_work_ids":[],"related_report_ids":["counter-source-BATCH-2026-003-001","counter-source-BATCH-2026-003-002","counter-source-BATCH-2026-003-003"],"changes_in_later_statements":["Later SPIFFE specifications add WIT token SVIDs and refine federation and workload-endpoint behavior beyond the book's 2020 scope.","Later author/project material documents serverless and Windows support, narrowing two deployment constraints visible in the first edition.","Later adoption claims broaden the deployment evidence but remain ecosystem-reported rather than independent comparative evaluation."],"edition_ids":["book-edition-BATCH-2026-002-001"],"related_source_ids":["source-BATCH-2026-003-001"],"related_statement_ids":["statement-BATCH-2026-003-001","statement-BATCH-2026-003-002","statement-BATCH-2026-003-003","statement-BATCH-2026-003-004","statement-BATCH-2026-003-005","statement-BATCH-2026-003-006","statement-BATCH-2026-003-007","statement-BATCH-2026-003-008","statement-BATCH-2026-003-009","statement-BATCH-2026-003-010","statement-BATCH-2026-003-011","statement-BATCH-2026-003-012","statement-BATCH-2026-003-013","statement-BATCH-2026-003-014","statement-BATCH-2026-003-015","statement-BATCH-2026-003-016","statement-BATCH-2026-003-017","statement-BATCH-2026-003-018"],"related_proposition_ids":["proposition-candidate-BATCH-2026-003-001","proposition-candidate-BATCH-2026-003-002","proposition-candidate-BATCH-2026-003-003","proposition-candidate-BATCH-2026-003-004","proposition-candidate-BATCH-2026-003-005","proposition-candidate-BATCH-2026-003-006","proposition-candidate-BATCH-2026-003-007","proposition-candidate-BATCH-2026-003-008"],"related_dossier_ids":[],"rights_notes":"Official PDF is licensed CC BY 4.0. This batch uses original paraphrases and no direct quotations; attribution and canonical link are retained.","review_status":"deep_analysis_complete_machine_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/book/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page and bibliographic metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Accepted discovery candidate candidate-BATCH-2026-001-095."},{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Complete 194-page PDF; printed and PDF page numbers align","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Whole-edition analysis; no human approval granted"}],"revision_history":[{"changed_at":"2026-08-15T00:00:00Z","changed_by":"OEII analysis agent","summary":"Advanced from catalogued metadata to complete-edition deep analysis.","batch_id":"BATCH-2026-003"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"book-work","book_work_id":"book-work-BATCH-2026-002-002","title":"Zero Trust Networks","subtitle":"Building Secure Systems in Untrusted Networks","alternate_titles":["Zero Trust Networks, 2nd Edition"],"authors":["person-BATCH-2026-002-013","person-BATCH-2026-002-014","person-BATCH-2026-002-003","person-BATCH-2026-002-015"],"contributors":[],"original_language":"lang-en","first_publication_date":null,"work_type":"materially_revised_second_edition_work","topics":["governed-agent-identities","identity-and-access-management"],"central_subjects":["zero trust","authentication","authorization","policy enforcement","network and workload identity"],"inclusion_rationale":"The revised four-author work provides foundational architecture for identity-first, least-privilege agent access; the agent-specific applicability requires complete review.","analysis_depth":"catalogued","analysis_basis":"authorized_preview","central_thesis":null,"principal_propositions":[],"frameworks":[],"evidence_base":"Bibliographic and access verification only; no whole-book argument synthesis performed in this batch.","executive_role_implications":{},"strongest_documented_arguments":[],"limitations":["No unsupported chapter summary or full-argument claim created.","Agent-specific contribution remains a question for a later complete-review batch."],"counterpoints":[],"later_author_interview_source_ids":[],"related_book_work_ids":[],"related_report_ids":[],"changes_in_later_statements":[],"edition_ids":["book-edition-BATCH-2026-002-002","book-edition-BATCH-2026-002-003","book-edition-BATCH-2026-002-004"],"related_source_ids":[],"related_statement_ids":[],"related_proposition_ids":[],"related_dossier_ids":[],"rights_notes":"Metadata, table of contents, and authorized preview only; no complete text was stored or claimed as reviewed.","review_status":"catalogued","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/titlepage01.html","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page and bibliographic metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Accepted discovery candidate candidate-BATCH-2026-001-096."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"book-work","book_work_id":"book-work-BATCH-2026-002-003","title":"OAuth 2 in Action","subtitle":null,"alternate_titles":[],"authors":["person-BATCH-2026-002-016","person-BATCH-2026-002-017"],"contributors":["Ian Glazer"],"original_language":"lang-en","first_publication_date":null,"work_type":"technical_book","topics":["governed-agent-identities","identity-and-access-management"],"central_subjects":["OAuth 2.0","delegated authorization","tokens","client and resource-server security"],"inclusion_rationale":"Foundational treatment of delegated authorization that may inform agents acting on behalf of users; agent-specific conclusions require full review.","analysis_depth":"catalogued","analysis_basis":"authorized_preview","central_thesis":null,"principal_propositions":[],"frameworks":[],"evidence_base":"Bibliographic and access verification only; no whole-book argument synthesis performed in this batch.","executive_role_implications":{},"strongest_documented_arguments":[],"limitations":["No unsupported chapter summary or full-argument claim created.","Agent-specific contribution remains a question for a later complete-review batch."],"counterpoints":[],"later_author_interview_source_ids":[],"related_book_work_ids":[],"related_report_ids":[],"changes_in_later_statements":[],"edition_ids":["book-edition-BATCH-2026-002-005"],"related_source_ids":[],"related_statement_ids":[],"related_proposition_ids":[],"related_dossier_ids":[],"rights_notes":"Publisher metadata and authorized preview only; metadata and link use are permitted, quotation rights not established.","review_status":"catalogued","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.manning.com/books/oauth-2-in-action","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page and bibliographic metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Accepted discovery candidate candidate-BATCH-2026-001-097."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"book-work","book_work_id":"book-work-BATCH-2026-002-004","title":"API Security in Action","subtitle":null,"alternate_titles":[],"authors":["person-BATCH-2026-002-018"],"contributors":[],"original_language":"lang-en","first_publication_date":null,"work_type":"technical_book","topics":["governed-agent-identities","identity-and-access-management"],"central_subjects":["API security","authentication","authorization","audit logging","capability-based security"],"inclusion_rationale":"Addresses the security boundary through which many agents invoke tools; relevance is architectural and does not establish agent-governance claims by itself.","analysis_depth":"catalogued","analysis_basis":"authorized_preview","central_thesis":null,"principal_propositions":[],"frameworks":[],"evidence_base":"Bibliographic and access verification only; no whole-book argument synthesis performed in this batch.","executive_role_implications":{},"strongest_documented_arguments":[],"limitations":["No unsupported chapter summary or full-argument claim created.","Agent-specific contribution remains a question for a later complete-review batch."],"counterpoints":[],"later_author_interview_source_ids":[],"related_book_work_ids":[],"related_report_ids":[],"changes_in_later_statements":[],"edition_ids":["book-edition-BATCH-2026-002-006"],"related_source_ids":[],"related_statement_ids":[],"related_proposition_ids":[],"related_dossier_ids":[],"rights_notes":"Publisher metadata, contents, and authorized preview only; no full-book access or quotation permission recorded.","review_status":"catalogued","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.manning.com/books/api-security-in-action","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page and bibliographic metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Accepted discovery candidate candidate-BATCH-2026-001-098."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"book-work","book_work_id":"book-work-BATCH-2026-002-005","title":"Building Secure and Reliable Systems","subtitle":"Best Practices for Designing, Implementing, and Maintaining Systems","alternate_titles":[],"authors":["person-BATCH-2026-002-019","person-BATCH-2026-002-020","person-BATCH-2026-002-021","person-BATCH-2026-002-022","person-BATCH-2026-002-023","person-BATCH-2026-002-024"],"contributors":[],"original_language":"lang-en","first_publication_date":"2020-04-08","work_type":"collaborative_technical_book","topics":["governed-agent-identities","identity-and-access-management"],"central_subjects":["least privilege","secure and reliable system design","authorization policy","audit and incident response"],"inclusion_rationale":"Official complete text covers least privilege, policy, access, audit, and responsibility; these are directly useful foundations for governed agents.","analysis_depth":"deeply_analyzed","analysis_basis":"Complete official Google-hosted first-edition HTML reviewed across all 35 front-matter, part, chapter, appendix, and back-matter files","central_thesis":"Security and reliability are mutually reinforcing, emergent properties that must be designed, implemented, tested, operated, and governed together across the system lifecycle rather than added by a specialist team at the end.","principal_propositions":["proposition-candidate-BATCH-2026-003-009","proposition-candidate-BATCH-2026-003-010","proposition-candidate-BATCH-2026-003-011","proposition-candidate-BATCH-2026-003-012","proposition-candidate-BATCH-2026-003-013","proposition-candidate-BATCH-2026-003-014","proposition-candidate-BATCH-2026-003-015","proposition-candidate-BATCH-2026-003-016"],"frameworks":[{"name":"Design for least privilege","description":"Grant humans, automated tasks, and machines only the narrow access needed, with risk classification and auditable functional interfaces."},{"name":"Layered resilience","description":"Use independent failure domains, controlled blast radius, graceful degradation, and recovery mechanisms."},{"name":"Artifact-centered software supply chain","description":"Verify binaries and provenance at deployment choke points rather than relying only on the identity of a human submitter."},{"name":"Incident management and recovery","description":"Separate coordination, mitigation, investigation, communication, and recovery through rehearsed roles and explicit state."},{"name":"Security and reliability culture","description":"Distribute responsibility, align incentives, support specialists and champions, and resource the work sustainably."}],"evidence_base":"Multi-author practitioner synthesis grounded in Google and industry operating experience, technical examples, case studies, incident narratives, analogies, and recommendations. It is not a controlled study and largely reflects large-technology-company conditions.","executive_role_implications":{"CISO":"Translate adversary models into contextual authorization, multi-party controls, audit evidence, and incident practice.","CIO":"Integrate security and reliability into platform standards, change systems, procurement, staffing, and disaster exercises.","CTO":"Design understandable interfaces, bounded failure domains, provenance gates, safe defaults, and recovery paths.","General Counsel":"Set privacy-aware logging, retention, investigation, disclosure, and evidence-handling requirements.","CEO":"Shape incentives and sustainable resourcing so production pressure does not externalize security and reliability risk.","Board Director":"Treat systemic access, supply-chain, recovery, and cultural risk as governance matters, not just technical metrics."},"strongest_documented_arguments":["Least privilege becomes operational when access is classified by impact and exposed through narrow, auditable functions.","Deployment confidence depends on verified artifacts and provenance, not merely trusted people or code-review events.","Recovery capability is a designed and rehearsed property, not a document presumed to work during a crisis."],"limitations":["Many recommendations reflect Google's scale, staffing, engineering maturity, and ability to build custom control planes.","The chapter evidence is primarily practitioner experience rather than externally replicated causal analysis.","The book predates modern general-purpose AI agents and does not define sponsor, delegation, session, model, tool-purpose, or decision-provenance identity fields.","Privacy, legal process, and geography are acknowledged but not developed into jurisdiction-specific operating models."],"counterpoints":["Smaller organizations may need managed services and fewer control layers because the full operating model can exceed their resources.","Immutable logging can conflict with data minimization, correction, deletion, and cross-border obligations unless governance is designed with counsel.","Identity and provenance controls still require trustworthy verification, policy, and runtime enforcement; attestations alone do not prove safe behavior."],"later_author_interview_source_ids":["later-author-source-BATCH-2026-003-004","later-author-source-BATCH-2026-003-005","later-author-source-BATCH-2026-003-006"],"related_book_work_ids":[],"related_report_ids":["counter-source-BATCH-2026-003-004","counter-source-BATCH-2026-003-005","counter-source-BATCH-2026-003-006"],"changes_in_later_statements":["Later author commentary expands zero-trust practice toward data-layer controls, activity metadata, peer review, and justified access.","Post-SolarWinds author commentary strengthens the book's artifact-provenance argument into an ecosystem supply-chain priority.","Later SRE commentary describes the field as evolving and points readers to a continuing compendium rather than treating the 2020 text as final."],"edition_ids":["book-edition-BATCH-2026-002-007","book-edition-BATCH-2026-002-008","book-edition-BATCH-2026-002-009"],"related_source_ids":["source-BATCH-2026-003-002"],"related_statement_ids":["statement-BATCH-2026-003-019","statement-BATCH-2026-003-020","statement-BATCH-2026-003-021","statement-BATCH-2026-003-022","statement-BATCH-2026-003-023","statement-BATCH-2026-003-024","statement-BATCH-2026-003-025","statement-BATCH-2026-003-026","statement-BATCH-2026-003-027","statement-BATCH-2026-003-028","statement-BATCH-2026-003-029","statement-BATCH-2026-003-030","statement-BATCH-2026-003-031","statement-BATCH-2026-003-032","statement-BATCH-2026-003-033","statement-BATCH-2026-003-034","statement-BATCH-2026-003-035","statement-BATCH-2026-003-036"],"related_proposition_ids":["proposition-candidate-BATCH-2026-003-009","proposition-candidate-BATCH-2026-003-010","proposition-candidate-BATCH-2026-003-011","proposition-candidate-BATCH-2026-003-012","proposition-candidate-BATCH-2026-003-013","proposition-candidate-BATCH-2026-003-014","proposition-candidate-BATCH-2026-003-015","proposition-candidate-BATCH-2026-003-016"],"related_dossier_ids":[],"rights_notes":"Official complete HTML was lawfully accessible for research. No open republication license was identified; this batch stores metadata, links, original analysis, and no direct quotations.","review_status":"deep_analysis_complete_machine_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page and bibliographic metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Accepted discovery candidate candidate-BATCH-2026-001-099."},{"source_url":"https://google.github.io/building-secure-and-reliable-systems/","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"All 35 official HTML content files; stable chapter and section anchors","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Manifest hash ae702b4e64364217f179317b4a46de6a5e7c51045a79efa67522245d76667e16; whole-edition analysis; no human approval granted"}],"revision_history":[{"changed_at":"2026-08-15T00:00:00Z","changed_by":"OEII analysis agent","summary":"Advanced from catalogued metadata to complete-edition deep analysis.","batch_id":"BATCH-2026-003"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"book-work","book_work_id":"book-work-BATCH-2026-002-006","title":"Identity in Modern Applications","subtitle":null,"alternate_titles":[],"authors":["person-BATCH-2026-002-025"],"contributors":[],"original_language":"lang-en","first_publication_date":null,"work_type":"short_technical_report","topics":["governed-agent-identities","identity-and-access-management"],"central_subjects":["application identity","authentication","authorization","nonhuman identity","trust systems"],"inclusion_rationale":"The official contents explicitly include nonhuman identities and trust systems, making the short work relevant to agent identity; complete argument review has not occurred.","analysis_depth":"catalogued","analysis_basis":"authorized_preview","central_thesis":null,"principal_propositions":[],"frameworks":[],"evidence_base":"Bibliographic and access verification only; no whole-book argument synthesis performed in this batch.","executive_role_implications":{},"strongest_documented_arguments":[],"limitations":["No unsupported chapter summary or full-argument claim created.","Agent-specific contribution remains a question for a later complete-review batch."],"counterpoints":[],"later_author_interview_source_ids":[],"related_book_work_ids":[],"related_report_ids":[],"changes_in_later_statements":[],"edition_ids":["book-edition-BATCH-2026-002-010"],"related_source_ids":[],"related_statement_ids":[],"related_proposition_ids":[],"related_dossier_ids":[],"rights_notes":"Publisher metadata, contents, and authorized preview only; no complete text or republication permission recorded.","review_status":"catalogued","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/identity-in-modern/9781098107789/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page and bibliographic metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Accepted discovery candidate candidate-BATCH-2026-001-100."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"book-work","book_work_id":"book-work-BATCH-2026-002-007","title":"Solving Identity Management in Modern Applications","subtitle":"Demystifying OAuth 2.0, OpenID Connect, and SAML 2.0","alternate_titles":[],"authors":["person-BATCH-2026-002-026","person-BATCH-2026-002-027"],"contributors":[],"original_language":"lang-en","first_publication_date":"2019-12-18","work_type":"technical_book_first_edition_work","topics":["governed-agent-identities","identity-and-access-management"],"central_subjects":["identity lifecycle","authentication","authorization","OAuth 2.0","OpenID Connect","SAML 2.0"],"inclusion_rationale":"Provides identity-lifecycle and protocol foundations applicable to provisioning and deprovisioning agent identities; the accepted candidate resolves to the first edition.","analysis_depth":"catalogued","analysis_basis":"table_of_contents_only","central_thesis":null,"principal_propositions":[],"frameworks":[],"evidence_base":"Bibliographic and access verification only; no whole-book argument synthesis performed in this batch.","executive_role_implications":{},"strongest_documented_arguments":[],"limitations":["No unsupported chapter summary or full-argument claim created.","Agent-specific contribution remains a question for a later complete-review batch."],"counterpoints":[],"later_author_interview_source_ids":[],"related_book_work_ids":["book-work-BATCH-2026-002-008"],"related_report_ids":[],"changes_in_later_statements":[],"edition_ids":["book-edition-BATCH-2026-002-011"],"related_source_ids":[],"related_statement_ids":[],"related_proposition_ids":[],"related_dossier_ids":[],"rights_notes":"Official publisher metadata and table of contents only; no complete lawful access or quotation permission recorded.","review_status":"catalogued","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://link.springer.com/book/10.1007/978-1-4842-5095-2","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page and bibliographic metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Accepted discovery candidate candidate-BATCH-2026-001-101."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"book-work","book_work_id":"book-work-BATCH-2026-002-009","title":"Identity-Native Infrastructure Access Management","subtitle":null,"alternate_titles":[],"authors":["person-BATCH-2026-002-028","person-BATCH-2026-002-029","person-BATCH-2026-002-030"],"contributors":[],"original_language":"lang-en","first_publication_date":null,"work_type":"technical_book","topics":["governed-agent-identities","identity-and-access-management"],"central_subjects":["identity-native access","ephemeral credentials","identity attestation","authorization","audit"],"inclusion_rationale":"Directly addresses ephemeral identities, machine access, authorization, and audit; agent-specific applicability requires complete review and vendor-context disclosure.","analysis_depth":"catalogued","analysis_basis":"authorized_preview","central_thesis":null,"principal_propositions":[],"frameworks":[],"evidence_base":"Bibliographic and access verification only; no whole-book argument synthesis performed in this batch.","executive_role_implications":{},"strongest_documented_arguments":[],"limitations":["No unsupported chapter summary or full-argument claim created.","Agent-specific contribution remains a question for a later complete-review batch."],"counterpoints":[],"later_author_interview_source_ids":[],"related_book_work_ids":[],"related_report_ids":[],"changes_in_later_statements":[],"edition_ids":["book-edition-BATCH-2026-002-014"],"related_source_ids":[],"related_statement_ids":[],"related_proposition_ids":[],"related_dossier_ids":[],"rights_notes":"Publisher metadata, contents, author biographies, and authorized preview only; no complete text or quotation permission recorded.","review_status":"catalogued","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page and bibliographic metadata","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Accepted discovery candidate candidate-BATCH-2026-001-102."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-amy-shillinglaw","canonical_name":"Amy Shillinglaw","display_name":"Amy Shillinglaw","alternate_names":["Amy Schillingla"],"name_disambiguation_note":"Caption misspelling corrected from official SailPoint speaker metadata and self-identification.","external_identifiers":{"sailpoint_community_handle":"amy_shillinglaw"},"current_role":"Technical Advocate / Technical Educator","current_organization_reference":"orgref-sailpoint","current_role_source":"https://go.sailpoint.com/onboarding-ai-agents-with-sailPoint-connectors.html","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_official_profile","historical_roles":[],"role_at_source_time":[{"source_id":"source-sailpoint-governing-ai-agents-2025","role":"Technical Advocate and sole on-record presenter","organization_reference":"orgref-sailpoint"}],"professional_geographies":[],"operating_markets":["geo-global"],"languages":["lang-en"],"expertise_topics":["topic-ai-agents","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"authored_book_work_ids":[],"contributed_work_ids":[],"source_ids":["source-sailpoint-governing-ai-agents-2025"],"statement_ids":["statement-BATCH-2026-004-011","statement-BATCH-2026-004-012","statement-BATCH-2026-004-013","statement-BATCH-2026-004-014","statement-BATCH-2026-004-015","statement-BATCH-2026-004-016","statement-BATCH-2026-004-017","statement-BATCH-2026-004-018"],"proposition_relationships":[],"relationship_to_off":"none","disclosure":"SailPoint employee presenting SailPoint products; vendor affiliation is material to every extracted statement.","public_profile_eligibility":false,"verification_status":"identity_and_current_role_verified","person_depth":"substantive","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://go.sailpoint.com/governing-ai-agents-with-agent-identity-security.html","accessed_at":"2026-08-15","retrieval_method":"official speaker page, recording self-identification, and speaker-labeled captions","exact_locator":"00:03-02:19","content_hash":null,"batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":"Kirby Fitch is explicitly absent; Paul Patti is not audible."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-001","canonical_name":"Daniel Feldman","display_name":"Daniel Feldman","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://spiffe.io/book/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-001"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/book/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 1 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-002","canonical_name":"Emily Fox","display_name":"Emily Fox","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://spiffe.io/book/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-001"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/book/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 2 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-003","canonical_name":"Evan Gilman","display_name":"Evan Gilman","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://spiffe.io/book/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-001","book-work-BATCH-2026-002-002"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/book/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 3 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-004","canonical_name":"Ian Haken","display_name":"Ian Haken","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://spiffe.io/book/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-001"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/book/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 4 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-005","canonical_name":"Frederick Kautz","display_name":"Frederick Kautz","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://spiffe.io/book/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-001"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/book/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 5 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-006","canonical_name":"Umair Khan","display_name":"Umair Khan","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://spiffe.io/book/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-001"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/book/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 6 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-007","canonical_name":"Max Lambrecht","display_name":"Max Lambrecht","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://spiffe.io/book/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-001"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/book/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 7 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-008","canonical_name":"Brandon Lum","display_name":"Brandon Lum","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://spiffe.io/book/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-001"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/book/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 8 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-009","canonical_name":"Agustín Martínez Fayó","display_name":"Agustín Martínez Fayó","alternate_names":["Agustin Martinez Fayo"],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://spiffe.io/book/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-001"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/book/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 9 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-010","canonical_name":"Eli Nesterov","display_name":"Eli Nesterov","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://spiffe.io/book/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-001"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/book/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 10 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-011","canonical_name":"Andrés Vega","display_name":"Andrés Vega","alternate_names":["Andres Vega"],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://spiffe.io/book/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-001"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/book/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 11 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-012","canonical_name":"Michael Wardrop","display_name":"Michael Wardrop","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://spiffe.io/book/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-001"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/book/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 12 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-013","canonical_name":"Razi Rais","display_name":"Razi Rais","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/titlepage01.html"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-002"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/titlepage01.html","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 13 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-014","canonical_name":"Christina Morillo","display_name":"Christina Morillo","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/titlepage01.html"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-002"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/titlepage01.html","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 14 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-015","canonical_name":"Doug Barth","display_name":"Doug Barth","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/titlepage01.html"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-002"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/titlepage01.html","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 15 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-016","canonical_name":"Justin Richer","display_name":"Justin Richer","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.manning.com/books/oauth-2-in-action"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-003"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.manning.com/books/oauth-2-in-action","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 16 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-017","canonical_name":"Antonio Sanso","display_name":"Antonio Sanso","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.manning.com/books/oauth-2-in-action"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-003"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.manning.com/books/oauth-2-in-action","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 17 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-018","canonical_name":"Neil Madden","display_name":"Neil Madden","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.manning.com/books/api-security-in-action"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-004"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.manning.com/books/api-security-in-action","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 18 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-019","canonical_name":"Heather Adkins","display_name":"Heather Adkins","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-005"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 19 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-020","canonical_name":"Betsy Beyer","display_name":"Betsy Beyer","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-005"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 20 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-021","canonical_name":"Paul Blankinship","display_name":"Paul Blankinship","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-005"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 21 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-022","canonical_name":"Piotr Lewandowski","display_name":"Piotr Lewandowski","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-005"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 22 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-023","canonical_name":"Ana Oprea","display_name":"Ana Oprea","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-005"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 23 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-024","canonical_name":"Adam Stubblefield","display_name":"Adam Stubblefield","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-005"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 24 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-025","canonical_name":"Lee Atchison","display_name":"Lee Atchison","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.oreilly.com/library/view/identity-in-modern/9781098107789/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-006"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/identity-in-modern/9781098107789/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 25 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-026","canonical_name":"Yvonne Wilson","display_name":"Yvonne Wilson","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://link.springer.com/book/10.1007/978-1-4842-5095-2"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-007"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://link.springer.com/book/10.1007/978-1-4842-5095-2","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 26 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-027","canonical_name":"Abhishek Hingnikar","display_name":"Abhishek Hingnikar","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://link.springer.com/book/10.1007/978-1-4842-5095-2"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-007"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://link.springer.com/book/10.1007/978-1-4842-5095-2","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 27 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-028","canonical_name":"Ev Kontsevoy","display_name":"Ev Kontsevoy","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/colophon01.html"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-009"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/colophon01.html","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 28 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-029","canonical_name":"Sakshyam Shah","display_name":"Sakshyam Shah","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/colophon01.html"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-009"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/colophon01.html","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 29 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-002-030","canonical_name":"Peter Conrad","display_name":"Peter Conrad","alternate_names":[],"name_disambiguation_note":"Verified only as the named author of the linked work; current role and broader identity profile were not inferred.","external_identifiers":{"official_profile_url":null,"author_attribution_url":"https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/colophon01.html"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"not_researched","historical_roles":[],"role_at_source_time":[],"professional_geographies":[],"operating_markets":[],"languages":[],"expertise_topics":["identity-and-access-management"],"authored_book_work_ids":["book-work-BATCH-2026-002-009"],"contributed_work_ids":[],"source_ids":[],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":"Staging author identity candidate; named-human identity review pending.","public_profile_eligibility":false,"verification_status":"verified_as_named_author_on_official_work_source","person_depth":"identity_record","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/colophon01.html","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official work page author attribution","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author candidate 30 of 30; current role not researched."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-alex-pentland","canonical_name":"Alex Pentland","display_name":"Alex Pentland","alternate_names":["Alex ‘Sandy’ Pentland","Sandy Pentland","A. Pentland"],"name_disambiguation_note":"The MIT professor also known as Sandy Pentland and a contributor/author of the indexed OpenID Foundation report and arXiv rendition.","external_identifiers":{"official_profile_url":"https://professional.mit.edu/programs/faculty-profiles/alex-pentland"},"current_role":"Toshiba Professor of Media Arts and Sciences","current_organization_reference":"Massachusetts Institute of Technology","current_role_source":"https://professional.mit.edu/programs/faculty-profiles/alex-pentland","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_official_university_profile_checked_2026-08-15","historical_roles":[{"person_id":"person-BATCH-2026-005-alex-pentland","source_id":"source-BATCH-2026-005-004","source_title":"Identity Management for Agentic AI","source_version":"October 2025 official OpenID Foundation report","relationship":"contributor","author_order":21,"organization_at_source_time":"not reported","role_at_source_time":"Contributor","verification_basis":"PDF title or contributor page","verification_status":"relationship_verified_affiliation_not_reported","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-alex-pentland","source_id":"source-BATCH-2026-005-004","source_title":"Identity Management for Agentic AI","source_version":"October 2025 official OpenID Foundation report","relationship":"contributor","author_order":21,"organization_at_source_time":"not reported","role_at_source_time":"Contributor","verification_basis":"PDF title or contributor page","verification_status":"relationship_verified_affiliation_not_reported","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["United States"],"operating_markets":[],"languages":[],"expertise_topics":["AI agent identity","authenticated delegation","AI-agent auditability"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-004"],"source_ids":["source-BATCH-2026-005-004"],"statement_ids":["statement-BATCH-2026-006-015","statement-BATCH-2026-006-016","statement-BATCH-2026-006-017","statement-BATCH-2026-006-018","statement-BATCH-2026-006-019","statement-BATCH-2026-006-020","statement-BATCH-2026-006-021"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_authorship_and_current_role_machine_verified_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://professional.mit.edu/programs/faculty-profiles/alex-pentland","accessed_at":"2026-08-15","retrieval_method":"official institutional/company page or self-authored professional CV reviewed on the public web","exact_locator":"Faculty profile heading — Toshiba Professor of Media Arts and Sciences","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Current-role evidence; named human review pending."},{"source_url":"https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"October 2025 official OpenID Foundation report; byline/contributor relationship and source-time affiliation","content_hash":"e6a0e5909fcb2486568180f69d511ae2af8d20a1bfb3028b39b3d1072846f4f3","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-daniel-kang","canonical_name":"Daniel Kang","display_name":"Daniel Kang","alternate_names":["D. Kang"],"name_disambiguation_note":"The UIUC faculty member and final author of the indexed HPTSA paper.","external_identifiers":{"official_profile_url":"https://siebelschool.illinois.edu/about/people/faculty/ddkang"},"current_role":"Assistant Professor","current_organization_reference":"University of Illinois Urbana-Champaign","current_role_source":"https://siebelschool.illinois.edu/about/people/faculty/ddkang","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_official_university_profile_checked_2026-08-15","historical_roles":[{"person_id":"person-BATCH-2026-005-daniel-kang","source_id":"source-BATCH-2026-005-008","source_title":"Teams of LLM Agents Can Exploit Zero-Day Vulnerabilities","source_version":"arXiv v2 submitted 2025-03-30","relationship":"author","author_order":7,"organization_at_source_time":"University of Illinois Urbana-Champaign","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-daniel-kang","source_id":"source-BATCH-2026-005-008","source_title":"Teams of LLM Agents Can Exploit Zero-Day Vulnerabilities","source_version":"arXiv v2 submitted 2025-03-30","relationship":"author","author_order":7,"organization_at_source_time":"University of Illinois Urbana-Champaign","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["United States"],"operating_markets":[],"languages":[],"expertise_topics":["AI red-teaming agents","zero-day vulnerability evaluation"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-008"],"source_ids":["source-BATCH-2026-005-008"],"statement_ids":["statement-BATCH-2026-006-033","statement-BATCH-2026-006-034","statement-BATCH-2026-006-035","statement-BATCH-2026-006-036","statement-BATCH-2026-006-037","statement-BATCH-2026-006-038"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_authorship_and_current_role_machine_verified_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://siebelschool.illinois.edu/about/people/faculty/ddkang","accessed_at":"2026-08-15","retrieval_method":"official institutional/company page or self-authored professional CV reviewed on the public web","exact_locator":"Faculty profile heading — Daniel Kang — Assistant Professor","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Current-role evidence; named human review pending."},{"source_url":"https://arxiv.org/abs/2406.01637","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"arXiv v2 submitted 2025-03-30; byline/contributor relationship and source-time affiliation","content_hash":"f4fc06040f0856d99d2009042b4c6fa0c01206da8ca61cb39a94d52b9867cf71","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-edoardo-debenedetti","canonical_name":"Edoardo Debenedetti","display_name":"Edoardo Debenedetti","alternate_names":["E. Debenedetti"],"name_disambiguation_note":"The AgentDojo first author who is listed as a PhD student in Florian Tramèr's ETH Zurich SPY Lab.","external_identifiers":{"personal_website":"https://edoardo.science/"},"current_role":"PhD Student","current_organization_reference":"ETH Zurich","current_role_source":"https://spylab.ai/","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_official_lab_page_checked_2026-08-15","historical_roles":[{"person_id":"person-BATCH-2026-005-edoardo-debenedetti","source_id":"source-BATCH-2026-005-006","source_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","source_version":"arXiv v3","relationship":"author","author_order":1,"organization_at_source_time":"ETH Zurich","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-edoardo-debenedetti","source_id":"source-BATCH-2026-005-006","source_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","source_version":"arXiv v3","relationship":"author","author_order":1,"organization_at_source_time":"ETH Zurich","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["Switzerland"],"operating_markets":[],"languages":[],"expertise_topics":["AI agent security","prompt injection evaluation"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-006"],"source_ids":["source-BATCH-2026-005-006"],"statement_ids":["statement-BATCH-2026-006-022","statement-BATCH-2026-006-023","statement-BATCH-2026-006-024","statement-BATCH-2026-006-025","statement-BATCH-2026-006-026","statement-BATCH-2026-006-027"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_authorship_and_current_role_machine_verified_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spylab.ai/","accessed_at":"2026-08-15","retrieval_method":"official institutional/company page or self-authored professional CV reviewed on the public web","exact_locator":"People — Edoardo Debenedetti — PhD Student","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Current-role evidence; named human review pending."},{"source_url":"https://arxiv.org/abs/2406.13352","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"arXiv v3; byline/contributor relationship and source-time affiliation","content_hash":"349884fffbf43282591c5accffd57bb651632f38e412fe303114941bdd111b05","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-florian-tramer","canonical_name":"Florian Tramèr","display_name":"Florian Tramèr","alternate_names":["Florian Tramer","F. Tramèr","F. Tramer"],"name_disambiguation_note":"The ETH Zurich professor and final AgentDojo author; diacritic-free forms refer to the same person.","external_identifiers":{"orcid":"0000-0001-8703-8762","official_profile_url":"https://inf.ethz.ch/people/people-atoz/person-detail.MjU5NzMw.TGlzdC8zMDQsLTIxNDE4MTU0NjA%3D.html"},"current_role":"Assistant Professor at the Department of Computer Science","current_organization_reference":"ETH Zurich","current_role_source":"https://inf.ethz.ch/people/people-atoz/person-detail.MjU5NzMw.TGlzdC8zMDQsLTIxNDE4MTU0NjA%3D.html","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_official_university_profile_checked_2026-08-15","historical_roles":[{"person_id":"person-BATCH-2026-005-florian-tramer","source_id":"source-BATCH-2026-005-006","source_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","source_version":"arXiv v3","relationship":"author","author_order":6,"organization_at_source_time":"ETH Zurich","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-florian-tramer","source_id":"source-BATCH-2026-005-006","source_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","source_version":"arXiv v3","relationship":"author","author_order":6,"organization_at_source_time":"ETH Zurich","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["Switzerland"],"operating_markets":[],"languages":[],"expertise_topics":["AI agent security","prompt injection evaluation"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-006"],"source_ids":["source-BATCH-2026-005-006"],"statement_ids":["statement-BATCH-2026-006-022","statement-BATCH-2026-006-023","statement-BATCH-2026-006-024","statement-BATCH-2026-006-025","statement-BATCH-2026-006-026","statement-BATCH-2026-006-027"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_authorship_and_current_role_machine_verified_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://inf.ethz.ch/people/people-atoz/person-detail.MjU5NzMw.TGlzdC8zMDQsLTIxNDE4MTU0NjA%3D.html","accessed_at":"2026-08-15","retrieval_method":"official institutional/company page or self-authored professional CV reviewed on the public web","exact_locator":"Profile heading — Assistant Professor at the Department of Computer Science","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Current-role evidence; named human review pending."},{"source_url":"https://arxiv.org/abs/2406.13352","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"arXiv v3; byline/contributor relationship and source-time affiliation","content_hash":"349884fffbf43282591c5accffd57bb651632f38e412fe303114941bdd111b05","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-hanrong-zhang","canonical_name":"Hanrong Zhang","display_name":"Hanrong Zhang","alternate_names":["H. Zhang"],"name_disambiguation_note":"The first author of Agent Security Bench, formerly at Zhejiang University and now documented in a self-authored CV as a UIC PhD student.","external_identifiers":{"personal_cv_url":"https://zhang-henry.github.io/assets/pdf/CV_Hanrong_Zhang.pdf"},"current_role":"PhD Student in Computer Science","current_organization_reference":"University of Illinois Chicago","current_role_source":"https://zhang-henry.github.io/assets/pdf/CV_Hanrong_Zhang.pdf","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_self_authored_cv_checked_2026-08-15","historical_roles":[{"person_id":"person-BATCH-2026-005-hanrong-zhang","source_id":"source-BATCH-2026-005-007","source_title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","source_version":"arXiv v4; ICLR 2025","relationship":"author","author_order":1,"organization_at_source_time":"Zhejiang University","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-hanrong-zhang","source_id":"source-BATCH-2026-005-007","source_title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","source_version":"arXiv v4; ICLR 2025","relationship":"author","author_order":1,"organization_at_source_time":"Zhejiang University","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["United States","China"],"operating_markets":[],"languages":[],"expertise_topics":["AI agent security benchmarking","agent attack and defense evaluation"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-007"],"source_ids":["source-BATCH-2026-005-007"],"statement_ids":["statement-BATCH-2026-006-028","statement-BATCH-2026-006-029","statement-BATCH-2026-006-030","statement-BATCH-2026-006-031","statement-BATCH-2026-006-032"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_authorship_and_current_role_machine_verified_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://zhang-henry.github.io/assets/pdf/CV_Hanrong_Zhang.pdf","accessed_at":"2026-08-15","retrieval_method":"official institutional/company page or self-authored professional CV reviewed on the public web","exact_locator":"CV p. 1, Education — University of Illinois Chicago, Aug. 2025–Present; updated July 14, 2026","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Current-role evidence; named human review pending."},{"source_url":"https://arxiv.org/abs/2410.02644","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"arXiv v4; ICLR 2025; byline/contributor relationship and source-time affiliation","content_hash":"e20155df01b3a1f6c0a947c4e9e4871957cff2e507939f7ea21a5fe967d84504","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-jie-zhang","canonical_name":"Jie Zhang","display_name":"Jie Zhang","alternate_names":["J. Zhang"],"name_disambiguation_note":"The AgentDojo coauthor in Florian Tramèr's ETH Zurich SPY Lab, not another researcher with the same name.","external_identifiers":{"official_profile_url":"https://zj-jayzhang.github.io/"},"current_role":"PhD Student","current_organization_reference":"ETH Zurich","current_role_source":"https://spylab.ai/","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_official_lab_page_checked_2026-08-15","historical_roles":[{"person_id":"person-BATCH-2026-005-jie-zhang","source_id":"source-BATCH-2026-005-006","source_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","source_version":"arXiv v3","relationship":"author","author_order":2,"organization_at_source_time":"ETH Zurich","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-jie-zhang","source_id":"source-BATCH-2026-005-006","source_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","source_version":"arXiv v3","relationship":"author","author_order":2,"organization_at_source_time":"ETH Zurich","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["Switzerland"],"operating_markets":[],"languages":[],"expertise_topics":["AI agent security","prompt injection evaluation"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-006"],"source_ids":["source-BATCH-2026-005-006"],"statement_ids":["statement-BATCH-2026-006-022","statement-BATCH-2026-006-023","statement-BATCH-2026-006-024","statement-BATCH-2026-006-025","statement-BATCH-2026-006-026","statement-BATCH-2026-006-027"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_authorship_and_current_role_machine_verified_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spylab.ai/","accessed_at":"2026-08-15","retrieval_method":"official institutional/company page or self-authored professional CV reviewed on the public web","exact_locator":"People — Jie Zhang — PhD Student","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Current-role evidence; named human review pending."},{"source_url":"https://arxiv.org/abs/2406.13352","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"arXiv v3; byline/contributor relationship and source-time affiliation","content_hash":"349884fffbf43282591c5accffd57bb651632f38e412fe303114941bdd111b05","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-jingyuan-huang","canonical_name":"Jingyuan Huang","display_name":"Jingyuan Huang","alternate_names":["J. Huang"],"name_disambiguation_note":"The Agent Security Bench coauthor listed in Rutgers Computer Science's graduate directory under netid jh2164.","external_identifiers":{"rutgers_netid":"jh2164"},"current_role":"PhD Student","current_organization_reference":"Rutgers University","current_role_source":"https://www.cs.rutgers.edu/people/directory.php?netid=jh2164&type=grad","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_official_university_directory_checked_2026-08-15","historical_roles":[{"person_id":"person-BATCH-2026-005-jingyuan-huang","source_id":"source-BATCH-2026-005-007","source_title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","source_version":"arXiv v4; ICLR 2025","relationship":"author","author_order":2,"organization_at_source_time":"Rutgers University","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-jingyuan-huang","source_id":"source-BATCH-2026-005-007","source_title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","source_version":"arXiv v4; ICLR 2025","relationship":"author","author_order":2,"organization_at_source_time":"Rutgers University","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["United States"],"operating_markets":[],"languages":[],"expertise_topics":["AI agent security benchmarking","agent attack and defense evaluation"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-007"],"source_ids":["source-BATCH-2026-005-007"],"statement_ids":["statement-BATCH-2026-006-028","statement-BATCH-2026-006-029","statement-BATCH-2026-006-030","statement-BATCH-2026-006-031","statement-BATCH-2026-006-032"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_authorship_and_current_role_machine_verified_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.cs.rutgers.edu/people/directory.php?netid=jh2164&type=grad","accessed_at":"2026-08-15","retrieval_method":"official institutional/company page or self-authored professional CV reviewed on the public web","exact_locator":"Student Information — Jingyuan Huang — Program: PhD","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Current-role evidence; named human review pending."},{"source_url":"https://arxiv.org/abs/2410.02644","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"arXiv v4; ICLR 2025; byline/contributor relationship and source-time affiliation","content_hash":"e20155df01b3a1f6c0a947c4e9e4871957cff2e507939f7ea21a5fe967d84504","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-kai-mei","canonical_name":"Kai Mei","display_name":"Kai Mei","alternate_names":["K. Mei"],"name_disambiguation_note":"The Agent Security Bench coauthor listed as a graduate student by Rutgers Computer Science, not another professional with the same name.","external_identifiers":{"rutgers_netid":"km1558"},"current_role":"Graduate Student","current_organization_reference":"Rutgers University","current_role_source":"https://computerscience.rutgers.edu/people/graduate-students/details/kai-mei","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_official_university_directory_checked_2026-08-15","historical_roles":[{"person_id":"person-BATCH-2026-005-kai-mei","source_id":"source-BATCH-2026-005-007","source_title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","source_version":"arXiv v4; ICLR 2025","relationship":"author","author_order":3,"organization_at_source_time":"Rutgers University","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-kai-mei","source_id":"source-BATCH-2026-005-007","source_title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","source_version":"arXiv v4; ICLR 2025","relationship":"author","author_order":3,"organization_at_source_time":"Rutgers University","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["United States"],"operating_markets":[],"languages":[],"expertise_topics":["AI agent security benchmarking","agent attack and defense evaluation"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-007"],"source_ids":["source-BATCH-2026-005-007"],"statement_ids":["statement-BATCH-2026-006-028","statement-BATCH-2026-006-029","statement-BATCH-2026-006-030","statement-BATCH-2026-006-031","statement-BATCH-2026-006-032"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_authorship_and_current_role_machine_verified_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://computerscience.rutgers.edu/people/graduate-students/details/kai-mei","accessed_at":"2026-08-15","retrieval_method":"official institutional/company page or self-authored professional CV reviewed on the public web","exact_locator":"Graduate Student Details — Kai Mei","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Current-role evidence; named human review pending."},{"source_url":"https://arxiv.org/abs/2410.02644","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"arXiv v4; ICLR 2025; byline/contributor relationship and source-time affiliation","content_hash":"e20155df01b3a1f6c0a947c4e9e4871957cff2e507939f7ea21a5fe967d84504","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-luca-beurer-kellner","canonical_name":"Luca Beurer-Kellner","display_name":"Luca Beurer-Kellner","alternate_names":["L. Beurer-Kellner"],"name_disambiguation_note":"The AgentDojo coauthor affiliated with ETH Zurich and Invariant Labs in the indexed source.","external_identifiers":{},"current_role":"Chief Technology Officer","current_organization_reference":"Invariant Labs AG","current_role_source":"https://invariantlabs.ai/about","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_official_company_page_checked_2026-08-15","historical_roles":[{"person_id":"person-BATCH-2026-005-luca-beurer-kellner","source_id":"source-BATCH-2026-005-006","source_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","source_version":"arXiv v3","relationship":"author","author_order":4,"organization_at_source_time":"ETH Zurich; Invariant Labs","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-luca-beurer-kellner","source_id":"source-BATCH-2026-005-006","source_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","source_version":"arXiv v3","relationship":"author","author_order":4,"organization_at_source_time":"ETH Zurich; Invariant Labs","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["Switzerland"],"operating_markets":[],"languages":[],"expertise_topics":["AI agent security","prompt injection evaluation"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-006"],"source_ids":["source-BATCH-2026-005-006"],"statement_ids":["statement-BATCH-2026-006-022","statement-BATCH-2026-006-023","statement-BATCH-2026-006-024","statement-BATCH-2026-006-025","statement-BATCH-2026-006-026","statement-BATCH-2026-006-027"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_authorship_and_current_role_machine_verified_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://invariantlabs.ai/about","accessed_at":"2026-08-15","retrieval_method":"official institutional/company page or self-authored professional CV reviewed on the public web","exact_locator":"About — Luca Beurer-Kellner — Chief Technology Officer","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Current-role evidence; named human review pending."},{"source_url":"https://arxiv.org/abs/2406.13352","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"arXiv v3; byline/contributor relationship and source-time affiliation","content_hash":"349884fffbf43282591c5accffd57bb651632f38e412fe303114941bdd111b05","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-marc-fischer","canonical_name":"Marc Fischer","display_name":"Marc Fischer","alternate_names":["M. Fischer"],"name_disambiguation_note":"The AgentDojo coauthor affiliated with ETH Zurich and Invariant Labs in the indexed source.","external_identifiers":{},"current_role":"Chief Executive Officer","current_organization_reference":"Invariant Labs AG","current_role_source":"https://invariantlabs.ai/about","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_official_company_page_checked_2026-08-15","historical_roles":[{"person_id":"person-BATCH-2026-005-marc-fischer","source_id":"source-BATCH-2026-005-006","source_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","source_version":"arXiv v3","relationship":"author","author_order":5,"organization_at_source_time":"ETH Zurich; Invariant Labs","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-marc-fischer","source_id":"source-BATCH-2026-005-006","source_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","source_version":"arXiv v3","relationship":"author","author_order":5,"organization_at_source_time":"ETH Zurich; Invariant Labs","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["Switzerland"],"operating_markets":[],"languages":[],"expertise_topics":["AI agent security","prompt injection evaluation"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-006"],"source_ids":["source-BATCH-2026-005-006"],"statement_ids":["statement-BATCH-2026-006-022","statement-BATCH-2026-006-023","statement-BATCH-2026-006-024","statement-BATCH-2026-006-025","statement-BATCH-2026-006-026","statement-BATCH-2026-006-027"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_authorship_and_current_role_machine_verified_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://invariantlabs.ai/about","accessed_at":"2026-08-15","retrieval_method":"official institutional/company page or self-authored professional CV reviewed on the public web","exact_locator":"About — Marc Fischer — Chief Executive Officer","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Current-role evidence; named human review pending."},{"source_url":"https://arxiv.org/abs/2406.13352","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"arXiv v3; byline/contributor relationship and source-time affiliation","content_hash":"349884fffbf43282591c5accffd57bb651632f38e412fe303114941bdd111b05","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-mislav-balunovic","canonical_name":"Mislav Balunović","display_name":"Mislav Balunović","alternate_names":["Mislav Balunovic","M. Balunović","M. Balunovic"],"name_disambiguation_note":"The AgentDojo coauthor affiliated with ETH Zurich and Invariant Labs in the indexed source; diacritic-free author forms refer to the same person.","external_identifiers":{"eth_profile_url":"https://www.sri.inf.ethz.ch/people/mislav","insait_profile_url":"https://insait.ai/mislav-balunovic/"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"unresolved_conflicting_current_sources","historical_roles":[{"person_id":"person-BATCH-2026-005-mislav-balunovic","source_id":"source-BATCH-2026-005-006","source_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","source_version":"arXiv v3","relationship":"author","author_order":3,"organization_at_source_time":"ETH Zurich; Invariant Labs","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-mislav-balunovic","source_id":"source-BATCH-2026-005-006","source_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","source_version":"arXiv v3","relationship":"author","author_order":3,"organization_at_source_time":"ETH Zurich; Invariant Labs","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["Switzerland"],"operating_markets":[],"languages":[],"expertise_topics":["AI agent security","prompt injection evaluation"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-006"],"source_ids":["source-BATCH-2026-005-006"],"statement_ids":["statement-BATCH-2026-006-022","statement-BATCH-2026-006-023","statement-BATCH-2026-006-024","statement-BATCH-2026-006-025","statement-BATCH-2026-006-026","statement-BATCH-2026-006-027"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_and_authorship_verified_current_role_unresolved_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.sri.inf.ethz.ch/people/mislav","accessed_at":"2026-08-15","retrieval_method":"official institutional profile review","exact_locator":"Profile heading — Post-Doc at ETH Zurich","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Conflicts with INSAIT past-member status and a newer self-maintained professional profile; exact present appointment held unresolved."},{"source_url":"https://insait.ai/phd-post-docs-research-scientists/","accessed_at":"2026-08-15","retrieval_method":"official institutional directory review","exact_locator":"Past Members — Dr. Mislav Balunović","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Shows the INSAIT appointment is historical, but does not establish a current role."},{"source_url":"https://arxiv.org/abs/2406.13352","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"arXiv v3; byline/contributor relationship and source-time affiliation","content_hash":"349884fffbf43282591c5accffd57bb651632f38e412fe303114941bdd111b05","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-richard-fang","canonical_name":"Richard Fang","display_name":"Richard Fang","alternate_names":["R. Fang"],"name_disambiguation_note":"The HPTSA coauthor who participated in Daniel Kang's UIUC research program; current appointment is held unresolved because recent professional profiles do not agree or state an exact role.","external_identifiers":{"openreview_profile":"https://openreview.net/profile?id=~Richard_Fang1","uiuc_profile_url":"https://siebelschool.illinois.edu/research/undergraduate-research/summer-research-experience-undergraduates/participants/Richard-Fang"},"current_role":null,"current_organization_reference":null,"current_role_source":null,"current_role_verified_at":null,"current_role_freshness_status":"unresolved_conflicting_or_incomplete_current_sources","historical_roles":[{"person_id":"person-BATCH-2026-005-richard-fang","source_id":"source-BATCH-2026-005-008","source_title":"Teams of LLM Agents Can Exploit Zero-Day Vulnerabilities","source_version":"arXiv v2 submitted 2025-03-30","relationship":"author","author_order":5,"organization_at_source_time":"University of Illinois Urbana-Champaign","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-richard-fang","source_id":"source-BATCH-2026-005-008","source_title":"Teams of LLM Agents Can Exploit Zero-Day Vulnerabilities","source_version":"arXiv v2 submitted 2025-03-30","relationship":"author","author_order":5,"organization_at_source_time":"University of Illinois Urbana-Champaign","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["United States"],"operating_markets":[],"languages":[],"expertise_topics":["AI red-teaming agents","zero-day vulnerability evaluation"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-008"],"source_ids":["source-BATCH-2026-005-008"],"statement_ids":["statement-BATCH-2026-006-033","statement-BATCH-2026-006-034","statement-BATCH-2026-006-035","statement-BATCH-2026-006-036","statement-BATCH-2026-006-037","statement-BATCH-2026-006-038"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_and_authorship_verified_current_role_unresolved_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://siebelschool.illinois.edu/research/undergraduate-research/summer-research-experience-undergraduates/participants/Richard-Fang","accessed_at":"2026-08-15","retrieval_method":"official institutional profile review","exact_locator":"2024 research participant — UIUC, freshman, faculty mentor Daniel Kang","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Verifies source-era identity but is not fresh enough to establish a current role."},{"source_url":"https://openreview.net/profile?id=~Richard_Fang1","accessed_at":"2026-08-15","retrieval_method":"public scholarly identity profile review","exact_locator":"Career & Education History — UIUC undergraduate, 2023–2027","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Conflicts with a newer self-maintained professional profile indicating Stanford education; exact present role held unresolved."},{"source_url":"https://arxiv.org/abs/2406.01637","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"arXiv v2 submitted 2025-03-30; byline/contributor relationship and source-time affiliation","content_hash":"f4fc06040f0856d99d2009042b4c6fa0c01206da8ca61cb39a94d52b9867cf71","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-tobin-south","canonical_name":"Tobin South","display_name":"Tobin South","alternate_names":["T. South"],"name_disambiguation_note":"The lead editor/first author of the indexed OpenID Foundation report and its arXiv rendition; MIT records show a 2025 PhD completion.","external_identifiers":{"official_profile_url":"https://digitaleconomy.stanford.edu/person/tobin-south/"},"current_role":"Research Fellow","current_organization_reference":"Stanford University","current_role_source":"https://digitaleconomy.stanford.edu/person/tobin-south/","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_official_university_profile_checked_2026-08-15","historical_roles":[{"person_id":"person-BATCH-2026-005-tobin-south","source_id":"source-BATCH-2026-005-004","source_title":"Identity Management for Agentic AI","source_version":"October 2025 official OpenID Foundation report","relationship":"lead_editor","author_order":1,"organization_at_source_time":"not reported","role_at_source_time":"Lead editor","verification_basis":"PDF title or contributor page","verification_status":"relationship_verified_affiliation_not_reported","current_role_backfilled":false,"human_review_status":"approved"},{"person_id":"person-BATCH-2026-005-tobin-south","source_id":"source-idac-390-agentic-ai-identity","source_title":"#390 - Identity Management for Agentic AI with Tobin South","source_version":"Podcast episode published 2025-12-08","relationship":"speaker","author_order":null,"organization_at_source_time":"OpenID Foundation","role_at_source_time":"Co-chair, OpenID Foundation Artificial Intelligence Identity Management Community Group","verification_basis":"Official publisher context and in-recording identification","verification_status":"verified","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-tobin-south","source_id":"source-BATCH-2026-005-004","source_title":"Identity Management for Agentic AI","source_version":"October 2025 official OpenID Foundation report","relationship":"lead_editor","author_order":1,"organization_at_source_time":"not reported","role_at_source_time":"Lead editor","verification_basis":"PDF title or contributor page","verification_status":"relationship_verified_affiliation_not_reported","current_role_backfilled":false,"human_review_status":"approved"},{"person_id":"person-BATCH-2026-005-tobin-south","source_id":"source-idac-390-agentic-ai-identity","source_title":"#390 - Identity Management for Agentic AI with Tobin South","source_version":"Podcast episode published 2025-12-08","relationship":"speaker","author_order":null,"organization_at_source_time":"OpenID Foundation","role_at_source_time":"Co-chair, OpenID Foundation Artificial Intelligence Identity Management Community Group","verification_basis":"Official publisher context and in-recording identification","verification_status":"verified","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["United States"],"operating_markets":[],"languages":[],"expertise_topics":["AI agent identity","authenticated delegation","AI-agent auditability"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-004","source-idac-390-agentic-ai-identity"],"source_ids":["source-BATCH-2026-005-004","source-idac-390-agentic-ai-identity"],"statement_ids":["statement-BATCH-2026-006-015","statement-BATCH-2026-006-016","statement-BATCH-2026-006-017","statement-BATCH-2026-006-018","statement-BATCH-2026-006-019","statement-BATCH-2026-006-020","statement-BATCH-2026-006-021","statement-BATCH-2026-004-001","statement-BATCH-2026-004-002","statement-BATCH-2026-004-003","statement-BATCH-2026-004-004","statement-BATCH-2026-004-005","statement-BATCH-2026-004-006","statement-BATCH-2026-004-007","statement-BATCH-2026-004-008","statement-BATCH-2026-004-009","statement-BATCH-2026-004-010"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_authorship_and_current_role_machine_verified_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://digitaleconomy.stanford.edu/person/tobin-south/","accessed_at":"2026-08-15","retrieval_method":"official institutional/company page or self-authored professional CV reviewed on the public web","exact_locator":"Profile heading — Research Fellow, Stanford University","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Current-role evidence; named human review pending."},{"source_url":"https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"October 2025 official OpenID Foundation report; byline/contributor relationship and source-time affiliation","content_hash":"e6a0e5909fcb2486568180f69d511ae2af8d20a1bfb3028b39b3d1072846f4f3","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-yongfeng-zhang","canonical_name":"Yongfeng Zhang","display_name":"Yongfeng Zhang","alternate_names":["Y. Zhang"],"name_disambiguation_note":"The Rutgers faculty member and eighth author of Agent Security Bench, not another researcher named Yongfeng Zhang.","external_identifiers":{"official_profile_url":"https://www.cs.rutgers.edu/people/professors/details/yongfeng-zhang"},"current_role":"Associate Professor, Director of the Master Program","current_organization_reference":"Rutgers University","current_role_source":"https://www.cs.rutgers.edu/people/professors/details/yongfeng-zhang","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_official_university_profile_checked_2026-08-15","historical_roles":[{"person_id":"person-BATCH-2026-005-yongfeng-zhang","source_id":"source-BATCH-2026-005-007","source_title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","source_version":"arXiv v4; ICLR 2025","relationship":"author","author_order":8,"organization_at_source_time":"Rutgers University","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-yongfeng-zhang","source_id":"source-BATCH-2026-005-007","source_title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","source_version":"arXiv v4; ICLR 2025","relationship":"author","author_order":8,"organization_at_source_time":"Rutgers University","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["United States"],"operating_markets":[],"languages":[],"expertise_topics":["AI agent security benchmarking","agent attack and defense evaluation"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-007"],"source_ids":["source-BATCH-2026-005-007"],"statement_ids":["statement-BATCH-2026-006-028","statement-BATCH-2026-006-029","statement-BATCH-2026-006-030","statement-BATCH-2026-006-031","statement-BATCH-2026-006-032"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_authorship_and_current_role_machine_verified_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.cs.rutgers.edu/people/professors/details/yongfeng-zhang","accessed_at":"2026-08-15","retrieval_method":"official institutional/company page or self-authored professional CV reviewed on the public web","exact_locator":"Faculty Details — Associate Professor, Director of the Master Program","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Current-role evidence; named human review pending."},{"source_url":"https://arxiv.org/abs/2410.02644","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"arXiv v4; ICLR 2025; byline/contributor relationship and source-time affiliation","content_hash":"e20155df01b3a1f6c0a947c4e9e4871957cff2e507939f7ea21a5fe967d84504","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-BATCH-2026-005-yuxuan-zhu","canonical_name":"Yuxuan Zhu","display_name":"Yuxuan Zhu","alternate_names":["Y. Zhu"],"name_disambiguation_note":"The first author of the indexed HPTSA paper and Daniel Kang advisee at the University of Illinois Urbana-Champaign.","external_identifiers":{"personal_cv_url":"https://yuxuan18.github.io/assets/cv.pdf"},"current_role":"PhD Student in Computer Science","current_organization_reference":"University of Illinois Urbana-Champaign","current_role_source":"https://yuxuan18.github.io/assets/cv.pdf","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_self_authored_cv_checked_2026-08-15","historical_roles":[{"person_id":"person-BATCH-2026-005-yuxuan-zhu","source_id":"source-BATCH-2026-005-008","source_title":"Teams of LLM Agents Can Exploit Zero-Day Vulnerabilities","source_version":"arXiv v2 submitted 2025-03-30","relationship":"author","author_order":1,"organization_at_source_time":"University of Illinois Urbana-Champaign","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"role_at_source_time":[{"person_id":"person-BATCH-2026-005-yuxuan-zhu","source_id":"source-BATCH-2026-005-008","source_title":"Teams of LLM Agents Can Exploit Zero-Day Vulnerabilities","source_version":"arXiv v2 submitted 2025-03-30","relationship":"author","author_order":1,"organization_at_source_time":"University of Illinois Urbana-Champaign","role_at_source_time":"Author","verification_basis":"PDF title or contributor page","verification_status":"verified_from_source_byline_and_affiliation","current_role_backfilled":false,"human_review_status":"approved"}],"professional_geographies":["United States"],"operating_markets":[],"languages":[],"expertise_topics":["AI red-teaming agents","zero-day vulnerability evaluation"],"authored_book_work_ids":[],"contributed_work_ids":["source-BATCH-2026-005-008"],"source_ids":["source-BATCH-2026-005-008"],"statement_ids":["statement-BATCH-2026-006-033","statement-BATCH-2026-006-034","statement-BATCH-2026-006-035","statement-BATCH-2026-006-036","statement-BATCH-2026-006-037","statement-BATCH-2026-006-038"],"proposition_relationships":[],"relationship_to_off":"none_identified","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_authorship_and_current_role_machine_verified_human_approved","person_depth":"source_connected_dataset_only","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://yuxuan18.github.io/assets/cv.pdf","accessed_at":"2026-08-15","retrieval_method":"official institutional/company page or self-authored professional CV reviewed on the public web","exact_locator":"CV p. 1, Education — UIUC PhD, Aug. 2023–present; dated March 1, 2026","content_hash":null,"batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Current-role evidence; named human review pending."},{"source_url":"https://arxiv.org/abs/2406.01637","accessed_at":"2026-08-15","retrieval_method":"inherited verified source metadata and author relationship cross-check","exact_locator":"arXiv v2 submitted 2025-03-30; byline/contributor relationship and source-time affiliation","content_hash":"f4fc06040f0856d99d2009042b4c6fa0c01206da8ca61cb39a94d52b9867cf71","batch_id":"BATCH-2026-007","prompt_id":"OEII-PERSON-RESEARCH","prompt_version":"2.0","notes":"Relationship inherited from BATCH-2026-005 and rechecked for this person batch; named human review pending."}],"revision_history":[{"changed_at":"2026-08-15T22:30:00Z","changed_by":"OpenAI Codex","summary":"Created staging person record with identity disambiguation, source-time role separation, current-role verification, and intellectual-contribution links.","batch_id":"BATCH-2026-007"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-007"}]}
{"entity_type":"person","person_id":"person-jeff-steadman","canonical_name":"Jeff Steadman","display_name":"Jeff Steadman","alternate_names":[],"name_disambiguation_note":"Identity at the Center co-host and RSM digital identity consulting leader.","external_identifiers":{"linkedin":"https://www.linkedin.com/in/jeffsteadman/"},"current_role":"Leader, Digital Identity consulting practice","current_organization_reference":"orgref-rsm","current_role_source":"https://www.identityatthecenter.com/about","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_official_profile","historical_roles":[],"role_at_source_time":[{"source_id":"source-idac-390-agentic-ai-identity","role":"Co-host and interviewer","organization_reference":"orgref-idac"}],"professional_geographies":[],"operating_markets":["geo-global"],"languages":["lang-en"],"expertise_topics":["topic-cybersecurity","topic-non-human-identity"],"authored_book_work_ids":[],"contributed_work_ids":[],"source_ids":["source-idac-390-agentic-ai-identity"],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_and_current_role_verified","person_depth":"metadata","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.identityatthecenter.com/about","accessed_at":"2026-08-15","retrieval_method":"official podcast about page and audio self-identification","exact_locator":"The Hosts; episode 00:10-00:16","content_hash":null,"batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"person","person_id":"person-jim-mcdonald","canonical_name":"Jim McDonald","display_name":"Jim McDonald","alternate_names":[],"name_disambiguation_note":"Identity at the Center co-host and RSM digital identity leader.","external_identifiers":{"linkedin":"https://www.linkedin.com/in/jimmcdonaldpmp/"},"current_role":"Leader, Digital Identity Advisory Services","current_organization_reference":"orgref-rsm","current_role_source":"https://www.identityatthecenter.com/about","current_role_verified_at":"2026-08-15","current_role_freshness_status":"current_official_profile","historical_roles":[],"role_at_source_time":[{"source_id":"source-idac-390-agentic-ai-identity","role":"Co-host and interviewer","organization_reference":"orgref-idac"}],"professional_geographies":[],"operating_markets":["geo-global"],"languages":["lang-en"],"expertise_topics":["topic-cybersecurity","topic-non-human-identity"],"authored_book_work_ids":[],"contributed_work_ids":[],"source_ids":["source-idac-390-agentic-ai-identity"],"statement_ids":[],"proposition_relationships":[],"relationship_to_off":"none","disclosure":null,"public_profile_eligibility":false,"verification_status":"identity_and_current_role_verified","person_depth":"metadata","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.identityatthecenter.com/about","accessed_at":"2026-08-15","retrieval_method":"official podcast about page and audio self-identification","exact_locator":"The Hosts; episode 00:10-00:16","content_hash":null,"batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"source","source_id":"related-source-BATCH-2026-002-002","canonical_title":"Zero Trust Networks — Audiobook","alternate_titles":[],"source_type":"audiobook","series_or_parent_source":null,"publisher":"Ascent Audio / O’Reilly","channel":null,"speaker_ids":[],"author_ids":[],"institutional_author":"Ascent Audio / O’Reilly","organization_references":[],"recorded_at":null,"event_date":null,"published_at":null,"updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["geo-global"],"study_geography":[],"original_url":"https://www.oreilly.com/library/view/zero-trust-networks/9781663735591/","canonical_url":"https://www.oreilly.com/library/view/zero-trust-networks/9781663735591/","archived_url":null,"embed_url":null,"doi":null,"canonical_identity_status":"machine_verified_human_pending","repost_status":"original_or_official","original_source_id":null,"rights_status":"metadata_only","ownership_status":"third_party","relationship_to_off":"none_identified","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"official_metadata","topics":["governed-agent-identities","book-related-source"],"executive_roles":["role-ciso","role-cio","role-cto"],"original_abstract":null,"inclusion_rationale":"Related format and narrator metadata for book-work-BATCH-2026-002-002.","source_quality_dimensions":{"primary_source":true,"bibliographic_stability":"high"},"methodology_quality":{"not_applicable":true},"study_design":null,"sample":{},"population":null,"date_range":{},"funding":null,"sponsor":null,"peer_review_status":null,"findings":[],"limitations":["Candidate related source only; not accepted for statement extraction."],"correction_ids":[],"retraction_status":null,"content_hash":null,"accessed_at":"2026-08-15","verification_status":"machine_verified_human_approved","source_depth":"metadata_only","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/zero-trust-networks/9781663735591/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official related-source page","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Related format and narrator metadata for book-work-BATCH-2026-002-002."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"source","source_id":"related-source-BATCH-2026-002-003","canonical_title":"OAuth 2 in Action — Authorized Chapter 1 Preview","alternate_titles":[],"source_type":"other_approved","series_or_parent_source":null,"publisher":"Manning Publications","channel":null,"speaker_ids":[],"author_ids":[],"institutional_author":"Manning Publications","organization_references":[],"recorded_at":null,"event_date":null,"published_at":null,"updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["geo-global"],"study_geography":[],"original_url":"https://www.manning.com/preview/oauth-2-in-action/chapter-1","canonical_url":"https://www.manning.com/preview/oauth-2-in-action/chapter-1","archived_url":null,"embed_url":null,"doi":null,"canonical_identity_status":"machine_verified_human_pending","repost_status":"original_or_official","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"authorized_preview","topics":["governed-agent-identities","book-related-source"],"executive_roles":["role-ciso","role-cio","role-cto"],"original_abstract":null,"inclusion_rationale":"Limited authorized preview related to book-work-BATCH-2026-002-003.","source_quality_dimensions":{"primary_source":true,"bibliographic_stability":"high"},"methodology_quality":{"not_applicable":true},"study_design":null,"sample":{},"population":null,"date_range":{},"funding":null,"sponsor":null,"peer_review_status":null,"findings":[],"limitations":["Candidate related source only; not accepted for statement extraction."],"correction_ids":[],"retraction_status":null,"content_hash":null,"accessed_at":"2026-08-15","verification_status":"machine_verified_human_approved","source_depth":"metadata_only","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.manning.com/preview/oauth-2-in-action/chapter-1","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official related-source page","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Limited authorized preview related to book-work-BATCH-2026-002-003."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"source","source_id":"related-source-BATCH-2026-002-004","canonical_title":"API Security in Action — Official Contents","alternate_titles":[],"source_type":"other_approved","series_or_parent_source":null,"publisher":"Manning Publications","channel":null,"speaker_ids":[],"author_ids":[],"institutional_author":"Manning Publications","organization_references":[],"recorded_at":null,"event_date":null,"published_at":null,"updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["geo-global"],"study_geography":[],"original_url":"https://livebook.manning.com/book/api-security-in-action/contents","canonical_url":"https://livebook.manning.com/book/api-security-in-action/contents","archived_url":null,"embed_url":null,"doi":null,"canonical_identity_status":"machine_verified_human_pending","repost_status":"original_or_official","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"table_of_contents_only","topics":["governed-agent-identities","book-related-source"],"executive_roles":["role-ciso","role-cio","role-cto"],"original_abstract":null,"inclusion_rationale":"Official contents related to book-work-BATCH-2026-002-004.","source_quality_dimensions":{"primary_source":true,"bibliographic_stability":"high"},"methodology_quality":{"not_applicable":true},"study_design":null,"sample":{},"population":null,"date_range":{},"funding":null,"sponsor":null,"peer_review_status":null,"findings":[],"limitations":["Candidate related source only; not accepted for statement extraction."],"correction_ids":[],"retraction_status":null,"content_hash":null,"accessed_at":"2026-08-15","verification_status":"machine_verified_human_approved","source_depth":"metadata_only","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://livebook.manning.com/book/api-security-in-action/contents","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official related-source page","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Official contents related to book-work-BATCH-2026-002-004."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"source","source_id":"related-source-BATCH-2026-002-005","canonical_title":"Introducing our new book Building Secure and Reliable Systems","alternate_titles":[],"source_type":"essay","series_or_parent_source":null,"publisher":"Google Security Blog","channel":null,"speaker_ids":[],"author_ids":[],"institutional_author":"Google Security Blog","organization_references":[],"recorded_at":null,"event_date":null,"published_at":"2020-04-08","updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["geo-global"],"study_geography":[],"original_url":"https://security.googleblog.com/2020/04/introducing-our-new-book-building.html","canonical_url":"https://security.googleblog.com/2020/04/introducing-our-new-book-building.html","archived_url":null,"embed_url":null,"doi":null,"canonical_identity_status":"machine_verified_human_pending","repost_status":"original_or_official","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"official_description","topics":["governed-agent-identities","book-related-source"],"executive_roles":["role-ciso","role-cio","role-cto"],"original_abstract":null,"inclusion_rationale":"Official launch essay related to book-work-BATCH-2026-002-005.","source_quality_dimensions":{"primary_source":true,"bibliographic_stability":"high"},"methodology_quality":{"not_applicable":true},"study_design":null,"sample":{},"population":null,"date_range":{},"funding":null,"sponsor":null,"peer_review_status":null,"findings":[],"limitations":["Candidate related source only; not accepted for statement extraction."],"correction_ids":[],"retraction_status":null,"content_hash":null,"accessed_at":"2026-08-15","verification_status":"machine_verified_human_approved","source_depth":"metadata_only","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://security.googleblog.com/2020/04/introducing-our-new-book-building.html","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official related-source page","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Official launch essay related to book-work-BATCH-2026-002-005."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"source","source_id":"related-source-BATCH-2026-002-006","canonical_title":"Learn to build secure and reliable systems with a new book from Google","alternate_titles":[],"source_type":"essay","series_or_parent_source":null,"publisher":"Google Cloud Blog","channel":null,"speaker_ids":[],"author_ids":[],"institutional_author":"Google Cloud Blog","organization_references":[],"recorded_at":null,"event_date":null,"published_at":"2020-04-08","updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["geo-global"],"study_geography":[],"original_url":"https://cloud.google.com/blog/products/management-tools/learn-to-build-secure-and-reliable-systems-with-a-new-book-from-google","canonical_url":"https://cloud.google.com/blog/products/management-tools/learn-to-build-secure-and-reliable-systems-with-a-new-book-from-google","archived_url":null,"embed_url":null,"doi":null,"canonical_identity_status":"machine_verified_human_pending","repost_status":"original_or_official","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"official_description","topics":["governed-agent-identities","book-related-source"],"executive_roles":["role-ciso","role-cio","role-cto"],"original_abstract":null,"inclusion_rationale":"Author launch essay related to book-work-BATCH-2026-002-005.","source_quality_dimensions":{"primary_source":true,"bibliographic_stability":"high"},"methodology_quality":{"not_applicable":true},"study_design":null,"sample":{},"population":null,"date_range":{},"funding":null,"sponsor":null,"peer_review_status":null,"findings":[],"limitations":["Candidate related source only; not accepted for statement extraction."],"correction_ids":[],"retraction_status":null,"content_hash":null,"accessed_at":"2026-08-15","verification_status":"machine_verified_human_approved","source_depth":"metadata_only","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://cloud.google.com/blog/products/management-tools/learn-to-build-secure-and-reliable-systems-with-a-new-book-from-google","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official related-source page","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Author launch essay related to book-work-BATCH-2026-002-005."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"source","source_id":"related-source-BATCH-2026-002-007","canonical_title":"Identity in Modern Applications — Official Contents and Preview","alternate_titles":[],"source_type":"other_approved","series_or_parent_source":null,"publisher":"O’Reilly Media, Inc.","channel":null,"speaker_ids":[],"author_ids":[],"institutional_author":"O’Reilly Media, Inc.","organization_references":[],"recorded_at":null,"event_date":null,"published_at":null,"updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["geo-global"],"study_geography":[],"original_url":"https://www.oreilly.com/library/view/identity-in-modern/9781098107789/","canonical_url":"https://www.oreilly.com/library/view/identity-in-modern/9781098107789/","archived_url":null,"embed_url":null,"doi":null,"canonical_identity_status":"machine_verified_human_pending","repost_status":"original_or_official","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"authorized_preview","topics":["governed-agent-identities","book-related-source"],"executive_roles":["role-ciso","role-cio","role-cto"],"original_abstract":null,"inclusion_rationale":"Official preview related to book-work-BATCH-2026-002-006.","source_quality_dimensions":{"primary_source":true,"bibliographic_stability":"high"},"methodology_quality":{"not_applicable":true},"study_design":null,"sample":{},"population":null,"date_range":{},"funding":null,"sponsor":null,"peer_review_status":null,"findings":[],"limitations":["Candidate related source only; not accepted for statement extraction."],"correction_ids":[],"retraction_status":null,"content_hash":null,"accessed_at":"2026-08-15","verification_status":"machine_verified_human_approved","source_depth":"metadata_only","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/identity-in-modern/9781098107789/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official related-source page","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Official preview related to book-work-BATCH-2026-002-006."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"source","source_id":"related-source-BATCH-2026-002-009","canonical_title":"Identity-Native Infrastructure Access Management — Preface","alternate_titles":[],"source_type":"other_approved","series_or_parent_source":null,"publisher":"O’Reilly Media, Inc.","channel":null,"speaker_ids":[],"author_ids":[],"institutional_author":"O’Reilly Media, Inc.","organization_references":[],"recorded_at":null,"event_date":null,"published_at":null,"updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["geo-global"],"study_geography":[],"original_url":"https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/preface01.html","canonical_url":"https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/preface01.html","archived_url":null,"embed_url":null,"doi":null,"canonical_identity_status":"machine_verified_human_pending","repost_status":"original_or_official","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"authorized_preview","topics":["governed-agent-identities","book-related-source"],"executive_roles":["role-ciso","role-cio","role-cto"],"original_abstract":null,"inclusion_rationale":"Official preface related to book-work-BATCH-2026-002-009.","source_quality_dimensions":{"primary_source":true,"bibliographic_stability":"high"},"methodology_quality":{"not_applicable":true},"study_design":null,"sample":{},"population":null,"date_range":{},"funding":null,"sponsor":null,"peer_review_status":null,"findings":[],"limitations":["Candidate related source only; not accepted for statement extraction."],"correction_ids":[],"retraction_status":null,"content_hash":null,"accessed_at":"2026-08-15","verification_status":"machine_verified_human_approved","source_depth":"metadata_only","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.oreilly.com/library/view/identity-native-infrastructure-access/9781098131883/preface01.html","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official related-source page","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Official preface related to book-work-BATCH-2026-002-009."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"source","source_id":"related-source-BATCH-2026-002-010","canonical_title":"Building Secure and Reliable Systems — Official Complete HTML","alternate_titles":[],"source_type":"other_approved","series_or_parent_source":null,"publisher":"Google","channel":null,"speaker_ids":[],"author_ids":[],"institutional_author":"Google","organization_references":[],"recorded_at":null,"event_date":null,"published_at":null,"updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["geo-global"],"study_geography":[],"original_url":"https://google.github.io/building-secure-and-reliable-systems/","canonical_url":"https://google.github.io/building-secure-and-reliable-systems/","archived_url":null,"embed_url":null,"doi":null,"canonical_identity_status":"machine_verified_human_pending","repost_status":"original_or_official","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"full_text_lawfully_accessed","topics":["governed-agent-identities","book-related-source"],"executive_roles":["role-ciso","role-cio","role-cto"],"original_abstract":null,"inclusion_rationale":"Official complete text access point; reuse license not established.","source_quality_dimensions":{"primary_source":true,"bibliographic_stability":"high"},"methodology_quality":{"not_applicable":true},"study_design":null,"sample":{},"population":null,"date_range":{},"funding":null,"sponsor":null,"peer_review_status":null,"findings":[],"limitations":["Candidate related source only; not accepted for statement extraction."],"correction_ids":[],"retraction_status":null,"content_hash":null,"accessed_at":"2026-08-15","verification_status":"machine_verified_human_approved","source_depth":"metadata_only","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/","accessed_at":"2026-08-15","retrieval_method":"Official publisher, project, or author-hosted bibliographic page inspected through public web access","exact_locator":"Official related-source page","content_hash":null,"batch_id":"BATCH-2026-002","prompt_id":"OEII-BOOK-METADATA","prompt_version":"2.0","notes":"Official complete text access point; reuse license not established."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-002"}]}
{"entity_type":"release","release_id":"release-0.2.0-governed-identities-pilot","semantic_version":"0.2.0","schema_version":"1.0.0","data_version":"1.0.0","content_version":"0.2.0","release_date":"2026-08-16","included_batch_ids":["BUILD-2026-08-14-001","BATCH-2026-001","BATCH-2026-002","BATCH-2026-003","BATCH-2026-004","BATCH-2026-005","BATCH-2026-006","BATCH-2026-007"],"included_record_counts":{"people":48,"book_works":8,"book_editions":11,"sources":20,"statements":100,"propositions":0,"debates":0,"dossiers":0,"trends":0,"reviews":1},"checksums":{"data/people/governed-identities-pilot.json":"bc7b8ab77e350191c4895d38947dfa70f66a8c3b79f39b1d293f1dd365610bfd","data/book-works/governed-identities-pilot.json":"8fc8b239f79469c3fb14c1b84a1e82be857fd70c0fa3f97cb4b4da474ffdc07d","data/book-editions/governed-identities-pilot.json":"d8ebc3a21bf9258a107d82d840026f081505d34db1605fa0f1adcde85cdf9e92","data/sources/governed-identities-pilot.json":"98fc22e01020e73649c248907df4e3e0515b68d7eeb74809dd90355335bd7f12","data/statements/governed-identities-pilot.json":"dfc46a915058d0953b66381f1783a4474d30749fa8b0a1e11dcd3545e20a0f24","data/reviews/governed-identities-pilot.json":"16bb9c5e057372338415cb8afb7677b3a59fef543a2f4f65c43906064aef9e90"},"release_fingerprint":"11cd89598eb4f172e5477e1cc86fd139b70f97cea1a7a3ea3631db077b40ae40","upstream_crosswalk_versions":{},"known_limitations":["This pilot is limited to governed identities for AI agents and is not representative of all executives, roles, industries, regions, or markets.","The corpus is substantially English-language and source-concentrated.","Inclusion does not imply endorsement, prevalence, adoption, consensus, or truth.","Person records are data-only identity and source-time-role records; no person meets the configured public-profile threshold in this release.","Candidate propositions, debates, dossiers, role comparisons, geographic generalizations, market generalizations, and trends remain unpublished.","Third-party full text, extensive quotations, transcripts, figures, tables, and private information are not republished."],"changelog":["Published the first named-human-approved pilot corpus for governed identities for AI agents.","Published verified works, exact editions, canonical sources, source-located statements, and data-only resolved identity records.","Retained every reviewed exclusion and withheld all higher-order propositions and synthesis."],"approval_status":"APPROVE PILOT PROMOTION","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://github.com/OpenFutureForum/executive-intelligence-index/issues/18#issuecomment-5310177421","accessed_at":"2026-08-16","retrieval_method":"named human approval recorded in the repository issue tracker","exact_locator":"Comment containing approved batches, scope, exclusions, rights decision, limitations, and APPROVE PILOT PROMOTION","content_hash":null,"batch_id":"PILOT-PROMOTION-2026-08-16","prompt_id":"OEII-HUMAN-REVIEW-PROMOTION","prompt_version":"1.0","notes":"The release is valid only for the enumerated production record IDs."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"PILOT-PROMOTION-2026-08-16"}]}
{"entity_type":"review","review_id":"review-governed-identities-pilot-2026-08-16","batch_id":"PILOT-PROMOTION-2026-08-16","record_ids":["book-edition-BATCH-2026-002-001","book-edition-BATCH-2026-002-002","book-edition-BATCH-2026-002-003","book-edition-BATCH-2026-002-005","book-edition-BATCH-2026-002-006","book-edition-BATCH-2026-002-007","book-edition-BATCH-2026-002-008","book-edition-BATCH-2026-002-009","book-edition-BATCH-2026-002-010","book-edition-BATCH-2026-002-011","book-edition-BATCH-2026-002-014","book-work-BATCH-2026-002-001","book-work-BATCH-2026-002-002","book-work-BATCH-2026-002-003","book-work-BATCH-2026-002-004","book-work-BATCH-2026-002-005","book-work-BATCH-2026-002-006","book-work-BATCH-2026-002-007","book-work-BATCH-2026-002-009","person-BATCH-2026-002-001","person-BATCH-2026-002-002","person-BATCH-2026-002-003","person-BATCH-2026-002-004","person-BATCH-2026-002-005","person-BATCH-2026-002-006","person-BATCH-2026-002-007","person-BATCH-2026-002-008","person-BATCH-2026-002-009","person-BATCH-2026-002-010","person-BATCH-2026-002-011","person-BATCH-2026-002-012","person-BATCH-2026-002-013","person-BATCH-2026-002-014","person-BATCH-2026-002-015","person-BATCH-2026-002-016","person-BATCH-2026-002-017","person-BATCH-2026-002-018","person-BATCH-2026-002-019","person-BATCH-2026-002-020","person-BATCH-2026-002-021","person-BATCH-2026-002-022","person-BATCH-2026-002-023","person-BATCH-2026-002-024","person-BATCH-2026-002-025","person-BATCH-2026-002-026","person-BATCH-2026-002-027","person-BATCH-2026-002-028","person-BATCH-2026-002-029","person-BATCH-2026-002-030","person-BATCH-2026-005-alex-pentland","person-BATCH-2026-005-daniel-kang","person-BATCH-2026-005-edoardo-debenedetti","person-BATCH-2026-005-florian-tramer","person-BATCH-2026-005-hanrong-zhang","person-BATCH-2026-005-jie-zhang","person-BATCH-2026-005-jingyuan-huang","person-BATCH-2026-005-kai-mei","person-BATCH-2026-005-luca-beurer-kellner","person-BATCH-2026-005-marc-fischer","person-BATCH-2026-005-mislav-balunovic","person-BATCH-2026-005-richard-fang","person-BATCH-2026-005-tobin-south","person-BATCH-2026-005-yongfeng-zhang","person-BATCH-2026-005-yuxuan-zhu","person-amy-shillinglaw","person-jeff-steadman","person-jim-mcdonald","related-source-BATCH-2026-002-002","related-source-BATCH-2026-002-003","related-source-BATCH-2026-002-004","related-source-BATCH-2026-002-005","related-source-BATCH-2026-002-006","related-source-BATCH-2026-002-007","related-source-BATCH-2026-002-009","related-source-BATCH-2026-002-010","source-BATCH-2026-003-001","source-BATCH-2026-003-002","source-BATCH-2026-005-001","source-BATCH-2026-005-002","source-BATCH-2026-005-003","source-BATCH-2026-005-004","source-BATCH-2026-005-006","source-BATCH-2026-005-007","source-BATCH-2026-005-008","source-BATCH-2026-005-009","source-idac-390-agentic-ai-identity","source-sailpoint-governing-ai-agents-2025","statement-BATCH-2026-003-001","statement-BATCH-2026-003-002","statement-BATCH-2026-003-003","statement-BATCH-2026-003-004","statement-BATCH-2026-003-005","statement-BATCH-2026-003-006","statement-BATCH-2026-003-007","statement-BATCH-2026-003-008","statement-BATCH-2026-003-009","statement-BATCH-2026-003-010","statement-BATCH-2026-003-011","statement-BATCH-2026-003-012","statement-BATCH-2026-003-013","statement-BATCH-2026-003-014","statement-BATCH-2026-003-015","statement-BATCH-2026-003-016","statement-BATCH-2026-003-017","statement-BATCH-2026-003-018","statement-BATCH-2026-003-019","statement-BATCH-2026-003-020","statement-BATCH-2026-003-021","statement-BATCH-2026-003-022","statement-BATCH-2026-003-023","statement-BATCH-2026-003-024","statement-BATCH-2026-003-025","statement-BATCH-2026-003-026","statement-BATCH-2026-003-027","statement-BATCH-2026-003-028","statement-BATCH-2026-003-029","statement-BATCH-2026-003-030","statement-BATCH-2026-003-031","statement-BATCH-2026-003-032","statement-BATCH-2026-003-033","statement-BATCH-2026-003-034","statement-BATCH-2026-003-035","statement-BATCH-2026-003-036","statement-BATCH-2026-004-001","statement-BATCH-2026-004-002","statement-BATCH-2026-004-003","statement-BATCH-2026-004-004","statement-BATCH-2026-004-005","statement-BATCH-2026-004-006","statement-BATCH-2026-004-007","statement-BATCH-2026-004-008","statement-BATCH-2026-004-009","statement-BATCH-2026-004-010","statement-BATCH-2026-004-011","statement-BATCH-2026-004-012","statement-BATCH-2026-004-013","statement-BATCH-2026-004-014","statement-BATCH-2026-004-015","statement-BATCH-2026-004-016","statement-BATCH-2026-004-017","statement-BATCH-2026-004-018","statement-BATCH-2026-006-001","statement-BATCH-2026-006-002","statement-BATCH-2026-006-003","statement-BATCH-2026-006-004","statement-BATCH-2026-006-005","statement-BATCH-2026-006-006","statement-BATCH-2026-006-007","statement-BATCH-2026-006-008","statement-BATCH-2026-006-009","statement-BATCH-2026-006-010","statement-BATCH-2026-006-011","statement-BATCH-2026-006-012","statement-BATCH-2026-006-013","statement-BATCH-2026-006-014","statement-BATCH-2026-006-015","statement-BATCH-2026-006-016","statement-BATCH-2026-006-017","statement-BATCH-2026-006-018","statement-BATCH-2026-006-019","statement-BATCH-2026-006-020","statement-BATCH-2026-006-021","statement-BATCH-2026-006-022","statement-BATCH-2026-006-023","statement-BATCH-2026-006-024","statement-BATCH-2026-006-025","statement-BATCH-2026-006-026","statement-BATCH-2026-006-027","statement-BATCH-2026-006-028","statement-BATCH-2026-006-029","statement-BATCH-2026-006-030","statement-BATCH-2026-006-031","statement-BATCH-2026-006-032","statement-BATCH-2026-006-033","statement-BATCH-2026-006-034","statement-BATCH-2026-006-035","statement-BATCH-2026-006-036","statement-BATCH-2026-006-037","statement-BATCH-2026-006-038","statement-BATCH-2026-006-039","statement-BATCH-2026-006-040","statement-BATCH-2026-006-041","statement-BATCH-2026-006-042","statement-BATCH-2026-006-043","statement-BATCH-2026-006-044","statement-BATCH-2026-006-045","statement-BATCH-2026-006-046"],"review_type":"named_human_pilot_promotion_review","reviewer_type":"human","named_human_reviewer":"Murray Newlands","review_date":"2026-08-16","decisions":[{"decision":"APPROVE PILOT PROMOTION","approval_url":"https://github.com/OpenFutureForum/executive-intelligence-index/issues/18#issuecomment-5310177421","included_batch_ids":["BUILD-2026-08-14-001","BATCH-2026-001","BATCH-2026-002","BATCH-2026-003","BATCH-2026-004","BATCH-2026-005","BATCH-2026-006","BATCH-2026-007"]}],"corrections":[],"disagreements":[],"unresolved_issues":[],"rights_review":{"decision":"approved_link_and_paraphrase_only","excluded_material":["third-party full text","extensive quotations","transcripts","figures","tables","private information"]},"publication_recommendation":"approved_for_pilot_publication_with_recorded_exclusions_and_limitations","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://github.com/OpenFutureForum/executive-intelligence-index/issues/18#issuecomment-5310177421","accessed_at":"2026-08-16","retrieval_method":"named human approval recorded in the repository issue tracker","exact_locator":"Comment containing APPROVE PILOT PROMOTION","content_hash":null,"batch_id":"PILOT-PROMOTION-2026-08-16","prompt_id":"OEII-HUMAN-REVIEW-PROMOTION","prompt_version":"1.0","notes":"Approval is limited to the exact record IDs in this review record."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"PILOT-PROMOTION-2026-08-16"}]}
{"entity_type":"source","source_id":"source-BATCH-2026-003-001","canonical_title":"Solving the Bottom Turtle: A SPIFFE Way to Establish Trust in Your Infrastructure via Universal Identity","alternate_titles":["Solving the Bottom Turtle"],"source_type":"book","series_or_parent_source":null,"publisher":"SPIFFE Project","channel":null,"speaker_ids":[],"author_ids":["person-BATCH-2026-002-001","person-BATCH-2026-002-002","person-BATCH-2026-002-003","person-BATCH-2026-002-004","person-BATCH-2026-002-005","person-BATCH-2026-002-006","person-BATCH-2026-002-007","person-BATCH-2026-002-008","person-BATCH-2026-002-009","person-BATCH-2026-002-010","person-BATCH-2026-002-011","person-BATCH-2026-002-012"],"institutional_author":null,"organization_references":[],"recorded_at":null,"event_date":null,"published_at":"2020-11-17","updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":["United States"],"geography_discussed":["Global distributed infrastructure"],"study_geography":[],"original_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf","canonical_url":"https://spiffe.io/book/","archived_url":null,"embed_url":null,"doi":null,"canonical_identity_status":"Exact first edition verified by title page, ISBN, publisher, date, format, pagination, and SHA-256","repost_status":null,"original_source_id":null,"rights_status":"openly_licensed","ownership_status":"third_party","relationship_to_off":null,"transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[{"chapter":1},{"chapter":2},{"chapter":3},{"chapter":4},{"chapter":5},{"chapter":6},{"chapter":7},{"chapter":8},{"chapter":9},{"chapter":10}],"analysis_basis":"Complete 194-page official PDF read in full","topics":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_roles":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"original_abstract":"A practitioner book explaining SPIFFE and SPIRE as an architecture for workload identity, attestation, trust domains, deployment, integration, authorization, and operational adoption.","inclusion_rationale":"Directly addresses machine and workload identity—the technical substrate most closely adjacent to governed AI-agent identity—while exposing where identity ends and authorization begins.","source_quality_dimensions":{"authority":"Project-authored primary technical source","completeness":"Complete exact edition","independence":"Low; authors are project participants","reproducibility":"High; official PDF and page locators"},"methodology_quality":{"design":"Practitioner synthesis and technical argument","causal_strength":"Low","transparency":"Threat assumptions and design tradeoffs are usually explicit"},"study_design":"Technical architecture and practitioner case synthesis","sample":{"case_studies":5},"population":"Distributed infrastructure operators and service workloads","date_range":{"edition":"2020"},"funding":null,"sponsor":"SPIFFE Project","peer_review_status":"No formal academic peer review identified","findings":[],"limitations":["The case evidence is self-reported and does not isolate SPIFFE or SPIRE as the cause of the reported outcomes.","The book is written by project participants and sometimes moves from design argument to ecosystem advocacy.","Its workload identity model does not by itself encode an AI agent's sponsor, delegation chain, task purpose, model, session, or decision provenance.","The 2020 edition predates later token formats, wider platform support, current AI-agent systems, and subsequent identity standards work."],"correction_ids":[],"retraction_status":null,"content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","accessed_at":"2026-08-15","verification_status":"machine_verified_human_approved","source_depth":"complete_edition_deep_analysis","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Complete PDF pages 1–194","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"No direct quotations stored"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"source","source_id":"source-BATCH-2026-003-002","canonical_title":"Building Secure and Reliable Systems: Best Practices for Designing, Implementing, and Maintaining Systems","alternate_titles":["Building Secure & Reliable Systems"],"source_type":"book","series_or_parent_source":null,"publisher":"O’Reilly Media, Inc.","channel":null,"speaker_ids":[],"author_ids":["person-BATCH-2026-002-019","person-BATCH-2026-002-020","person-BATCH-2026-002-021","person-BATCH-2026-002-022","person-BATCH-2026-002-023","person-BATCH-2026-002-024"],"institutional_author":null,"organization_references":[],"recorded_at":null,"event_date":null,"published_at":"2020-04-08","updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":["United States"],"geography_discussed":["Global large-scale technology operations"],"study_geography":[],"original_url":"https://google.github.io/building-secure-and-reliable-systems/","canonical_url":"https://www.oreilly.com/library/view/building-secure-and/9781492083115/","archived_url":null,"embed_url":null,"doi":null,"canonical_identity_status":"Exact first online edition verified by title, ISBN, publisher, publication date, pagination, official content manifest, and normalized text hash","repost_status":null,"original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":null,"transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[{"chapter":1},{"chapter":2},{"chapter":3},{"chapter":4},{"chapter":5},{"chapter":6},{"chapter":7},{"chapter":8},{"chapter":9},{"chapter":10},{"chapter":11},{"chapter":12},{"chapter":13},{"chapter":14},{"chapter":15},{"chapter":16},{"chapter":17},{"chapter":18},{"chapter":19},{"chapter":20},{"chapter":21},{"chapter":22}],"analysis_basis":"Complete official first-edition HTML: 35 files and 176,914 normalized words read in full","topics":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_roles":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"original_abstract":"A multi-author practitioner volume integrating security and reliability across design, implementation, deployment, incident response, recovery, organization, and culture.","inclusion_rationale":"Provides governance patterns for least privilege, contextual authorization, artifact provenance, auditability, recovery, and organizational accountability that can be carefully adapted to AI agents.","source_quality_dimensions":{"authority":"Primary practitioner source from named Google and industry contributors","completeness":"Complete exact edition","independence":"Moderate to low; many examples concern the authors' employer","reproducibility":"High; stable official chapter and section URLs"},"methodology_quality":{"design":"Multi-author practitioner synthesis","causal_strength":"Low to moderate for design reasoning; low for generalized outcomes","transparency":"Tradeoffs are commonly stated; case selection is not systematic"},"study_design":"Practitioner guidance, technical examples, incident narratives, and case studies","sample":{"chapters":22,"content_files":35},"population":"Large-scale software and infrastructure organizations","date_range":{"edition":"2020"},"funding":null,"sponsor":"Google","peer_review_status":"Editorially reviewed technical book; no formal academic peer review identified","findings":[],"limitations":["Many recommendations reflect Google's scale, staffing, engineering maturity, and ability to build custom control planes.","The chapter evidence is primarily practitioner experience rather than externally replicated causal analysis.","The book predates modern general-purpose AI agents and does not define sponsor, delegation, session, model, tool-purpose, or decision-provenance identity fields.","Privacy, legal process, and geography are acknowledged but not developed into jurisdiction-specific operating models."],"correction_ids":[],"retraction_status":null,"content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","accessed_at":"2026-08-15","verification_status":"machine_verified_human_approved","source_depth":"complete_edition_deep_analysis","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"All 35 official HTML files; chapter/section anchors","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Manifest hash ae702b4e64364217f179317b4a46de6a5e7c51045a79efa67522245d76667e16; no direct quotations stored"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"source","source_id":"source-BATCH-2026-005-001","canonical_title":"Summary Analysis of Responses to the Request for Information Regarding Security Considerations for AI Agents","alternate_titles":[],"source_type":"research_report","series_or_parent_source":"NIST AI 800-5","publisher":"National Institute of Standards and Technology","channel":null,"speaker_ids":[],"author_ids":["person-BATCH-2026-005-jared-riggs","person-BATCH-2026-005-maia-hamin","person-BATCH-2026-005-neil-perry","person-BATCH-2026-005-benjamin-edelman","person-BATCH-2026-005-peter-cihon"],"institutional_author":"NIST Center for AI Standards and Innovation","organization_references":[],"recorded_at":null,"event_date":null,"published_at":"2026-05-18","updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["United States","global issues discussed"],"study_geography":["United States","global issues discussed"],"original_url":"https://www.nist.gov/publications/summary-analysis-responses-request-information-regarding-security-considerations-ai","canonical_url":"https://www.nist.gov/publications/summary-analysis-responses-request-information-regarding-security-considerations-ai","archived_url":null,"embed_url":null,"doi":null,"canonical_identity_status":"verified","repost_status":"original_or_authoritative_rendition","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified; Executive AI Research snapshot contains no matching production records","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"Official NIST publication page and its analytical abstract reviewed; no full report file was exposed by the canonical page.","topics":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_roles":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"original_abstract":null,"inclusion_rationale":"Accepted discovery candidate candidate-BATCH-2026-001-005; contributes government report evidence or normative context to governed AI-agent identity.","source_quality_dimensions":{"attribution_strength":"high","methodological_transparency":"low_for_accessible_version","independence":"government_publisher","bibliographic_stability":"high","evidence_strength":"moderate_for_describing_commenter_themes_not_population_prevalence","unresolved":"Full report body and response-level method were not available from the canonical page."},"methodology_quality":{"design":"qualitative synthesis of responses to a U.S. government request for information","transparency":"low_for_accessible_version","human_review_required":true},"study_design":"qualitative synthesis of responses to a U.S. government request for information","sample":{"size":"not reported on the canonical publication page","sampling_method":"self-selected RFI respondents; response recruitment and inclusion process not reported on the canonical page"},"population":"organizations and individuals responding to the CAISI RFI; composition not reported","date_range":{"fieldwork":"not reported","version":"official HTML publication page accessed 2026-08-15"},"funding":"U.S. government publication; separate research funding not reported","sponsor":"National Institute of Standards and Technology","peer_review_status":"not applicable; government report","findings":["The authors report broad agreement among commenters that agent security creates adoption barriers and requires adaptation of established cybersecurity practice."],"limitations":["No disclosed denominator, response composition, or qualitative coding method on the accessible page.","RFI respondents are self-selected and cannot be treated as a representative population."],"correction_ids":[],"retraction_status":"none_identified_on_canonical_page_as_of_2026-08-15","content_hash":"32c07aeeb8f49694dd407080eab757c905dc4395871b52edd46a113208064a03","accessed_at":"2026-08-15","verification_status":"metadata_content_and_version_machine_verified_human_approved","source_depth":"deeply_analyzed","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.nist.gov/publications/summary-analysis-responses-request-information-regarding-security-considerations-ai","accessed_at":"2026-08-15","retrieval_method":"official source retrieval and machine-assisted review","exact_locator":"official HTML publication page accessed 2026-08-15","content_hash":"32c07aeeb8f49694dd407080eab757c905dc4395871b52edd46a113208064a03","batch_id":"BATCH-2026-005","prompt_id":"OEII-EVIDENCE-RESEARCH","prompt_version":"2.0","notes":"Human review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-005"}]}
{"entity_type":"source","source_id":"source-BATCH-2026-005-002","canonical_title":"Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile","alternate_titles":[],"source_type":"public_policy_document","series_or_parent_source":"NIST AI 600-1","publisher":"National Institute of Standards and Technology","channel":null,"speaker_ids":[],"author_ids":[],"institutional_author":"National Institute of Standards and Technology","organization_references":[],"recorded_at":null,"event_date":null,"published_at":null,"updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["United States","cross-sectoral global applicability"],"study_geography":["United States","cross-sectoral global applicability"],"original_url":"https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence","canonical_url":"https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence","archived_url":null,"embed_url":null,"doi":"10.6028/NIST.AI.600-1","canonical_identity_status":"verified","repost_status":"original_or_authoritative_rendition","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified; Executive AI Research snapshot contains no matching production records","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"Complete official 64-page PDF reviewed; governance action tables and Appendix A limitation text visually inspected.","topics":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_roles":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"original_abstract":null,"inclusion_rationale":"Accepted discovery candidate candidate-BATCH-2026-001-007; contributes government standards profile evidence or normative context to governed AI-agent identity.","source_quality_dimensions":{"attribution_strength":"high","methodological_transparency":"moderate_for_consensus_process","independence":"government_publisher","bibliographic_stability":"high_doi_resolved","evidence_strength":"strong_normative_reference_not_empirical_outcome_evidence","unresolved":"PDF metadata shows a 2025 modification date without a visible new edition statement."},"methodology_quality":{"design":"non-empirical cross-sectoral risk-management profile informed by multistakeholder public working-group feedback and public comments","transparency":"moderate_for_consensus_process","human_review_required":true},"study_design":"non-empirical cross-sectoral risk-management profile informed by multistakeholder public working-group feedback and public comments","sample":{"size":"not applicable for a normative profile; contributor and commenter counts not reported","sampling_method":"open multistakeholder process; selection details not reported"},"population":"organizations designing, developing, deploying, or using generative AI","date_range":{"fieldwork":"not reported","version":"July 2024; Editorial Review Board approval 2024-07-25; retrieved PDF SHA-256 recorded"},"funding":"U.S. Department of Commerce/NIST publication; separate research funding not reported","sponsor":"National Institute of Standards and Technology","peer_review_status":"NIST Editorial Review Board; not a peer-reviewed academic study","findings":["The profile organizes suggested actions across governance, mapping, measurement, and management functions.","It explicitly warns that pre-deployment tests and benchmark results may not generalize to real-world contexts."],"limitations":["No quantitative sample or outcome evaluation.","Public-input synthesis method and denominator are not disclosed."],"correction_ids":[],"retraction_status":"none_identified_in_pdf_or_official_doi_resolution_as_of_2026-08-15","content_hash":"6e73620ab6b64e90ef2c04bf0e0d6246185a2f4b1b13cab0df494496cff89b6a","accessed_at":"2026-08-15","verification_status":"metadata_content_and_version_machine_verified_human_approved","source_depth":"deeply_analyzed","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf","accessed_at":"2026-08-15","retrieval_method":"official source retrieval and machine-assisted review","exact_locator":"July 2024; Editorial Review Board approval 2024-07-25; retrieved PDF SHA-256 recorded","content_hash":"6e73620ab6b64e90ef2c04bf0e0d6246185a2f4b1b13cab0df494496cff89b6a","batch_id":"BATCH-2026-005","prompt_id":"OEII-EVIDENCE-RESEARCH","prompt_version":"2.0","notes":"Human review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-005"}]}
{"entity_type":"source","source_id":"source-BATCH-2026-005-003","canonical_title":"AI Agent Authentication and Authorization","alternate_titles":[],"source_type":"working_paper","series_or_parent_source":"draft-klrc-aiagent-auth-02","publisher":"Internet Engineering Task Force","channel":null,"speaker_ids":[],"author_ids":["person-BATCH-2026-005-pieter-kasselman","person-BATCH-2026-005-jeff-lombardo","person-BATCH-2026-005-yaron-rosomakho","person-BATCH-2026-005-brian-campbell","person-BATCH-2026-005-nick-steele","person-BATCH-2026-005-aaron-parecki"],"institutional_author":"IETF Internet-Draft authors","organization_references":[],"recorded_at":null,"event_date":null,"published_at":"2026-06-01","updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["global standards context"],"study_geography":["global standards context"],"original_url":"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-02.html","canonical_url":"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-02.html","archived_url":null,"embed_url":null,"doi":null,"canonical_identity_status":"verified","repost_status":"original_or_authoritative_rendition","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified; Executive AI Research snapshot contains no matching production records","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"Complete official IETF HTML rendition reviewed with stable section and paragraph locators.","topics":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_roles":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"original_abstract":null,"inclusion_rationale":"Accepted discovery candidate candidate-BATCH-2026-001-009; contributes standards document; Internet-Draft evidence or normative context to governed AI-agent identity.","source_quality_dimensions":{"attribution_strength":"high","methodological_transparency":"not_applicable_non_empirical","independence":"multi_vendor_author_group","bibliographic_stability":"medium_due_to_expiring_draft","evidence_strength":"strong_for_current_proposal_weak_for_interoperability_outcomes","unresolved":"Future revisions may change normative language or identifier choices."},"methodology_quality":{"design":"non-empirical technical standards proposal","transparency":"not_applicable_non_empirical","human_review_required":true},"study_design":"non-empirical technical standards proposal","sample":{"size":"not applicable","sampling_method":"not applicable"},"population":"AI-agent workloads and the tools, services, models, systems, and users that interact with them","date_range":{"fieldwork":"not applicable","version":"revision 02; expires 2026-12-03"},"funding":"not reported","sponsor":"not reported","peer_review_status":"working document; not an RFC and not peer reviewed","findings":["The draft models an agent as a workload that requires a stable identifier and cryptographically bound credentials.","It proposes preserving user or system delegation context in authorization decisions and audit trails."],"limitations":["Revision 02 is an expiring work in progress.","No interoperability tests or deployment outcomes are reported."],"correction_ids":[],"retraction_status":"active_work_in_progress_not_retracted_as_of_2026-08-15","content_hash":"e34f335c56546a6d91d88d43159c9f80d4dcfbbad020d41c31607fc56848befa","accessed_at":"2026-08-15","verification_status":"metadata_content_and_version_machine_verified_human_approved","source_depth":"deeply_analyzed","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-02.html","accessed_at":"2026-08-15","retrieval_method":"official source retrieval and machine-assisted review","exact_locator":"revision 02; expires 2026-12-03","content_hash":"e34f335c56546a6d91d88d43159c9f80d4dcfbbad020d41c31607fc56848befa","batch_id":"BATCH-2026-005","prompt_id":"OEII-EVIDENCE-RESEARCH","prompt_version":"2.0","notes":"Human review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-005"}]}
{"entity_type":"source","source_id":"source-BATCH-2026-005-004","canonical_title":"Identity Management for Agentic AI","alternate_titles":[],"source_type":"research_report","series_or_parent_source":"official OpenID Foundation PDF","publisher":"OpenID Foundation","channel":null,"speaker_ids":[],"author_ids":["person-BATCH-2026-005-tobin-south","person-BATCH-2026-005-subramanya-nagabhushanaradhya","person-BATCH-2026-005-ayesha-dissanayaka","person-BATCH-2026-005-sarah-cecchetti","person-BATCH-2026-005-george-fletcher","person-BATCH-2026-005-victor-lu","person-BATCH-2026-005-aldo-pietropaolo","person-BATCH-2026-005-dean-h-saxe","person-BATCH-2026-005-jeff-lombardo","person-BATCH-2026-005-abhishek-shivalingaiah","person-BATCH-2026-005-stan-bounev","person-BATCH-2026-005-alex-keisner","person-BATCH-2026-005-andor-kesselman","person-BATCH-2026-005-zack-proser","person-BATCH-2026-005-ginny-fahs","person-BATCH-2026-005-andrew-bunyea","person-BATCH-2026-005-ben-moskowitz","person-BATCH-2026-005-atul-tulshibagwale","person-BATCH-2026-005-dazza-greenwood","person-BATCH-2026-005-jiaxin-pei","person-BATCH-2026-005-alex-pentland"],"institutional_author":"OpenID Foundation","organization_references":[],"recorded_at":null,"event_date":null,"published_at":null,"updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["global technology standards context"],"study_geography":["global technology standards context"],"original_url":"https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf","canonical_url":"https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf","archived_url":null,"embed_url":null,"doi":null,"canonical_identity_status":"verified","repost_status":"original_or_authoritative_rendition","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified; Executive AI Research snapshot contains no matching production records","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"Complete official 33-page PDF reviewed; identity, delegation, auditability, and use-case sections inspected visually.","topics":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_roles":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"original_abstract":null,"inclusion_rationale":"Accepted discovery candidate candidate-BATCH-2026-001-027; contributes nonprofit/company white paper evidence or normative context to governed AI-agent identity.","source_quality_dimensions":{"attribution_strength":"high","methodological_transparency":"appropriate_for_white_paper_but_source_selection_not_reported","independence":"standards_community_publisher","bibliographic_stability":"high_official_pdf","evidence_strength":"moderate_normative_synthesis_not_empirical","unresolved":"Substantially the same intellectual work appears as arXiv:2510.25819v1."},"methodology_quality":{"design":"non-empirical technical white paper and standards synthesis","transparency":"appropriate_for_white_paper_but_source_selection_not_reported","human_review_required":true},"study_design":"non-empirical technical white paper and standards synthesis","sample":{"size":"not applicable","sampling_method":"not applicable"},"population":"AI-agent systems interacting with protected resources and other agents","date_range":{"fieldwork":"not applicable","version":"October 2025"},"funding":"not reported","sponsor":"OpenID Foundation publisher; separate sponsorship not reported","peer_review_status":"not reported; not treated as peer reviewed","findings":["The authors argue that current mechanisms are strongest for synchronous, single-trust-domain patterns and weaker for cross-domain or recursive delegation.","The paper distinguishes agent identity from user identity and calls for lifecycle management and enriched audit trails."],"limitations":["No implementation benchmark or comparative test.","Formal source-selection, funding, conflicts, and review process are not reported."],"correction_ids":[],"retraction_status":"none_identified_on_official_pdf_or_publisher_url_as_of_2026-08-15","content_hash":"e6a0e5909fcb2486568180f69d511ae2af8d20a1bfb3028b39b3d1072846f4f3","accessed_at":"2026-08-15","verification_status":"metadata_content_and_version_machine_verified_human_approved","source_depth":"deeply_analyzed","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf","accessed_at":"2026-08-15","retrieval_method":"official source retrieval and machine-assisted review","exact_locator":"October 2025","content_hash":"e6a0e5909fcb2486568180f69d511ae2af8d20a1bfb3028b39b3d1072846f4f3","batch_id":"BATCH-2026-005","prompt_id":"OEII-EVIDENCE-RESEARCH","prompt_version":"2.0","notes":"Human review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-005"}]}
{"entity_type":"source","source_id":"source-BATCH-2026-005-006","canonical_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","alternate_titles":[],"source_type":"academic_paper","series_or_parent_source":"arXiv:2406.13352v3; NeurIPS 2024 proceedings record","publisher":"NeurIPS 2024 Datasets and Benchmarks Track","channel":null,"speaker_ids":[],"author_ids":["person-BATCH-2026-005-edoardo-debenedetti","person-BATCH-2026-005-jie-zhang","person-BATCH-2026-005-mislav-balunovic","person-BATCH-2026-005-luca-beurer-kellner","person-BATCH-2026-005-marc-fischer","person-BATCH-2026-005-florian-tramer"],"institutional_author":null,"organization_references":[],"recorded_at":null,"event_date":null,"published_at":"2024-06-19","updated_at":"2024-11-24","duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["synthetic environments; no human geography"],"study_geography":["synthetic environments; no human geography"],"original_url":"https://arxiv.org/abs/2406.13352","canonical_url":"https://arxiv.org/abs/2406.13352","archived_url":null,"embed_url":null,"doi":"10.48550/arXiv.2406.13352","canonical_identity_status":"verified","repost_status":"original_or_authoritative_rendition","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified; Executive AI Research snapshot contains no matching production records","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"Complete 26-page v3 conference paper reviewed; benchmark composition, figures, Tables 1 and 3-5, confidence intervals, limitations, and funding inspected visually.","topics":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_roles":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"original_abstract":null,"inclusion_rationale":"Accepted discovery candidate candidate-BATCH-2026-001-050; contributes peer-reviewed conference paper evidence or normative context to governed AI-agent identity.","source_quality_dimensions":{"attribution_strength":"high","methodological_transparency":"high","independence":"academic_with_disclosed_industry_affiliations","bibliographic_stability":"high_arxiv_and_neurips_records","evidence_strength":"strong_for_benchmark_conditions_not_real_world_incidence","unresolved":"Confidence-interval construction and raw row numerators are not stated in the reviewed tables."},"methodology_quality":{"design":"controlled benchmark experiments in stateful synthetic tool environments","transparency":"high","human_review_required":true},"study_design":"controlled benchmark experiments in stateful synthetic tool environments","sample":{"size":"97 user tasks; 27 injection tasks; 629 security test cases; seven listed agent/model configurations in Table 3","sampling_method":"researcher-curated realistic tasks and synthetic data; compatible task cross-product"},"population":"LLM agents executing tools over simulated workspace, Slack, travel, and banking environments","date_range":{"fieldwork":"not reported; v3 results reflect the paper's 2024 model/API versions","version":"v3; updated after a Llama implementation bug fix and travel-suite update"},"funding":"Edoardo Debenedetti supported by armasuisse Science and Technology; Jie Zhang funded by Swiss National Science Foundation grant 214838; benchmark funding statement says no institution explicitly funded benchmark creation","sponsor":"no benchmark sponsor reported","peer_review_status":"verified conference publication in official NeurIPS 2024 proceedings","findings":["The benchmark exposes substantial utility and security tradeoffs.","Table 5 reports targeted attack success of 57.69% with no defense and 6.84% with tool filtering for the listed GPT-4o setup, with reported intervals."],"limitations":["Synthetic environments and versioned APIs limit external validity.","Raw numerators and interval-construction method are not reported in the reviewed table.","v3 replaced earlier results after a bug fix and travel-suite update."],"correction_ids":["correction-BATCH-2026-005-001"],"retraction_status":"no_retraction_identified;_v3_documents_bug_fix_update","content_hash":"349884fffbf43282591c5accffd57bb651632f38e412fe303114941bdd111b05","accessed_at":"2026-08-15","verification_status":"metadata_content_and_version_machine_verified_human_approved","source_depth":"deeply_analyzed","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2406.13352","accessed_at":"2026-08-15","retrieval_method":"official source retrieval and machine-assisted review","exact_locator":"v3; updated after a Llama implementation bug fix and travel-suite update","content_hash":"349884fffbf43282591c5accffd57bb651632f38e412fe303114941bdd111b05","batch_id":"BATCH-2026-005","prompt_id":"OEII-EVIDENCE-RESEARCH","prompt_version":"2.0","notes":"Human review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-005"}]}
{"entity_type":"source","source_id":"source-BATCH-2026-005-007","canonical_title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","alternate_titles":[],"source_type":"academic_paper","series_or_parent_source":"arXiv:2410.02644v4","publisher":"ICLR 2025 / arXiv","channel":null,"speaker_ids":[],"author_ids":["person-BATCH-2026-005-hanrong-zhang","person-BATCH-2026-005-jingyuan-huang","person-BATCH-2026-005-kai-mei","person-BATCH-2026-005-yifei-yao","person-BATCH-2026-005-zhenting-wang","person-BATCH-2026-005-chenlu-zhan","person-BATCH-2026-005-hongwei-wang","person-BATCH-2026-005-yongfeng-zhang"],"institutional_author":null,"organization_references":[],"recorded_at":null,"event_date":null,"published_at":"2024-10-03","updated_at":"2025-05-30","duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["synthetic benchmark; no human geography"],"study_geography":["synthetic benchmark; no human geography"],"original_url":"https://arxiv.org/abs/2410.02644","canonical_url":"https://arxiv.org/abs/2410.02644","archived_url":null,"embed_url":null,"doi":"10.48550/arXiv.2410.02644","canonical_identity_status":"verified","repost_status":"original_or_authoritative_rendition","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified; Executive AI Research snapshot contains no matching production records","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"Complete 36-page v4 paper reviewed; attack/defense definitions, scenario tables, metric table, result tables, and reproducibility appendix inspected visually.","topics":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_roles":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"original_abstract":null,"inclusion_rationale":"Accepted discovery candidate candidate-BATCH-2026-001-054; contributes conference paper; acceptance marker verified in version, venue record not independently retrieved evidence or normative context to governed AI-agent identity.","source_quality_dimensions":{"attribution_strength":"high","methodological_transparency":"high_for_benchmark_structure","independence":"academic","bibliographic_stability":"high_arxiv_doi_resolved","evidence_strength":"moderate_to_strong_for_benchmark_conditions","unresolved":"Venue acceptance is author/arXiv-reported; OpenReview verification was unavailable in this run. Headline average lacks uncertainty and a compact denominator statement."},"methodology_quality":{"design":"multi-scenario controlled security benchmark","transparency":"high_for_benchmark_structure","human_review_required":true},"study_design":"multi-scenario controlled security benchmark","sample":{"size":"400 tasks; 10 scenarios; 10 agents; more than 400 tools; 27 attack/defense methods; 13 LLM backbones","sampling_method":"researcher-constructed scenarios, tasks, tools, and attacks; selection procedure not probabilistic"},"population":"LLM-agent configurations under synthetic attacks and defenses","date_range":{"fieldwork":"not reported; model versions correspond to experiments before v4 dated 2025-05-30","version":"v4; paper and arXiv page state accepted at ICLR 2025"},"funding":"not reported","sponsor":"not reported","peer_review_status":"conference acceptance reported in the paper and arXiv metadata; independent OpenReview record retrieval returned access denied, so peer-review verification remains qualified","findings":["The authors report a highest average attack success rate of 84.30% for a benchmark configuration.","Current defenses vary and often trade security against task performance."],"limitations":["No production population or human sample.","The headline average does not disclose a raw numerator or confidence interval.","Funding and conflicts are not reported."],"correction_ids":[],"retraction_status":"none_identified_on_arxiv_version_history_as_of_2026-08-15","content_hash":"e20155df01b3a1f6c0a947c4e9e4871957cff2e507939f7ea21a5fe967d84504","accessed_at":"2026-08-15","verification_status":"metadata_content_and_version_machine_verified_human_approved","source_depth":"deeply_analyzed","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2410.02644","accessed_at":"2026-08-15","retrieval_method":"official source retrieval and machine-assisted review","exact_locator":"v4; paper and arXiv page state accepted at ICLR 2025","content_hash":"e20155df01b3a1f6c0a947c4e9e4871957cff2e507939f7ea21a5fe967d84504","batch_id":"BATCH-2026-005","prompt_id":"OEII-EVIDENCE-RESEARCH","prompt_version":"2.0","notes":"Human review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-005"}]}
{"entity_type":"source","source_id":"source-BATCH-2026-005-008","canonical_title":"Teams of LLM Agents can Exploit Zero-Day Vulnerabilities","alternate_titles":[],"source_type":"academic_paper","series_or_parent_source":"arXiv:2406.01637v2","publisher":"arXiv","channel":null,"speaker_ids":[],"author_ids":["person-BATCH-2026-005-yuxuan-zhu","person-BATCH-2026-005-antony-kellermann","person-BATCH-2026-005-akul-gupta","person-BATCH-2026-005-philip-li","person-BATCH-2026-005-richard-fang","person-BATCH-2026-005-rohan-bindu","person-BATCH-2026-005-daniel-kang"],"institutional_author":null,"organization_references":[],"recorded_at":null,"event_date":null,"published_at":"2024-06-02","updated_at":"2025-03-30","duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["synthetic sandbox; no human geography"],"study_geography":["synthetic sandbox; no human geography"],"original_url":"https://arxiv.org/abs/2406.01637","canonical_url":"https://arxiv.org/abs/2406.01637","archived_url":null,"embed_url":null,"doi":"10.48550/arXiv.2406.01637","canonical_identity_status":"verified","repost_status":"original_or_authoritative_rendition","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified; Executive AI Research snapshot contains no matching production records","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"Complete 10-page v2 preprint reviewed; Tables 1-2, Figures 2-3, methods, results, and limitation text inspected visually.","topics":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_roles":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"original_abstract":null,"inclusion_rationale":"Accepted discovery candidate candidate-BATCH-2026-001-058; contributes preprint evidence or normative context to governed AI-agent identity.","source_quality_dimensions":{"attribution_strength":"high","methodological_transparency":"moderate","independence":"academic_with_platform_coordination_disclosed","bibliographic_stability":"high_arxiv_doi_resolved","evidence_strength":"moderate_for_selected_sandbox_cases","unresolved":"Nonrelease of code/prompts limits replication; funding and conflict disclosures are absent."},"methodology_quality":{"design":"controlled cybersecurity benchmark experiment in sandboxed reproductions","transparency":"moderate","human_review_required":true},"study_design":"controlled cybersecurity benchmark experiment in sandboxed reproductions","sample":{"size":"14 vulnerabilities; pass@1 and pass@5 trials; exact total run count not summarized","sampling_method":"purposive selection of recent, reproducible web vulnerabilities with clear success triggers and manual exploitability"},"population":"reproducible open-source web vulnerabilities; not all vulnerabilities or deployed systems","date_range":{"fieldwork":"not reported","version":"v2 submitted 2025-03-30"},"funding":"not reported","sponsor":"not reported; authors state OpenAI requested code and prompts remain confidential","peer_review_status":"not peer reviewed; preprint","findings":["The authors report 42% pass@5 and 18% pass@1 for HPTSA with GPT-4 on the 14-vulnerability benchmark.","Open-source scanners and listed open-source models report 0% on this benchmark."],"limitations":["Only 14 selected web vulnerabilities.","No confidence intervals.","Code and prompts are withheld, limiting replication.","Results are capability demonstrations, not estimates of incident prevalence."],"correction_ids":[],"retraction_status":"none_identified_on_arxiv_version_history_as_of_2026-08-15","content_hash":"f4fc06040f0856d99d2009042b4c6fa0c01206da8ca61cb39a94d52b9867cf71","accessed_at":"2026-08-15","verification_status":"metadata_content_and_version_machine_verified_human_approved","source_depth":"deeply_analyzed","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2406.01637","accessed_at":"2026-08-15","retrieval_method":"official source retrieval and machine-assisted review","exact_locator":"v2 submitted 2025-03-30","content_hash":"f4fc06040f0856d99d2009042b4c6fa0c01206da8ca61cb39a94d52b9867cf71","batch_id":"BATCH-2026-005","prompt_id":"OEII-EVIDENCE-RESEARCH","prompt_version":"2.0","notes":"Human review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-005"}]}
{"entity_type":"source","source_id":"source-BATCH-2026-005-009","canonical_title":"Practices for Governing Agentic AI Systems","alternate_titles":[],"source_type":"research_report","series_or_parent_source":"official OpenAI PDF","publisher":"OpenAI","channel":null,"speaker_ids":[],"author_ids":["person-BATCH-2026-005-yonadav-shavit","person-BATCH-2026-005-sandhini-agarwal","person-BATCH-2026-005-miles-brundage","person-BATCH-2026-005-steven-adler","person-BATCH-2026-005-cullen-o-keefe","person-BATCH-2026-005-rosie-campbell","person-BATCH-2026-005-teddy-lee","person-BATCH-2026-005-pamela-mishkin","person-BATCH-2026-005-tyna-eloundou","person-BATCH-2026-005-alan-hickey","person-BATCH-2026-005-katarina-slama","person-BATCH-2026-005-lama-ahmad","person-BATCH-2026-005-paul-mcmillan","person-BATCH-2026-005-alex-beutel","person-BATCH-2026-005-alexandre-passos","person-BATCH-2026-005-david-g-robinson"],"institutional_author":null,"organization_references":[],"recorded_at":null,"event_date":null,"published_at":null,"updated_at":null,"duration_seconds":null,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":[],"geography_discussed":["global policy context"],"study_geography":["global policy context"],"original_url":"https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf","canonical_url":"https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf","archived_url":null,"embed_url":null,"doi":null,"canonical_identity_status":"verified","repost_status":"original_or_authoritative_rendition","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none_identified; Executive AI Research snapshot contains no matching production records","transcript_status":null,"transcript_source":null,"transcript_republication_permission":null,"chapter_markers":[],"analysis_basis":"Complete official 23-page PDF reviewed; definition, accountability, monitoring, attribution, interruptibility, indirect impacts, and acknowledgements inspected visually.","topics":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_roles":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"original_abstract":null,"inclusion_rationale":"Accepted discovery candidate candidate-BATCH-2026-001-085; contributes company white paper and policy analysis evidence or normative context to governed AI-agent identity.","source_quality_dimensions":{"attribution_strength":"high","methodological_transparency":"appropriate_for_policy_analysis","independence":"company_published","bibliographic_stability":"high_official_pdf","evidence_strength":"moderate_normative_policy_analysis_not_empirical","unresolved":"Publication day, funding, affiliations, conflicts, and external review status are not reported in the PDF."},"methodology_quality":{"design":"non-empirical company white paper and policy analysis","transparency":"appropriate_for_policy_analysis","human_review_required":true},"study_design":"non-empirical company white paper and policy analysis","sample":{"size":"not applicable","sampling_method":"not applicable"},"population":"model developers, system deployers, users, and third parties in agentic-system lifecycles","date_range":{"fieldwork":"not applicable","version":"2023; PDF metadata created 2023-12-18"},"funding":"not reported","sponsor":"OpenAI publisher; separate sponsor involvement not reported","peer_review_status":"not reported; not treated as peer reviewed","findings":["The authors propose evaluation, action-space constraints, default behaviors, legibility, monitoring, attributability, and interruptibility as building blocks.","They argue that at least one human legal entity should remain accountable for uncompensated direct harm."],"limitations":["No empirical outcome evaluation.","Company-published and funding/conflicts are not reported.","Many recommendations are explicitly preliminary."],"correction_ids":[],"retraction_status":"none_identified_on_official_pdf_url_as_of_2026-08-15","content_hash":"22b3a8607ed781a848b82b0bfe8e638b16cd027aac90a19b2aecf236063d0e7c","accessed_at":"2026-08-15","verification_status":"metadata_content_and_version_machine_verified_human_approved","source_depth":"deeply_analyzed","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf","accessed_at":"2026-08-15","retrieval_method":"official source retrieval and machine-assisted review","exact_locator":"2023; PDF metadata created 2023-12-18","content_hash":"22b3a8607ed781a848b82b0bfe8e638b16cd027aac90a19b2aecf236063d0e7c","batch_id":"BATCH-2026-005","prompt_id":"OEII-EVIDENCE-RESEARCH","prompt_version":"2.0","notes":"Human review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-005"}]}
{"entity_type":"source","source_id":"source-idac-390-agentic-ai-identity","canonical_title":"#390 - Identity Management for Agentic AI with Tobin South","alternate_titles":["Identity at the Center #390: Identity Management for Agentic AI with Tobin South"],"source_type":"podcast_episode","series_or_parent_source":"Identity at the Center, episode 390","publisher":"IDAC Corp. / Identity at the Center","channel":"Identity at the Center","speaker_ids":["person-jeff-steadman","person-jim-mcdonald","person-BATCH-2026-005-tobin-south"],"author_ids":[],"institutional_author":null,"organization_references":["orgref-idac","orgref-openid-foundation"],"recorded_at":null,"event_date":null,"published_at":"2025-12-08","updated_at":null,"duration_seconds":3353,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":["geo-global"],"geography_discussed":["geo-global"],"study_geography":[],"original_url":"https://anchor.fm/s/c5fefcc/podcast/play/111687080/https%3A%2F%2Fd3ctxlq1ktw2nl.cloudfront.net%2Fstaging%2F2025-10-25%2F01f889a3-6ebf-b82d-8d03-61c6114f10df.mp3","canonical_url":"https://podcasts.apple.com/us/podcast/390-identity-management-for-agentic-ai-with-tobin-south/id1471899975?i=1000740200992","archived_url":null,"embed_url":"https://open.spotify.com/embed/episode/6djrGPlNiIlJZmBpcsR2KY","doi":null,"canonical_identity_status":"verified_original_episode_across_rss_apple_spotify_and_openid_media_index","repost_status":"original_episode_with_listening_platform_mirrors","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none","transcript_status":"unofficial_research_aids_only","transcript_source":"Podscan public preview plus local machine transcription checked against the original audio","transcript_republication_permission":"not_documented_do_not_publish_full_transcript","chapter_markers":[{"chapter_id":"chapter-idac390-01","start":0,"end":355},{"chapter_id":"chapter-idac390-02","start":355,"end":420},{"chapter_id":"chapter-idac390-03","start":420,"end":540},{"chapter_id":"chapter-idac390-04","start":540,"end":630},{"chapter_id":"chapter-idac390-05","start":630,"end":720},{"chapter_id":"chapter-idac390-06","start":720,"end":840},{"chapter_id":"chapter-idac390-07","start":840,"end":1020},{"chapter_id":"chapter-idac390-08","start":1020,"end":1200},{"chapter_id":"chapter-idac390-09","start":1200,"end":1380},{"chapter_id":"chapter-idac390-10","start":1380,"end":1560},{"chapter_id":"chapter-idac390-11","start":1560,"end":1800},{"chapter_id":"chapter-idac390-12","start":1800,"end":1920},{"chapter_id":"chapter-idac390-13","start":1920,"end":2160},{"chapter_id":"chapter-idac390-14","start":2160,"end":2280},{"chapter_id":"chapter-idac390-15","start":2280,"end":2520},{"chapter_id":"chapter-idac390-16","start":2520,"end":2760},{"chapter_id":"chapter-idac390-17","start":2760,"end":2880},{"chapter_id":"chapter-idac390-18","start":2880,"end":3240},{"chapter_id":"chapter-idac390-19","start":3240,"end":3353}],"analysis_basis":"Complete original audio reviewed with official chapter markers, platform metadata, an unofficial transcript preview, and a locally generated timestamped research transcript; statements were checked against the audio dialogue and attributed only where the guest response was clear.","topics":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-ai-liability","topic-enterprise-infrastructure"],"executive_roles":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"original_abstract":"Tobin South explains why AI agents strain identity systems designed for deterministic users and applications. The discussion separates impersonation from delegated authority, argues that agents need identities and credentials distinct from the people who invoke them, and connects governance to bounded scopes, traceable delegation chains, oversight, and responsibility for actions. South treats standards work as necessary infrastructure for both consumer assistants and enterprise deployments, while also describing Model Context Protocol as an interoperability layer whose security properties still depend on authentication and authorization. The episode's practical emphasis is that identity teams should prepare policies and architectures before agent adoption becomes widespread, without assuming current protocols or shared user credentials are adequate.","inclusion_rationale":"This is a complete, long-form interview with the lead author of the OpenID agentic-identity report and directly addresses delegation, credentials, governance, liability, MCP, and recursive authority.","source_quality_dimensions":{"primary_spoken_source":"high","identity_stability":"high","access_completeness":"complete","independence":"interview_not_peer_reviewed"},"methodology_quality":{"study_design":"expert_interview","empirical_method":"none","attribution_method":"dialogue_context_and_audio_verification"},"study_design":"expert_interview","sample":{},"population":null,"date_range":{},"funding":"IDAC Corp. states that the regular weekly podcast does not sell advertising or use commercial sponsorship contracts; no episode-specific funding was identified.","sponsor":null,"peer_review_status":"not_applicable","findings":[],"limitations":["Expert perspective rather than empirical study","Recording date not publicly established","No official transcript","Host banter and event promotion occupy the opening and closing sections"],"correction_ids":[],"retraction_status":null,"content_hash":"sha256:779b09ce66832cb86acf34c091302cc3a653f5487dd4b640bed84c16570af40d","accessed_at":"2026-08-15","verification_status":"machine_verified_human_approved","source_depth":"deep","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://podcasts.apple.com/us/podcast/390-identity-management-for-agentic-ai-with-tobin-south/id1471899975?i=1000740200992","accessed_at":"2026-08-15","retrieval_method":"official platform metadata and original RSS audio review","exact_locator":"episode 390; 00:00-55:53","content_hash":"sha256:779b09ce66832cb86acf34c091302cc3a653f5487dd4b640bed84c16570af40d","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":"No transcript asset is included in the repository."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"source","source_id":"source-sailpoint-governing-ai-agents-2025","canonical_title":"Governing AI agents with Agent Identity Security","alternate_titles":["Securing AI Agents with Agent Identity Security Nov 2025"],"source_type":"video","series_or_parent_source":"SailPoint Community Webinar / Video Library","publisher":"SailPoint Technologies","channel":"SailPoint Developer Community","speaker_ids":["person-amy-shillinglaw"],"author_ids":[],"institutional_author":"SailPoint Technologies","organization_references":["orgref-sailpoint"],"recorded_at":"2025-11-20","event_date":"2025-11-20","published_at":"2025-11-20","updated_at":null,"duration_seconds":3436,"language":"lang-en","translated_title":null,"translation_method":null,"geography_of_speaker":[],"geography_of_organization":["geo-global"],"geography_discussed":["geo-global"],"study_geography":[],"original_url":"https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944","canonical_url":"https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944","archived_url":null,"embed_url":"https://play.vidyard.com/qewbsaA1gHud1Dws5LQNac.html","doi":null,"canonical_identity_status":"verified_official_publisher_page_and_embedded_recording","repost_status":"original_publisher_embed_no_competing_canonical_upload","original_source_id":null,"rights_status":"link_and_paraphrase","ownership_status":"third_party","relationship_to_off":"none","transcript_status":"official_platform_captions_research_only","transcript_source":"Vidyard English WebVTT captions embedded by SailPoint","transcript_republication_permission":"not_documented_do_not_publish_full_captions","chapter_markers":[{"chapter_id":"chapter-sailpoint-01","start":0,"end":76},{"chapter_id":"chapter-sailpoint-02","start":76,"end":329},{"chapter_id":"chapter-sailpoint-03","start":329,"end":602},{"chapter_id":"chapter-sailpoint-04","start":602,"end":1072},{"chapter_id":"chapter-sailpoint-05","start":1072,"end":1431},{"chapter_id":"chapter-sailpoint-06","start":1431,"end":2020},{"chapter_id":"chapter-sailpoint-07","start":2020,"end":2091},{"chapter_id":"chapter-sailpoint-08","start":2091,"end":2645},{"chapter_id":"chapter-sailpoint-09","start":2645,"end":3071},{"chapter_id":"chapter-sailpoint-10","start":3071,"end":3436}],"analysis_basis":"Complete official Vidyard recording and speaker-labeled English platform captions reviewed against the SailPoint community page, registration page, and player metadata. The recording itself controlled speaker inclusion where promotional metadata differed.","topics":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_roles":["role-ciso","role-cio","role-cto"],"original_abstract":"Amy Shillinglaw presents SailPoint's model for governing AI agents as identities whose behavior combines machine execution with human-like autonomy. She separates inbound authorization—who may invoke an agent—from outbound authorization—what resources the agent may use for that person—and frames inventory, tool correlation, human ownership, succession, and dual-sided certification as the control sequence. A product demonstration shows how those ideas are represented in SailPoint's platform, including user entitlements, machine-account correlation, and access reviews. The session also identifies risks such as runaway subtasks, compromised code or credentials, poisoned data, and poor explainability. Because this is a vendor webinar, the record supports product and practitioner claims, not independent performance findings.","inclusion_rationale":"The full recording provides a concrete governance model, exact speaker attribution, a detailed demonstration, and timestamped product limitations relevant to enterprise identity teams.","source_quality_dimensions":{"primary_spoken_source":"high","identity_stability":"high","access_completeness":"complete","independence":"vendor_produced"},"methodology_quality":{"study_design":"vendor_practitioner_webinar_and_demo","empirical_method":"none","attribution_method":"speaker_labeled_platform_captions_and_self_identification"},"study_design":"vendor_practitioner_webinar_and_demo","sample":{},"population":null,"date_range":{},"funding":"SailPoint-produced webinar","sponsor":"SailPoint Technologies","peer_review_status":"not_applicable","findings":[],"limitations":["Vendor-produced product presentation","No independent customer outcomes","Capabilities and supported connectors are time-sensitive","Platform captions contain transcription errors","Promotional page speaker list differs from the actual recording"],"correction_ids":[],"retraction_status":null,"content_hash":"sha256:a254342e28dcc6b6bd1994f5366e0ea44c02899eacb3a2861a795f567a5ced7c","accessed_at":"2026-08-15","verification_status":"machine_verified_human_approved","source_depth":"deep","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944","accessed_at":"2026-08-15","retrieval_method":"official publisher page, embedded recording, player metadata, and platform captions","exact_locator":"Vidyard qewbsaA1gHud1Dws5LQNac; 00:00-57:15.627","content_hash":"sha256:a254342e28dcc6b6bd1994f5366e0ea44c02899eacb3a2861a795f567a5ced7c","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":"Caption hash sha256:4433395b628f50446a618e6608896ae2d4fc219c940678162fa8dbe817878a5a; caption file is not included."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-001","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"factual_assertion","neutral_paraphrase":"Dynamic scheduling, ephemeral workloads, and heterogeneous infrastructure make network location and manually managed secrets unreliable foundations for service identity.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 9–20","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Historical examples and architecture reasoning","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Distributed infrastructure rather than every identity environment","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=9","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 9–20","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-002","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"strategic_framework","neutral_paraphrase":"The bottom-turtle problem is the need to establish an initial root of trust without assuming a long-lived secret that itself requires prior protection.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 17–19","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Conceptual threat-model argument","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Trust bootstrap for workloads","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=17","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 17–19","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-003","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"definition","neutral_paraphrase":"A useful workload identity combines the workload's logical purpose with the authority that issued and vouches for that identity, rather than describing only its network address.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 38–41","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Normative technical definition","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"SPIFFE-style workload identity","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=38","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 38–41","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-004","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"recommendation","neutral_paraphrase":"Automatically renewed, short-lived identity documents reduce exposure from copied credentials and reduce dependence on conventional revocation distribution.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 45–48","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Cryptographic lifecycle reasoning","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Credential management; does not eliminate revocation needs in every system","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=45","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 45–48","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-005","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"strategic_framework","neutral_paraphrase":"SPIFFE specifies interoperable workload identity documents and APIs, while SPIRE implements attestation, registration, issuance, and federation as an identity control plane.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 52–59","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Specification and reference-implementation description","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"SPIFFE and SPIRE architecture in the first edition","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=52","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 52–59","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-006","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"strategic_framework","neutral_paraphrase":"Node attestation establishes the hosting agent's platform identity, workload attestation inspects process attributes, and registration entries bind accepted conditions to the identity that may be issued.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 65–70","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Architecture description and examples","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"SPIRE issuance flow","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=65","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 65–70","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-007","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"warning","neutral_paraphrase":"The threat model assumes a hostile network but places trust in specified hardware, platform, operator, and plugin boundaries; compromise of a SPIRE server can enable arbitrary identity issuance inside its trust domain.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 71–77","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Explicit threat model and compromise analysis","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Specified first-edition deployment assumptions","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=71","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 71–77","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-008","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"recommendation","neutral_paraphrase":"A production identity deployment should involve security, platform, application, networking, and operational stakeholders because identity semantics and availability cross team boundaries.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 78–80","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Practitioner implementation guidance","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Organizational adoption","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=78","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 78–80","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-009","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"warning","neutral_paraphrase":"Bridges and proxies can accelerate migration from existing identity islands, but intermediaries may hide or replace the original authenticated workload context.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 81–87","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Migration-pattern tradeoff analysis","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Transitional integrations","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=81","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 81–87","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-010","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"recommendation","neutral_paraphrase":"Migration should be staged through inventory, target-state design, dual operation, measurement, and rollback rather than requiring a single cutover.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 90–99","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Practitioner rollout guidance","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Enterprise adoption","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=90","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 90–99","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-011","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"recommendation","neutral_paraphrase":"Operators should test identity-control-plane failure modes and protect log integrity and custody because issuance and access records may be needed for investigation.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 99–103","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Operational guidance","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"SPIRE operations and audit evidence","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=99","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 99–103","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-012","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"strategic_framework","neutral_paraphrase":"Trust-domain boundaries, SPIFFE ID naming, federation relationships, and credential lifetimes jointly determine administrative scope, interoperability, and compromise impact.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 104–117","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Deployment design framework","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"SPIFFE deployment design","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=104","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 104–117","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-013","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"warning","neutral_paraphrase":"Automated registration reduces manual burden, but the registration API and data store become security-sensitive dependencies that require protected access, auditing, and reliable storage.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 123–131","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Control tradeoff analysis","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Automated registration systems","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"Pass after independent-review correction","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=123","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 123–131","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-15T00:00:00Z","changed_by":"independent machine review response","summary":"Narrowed the claim to registration API and data-store dependencies supported by pages 123–131.","batch_id":"BATCH-2026-003"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-014","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"recommendation","neutral_paraphrase":"Native workload API integration provides the clearest identity context, while sidecars, proxies, and helper libraries trade application change against operational complexity and context loss.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 133–138","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Integration-pattern comparison","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Application integration","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=133","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 133–138","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-015","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"interpretation","neutral_paraphrase":"Identity issuance and access logs can supply provenance about which workload received and used an identity, provided logs are protected and correlated across boundaries.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 139–141","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Operational inference grounded in logging guidance","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Security investigations; provenance is limited to recorded events","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=139","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 139–141","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-016","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"strategic_framework","neutral_paraphrase":"Authentication establishes identity but does not determine permission; authorization should map identities to external roles or carefully governed attributes and evaluate the requested action.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 146–153","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Authorization framework and caution","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Workload access control","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=146","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 146–153","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-017","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"opinion","neutral_paraphrase":"The book characterizes SPIFFE and SPIRE as the only complete solution covering the full workload-identity problem at the time of writing.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 159–166","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Comparative project-authored assessment","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Ecosystem state asserted in 2020; sweeping and time-bound","uncertainty":"Claim is time-bound, selected, or self-reported and should not be treated as independent causal evidence.","extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.86,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=159","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 159–166","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-018","source_id":"source-BATCH-2026-003-001","person_id":null,"institutional_author":"The 12 named authors of Solving the Bottom Turtle","book_edition_id":"book-edition-BATCH-2026-002-001","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"company_reported_outcome","neutral_paraphrase":"Five organization stories report that adopting SPIFFE or SPIRE simplified credential operations, strengthened service authentication, or enabled multi-platform trust.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"pages 168–178","locator_type":"page","source_date":"2020-11-17","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Self-reported case stories","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Five selected adopters; not a controlled comparison","uncertainty":"Claim is time-bound, selected, or self-reported and should not be treated as independent causal evidence.","extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.86,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://spiffe.io/pdf/Solving-the-bottom-turtle-SPIFFE-SPIRE-Book.pdf#page=168","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"pages 168–178","content_hash":"8353e3cf6fb8859ff34b0a43fe8146d7580dd32c9ace863c1a4758440f898fcb","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-019","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"The named book authors of Building Secure and Reliable Systems","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"strategic_framework","neutral_paraphrase":"Security and reliability should be designed and operated together across the system lifecycle because late-stage controls cannot reliably compensate for unsafe architecture and operations.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Preface > Why We Wrote This Book","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Practitioner synthesis and stated thesis","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Software and infrastructure lifecycle","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/pr01.html#why_we_wrote_this_book","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Preface > Why We Wrote This Book","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-020","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Adam Stubblefield, Massimiliano Poletto, and Piotr Lewandowski, with David Huska and Betsy Beyer","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"interpretation","neutral_paraphrase":"Security and reliability are emergent system properties with common needs for prevention, detection, containment, and recovery, even though adversarial intent changes the threat model.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 1 > Reliability and Security Commonalities","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Cross-domain conceptual analysis","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Large-scale systems","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch01.html#reliability_and_security_commonalities","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 1 > Reliability and Security Commonalities","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-021","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Heather Adkins and David Huska, with Jen Barnason","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"recommendation","neutral_paraphrase":"Risk assessment should model capable adversaries, valued assets, likely attack paths, and the consequences of successful attacks.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 2 > Risk Assessment Considerations","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Threat-model method and examples","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Adversarial system risk assessment","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"Pass after independent-review correction","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch02.html#risk_assessment_considerations","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 2 > Risk Assessment Considerations","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-15T00:00:00Z","changed_by":"independent machine review response","summary":"Removed benign-failure language not supported by the Chapter 2 locator.","batch_id":"BATCH-2026-003"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-022","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Christoph Kern, with Brian Gustafson, Paul Blankinship, and Felix Gröbert","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"strategic_framework","neutral_paraphrase":"Design decisions should make security, reliability, usability, cost, and other nonfunctional requirements explicit so tradeoffs are evaluated rather than hidden.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 4 > Design Objectives and Requirements","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Design framework","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"System design","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch04.html#design_objectives_and_requirements","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 4 > Design Objectives and Requirements","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-023","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Oliver Barrett, Aaron Joyner, and Rory Ward, with Guy Fischman and Betsy Beyer","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"recommendation","neutral_paraphrase":"Least privilege applies to people, automated jobs, and machines: each principal should receive only the access needed for the current responsibility.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 5 > Least Privilege","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Security principle with operational examples","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Human and machine access","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch05.html#least_privilege","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 5 > Least Privilege","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-024","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Oliver Barrett, Aaron Joyner, and Rory Ward, with Guy Fischman and Betsy Beyer","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"strategic_framework","neutral_paraphrase":"Organizations should classify access by the potential impact of misuse and apply controls proportionate to the resulting risk tier.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 5 > Classifying Access Based on Risk","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Risk-tiering framework","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Privileged operations","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"Pass after independent-review correction","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch05.html#classifying_access_based_on_risk","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 5 > Classifying Access Based on Risk","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-15T00:00:00Z","changed_by":"independent machine review response","summary":"Removed a specific control list not established by the access-classification section.","batch_id":"BATCH-2026-003"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-025","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Oliver Barrett, Aaron Joyner, and Rory Ward, with Guy Fischman and Betsy Beyer","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"recommendation","neutral_paraphrase":"Sensitive operations should be exposed through narrow functional APIs and recorded in action-oriented audit logs rather than granted as broad administrative access.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 5 > Small Functional APIs; Auditing","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Design guidance and examples","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Administrative and automated access","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch05.html#small_functional_apis","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 5 > Small Functional APIs; Auditing","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-026","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Oliver Barrett, Aaron Joyner, and Rory Ward, with Guy Fischman and Betsy Beyer","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"strategic_framework","neutral_paraphrase":"Authorization policy can evaluate the action, arguments, request source, principal metadata, and server-side context rather than treating a credential as sufficient permission.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 5 > A Policy Framework for Authentication and Authorization","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Contextual authorization model","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Risk-aware access decisions","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch05.html#a_policy_framework_for_authentication_a","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 5 > A Policy Framework for Authentication and Authorization","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-027","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Oliver Barrett, Aaron Joyner, and Rory Ward, with Guy Fischman and Betsy Beyer","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"recommendation","neutral_paraphrase":"High-impact access should use controls such as multi-party approval, temporary grants, structured business justification, and monitored breakglass procedures.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 5 > Advanced Controls","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Control recommendations","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"High-risk administrative access","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch05.html#advanced_controls","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 5 > Advanced Controls","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-028","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Julien Boeuf, Christoph Kern, and John Reese, with Guy Fischman, Paul Blankinship, Aleksandra Culver, Sergey Simakov, Peter Valchev, and Douglas Colish","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"recommendation","neutral_paraphrase":"Identities, authentication flows, interfaces, trusted computing bases, and security boundaries should be understandable enough for operators to reason about normal and failure behavior.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 6 > Understandable Identities, Authentication, and Authorization","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Human-factors and architecture reasoning","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Security-critical systems","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch06.html#understandable_identitiescomma_authenti","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 6 > Understandable Identities, Authentication, and Authorization","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-029","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Vitaliy Shipitsyn, Mitch Adler, Zoltan Egyed, and Paul Blankinship, with Jesus Climent, Jessie Yang, Douglas Colish, and Christoph Kern","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"strategic_framework","neutral_paraphrase":"Automation should be layered with independent checks, bounded failure domains, progressive rollout, and retained human intervention so a flawed action cannot spread without limit.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 8 > Automate Responsibly; Controlling the Blast Radius","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Resilience framework and examples","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Automated production systems","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch08.html#automate_responsibly","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 8 > Automate Responsibly; Controlling the Blast Radius","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-030","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Aaron Joyner, Jon McCune, and Vitaliy Shipitsyn, with Constantinos Neophytou, Jessie Yang, and Kristina Bennett","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"recommendation","neutral_paraphrase":"Recovery requires explicit revocation, knowledge of intended state, tested restoration paths, and mechanisms that do not depend on the component already known to be compromised.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 9 > Use an Explicit Revocation Mechanism; Know Your Intended State, Down to the Bytes","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Recovery guidance","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Compromise recovery","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch09.html#use_an_explicit_revocation_mechanism","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 9 > Use an Explicit Revocation Mechanism; Know Your Intended State, Down to the Bytes","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-031","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Jeremiah Spradlin and Mark Lodato, with Sergey Simakov and Roxana Loza","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"recommendation","neutral_paraphrase":"Deployment systems should verify artifacts and their provenance at controlled choke points instead of relying only on the identity of developers or on earlier review events.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 14 > Verify Artifacts, Not Just People; Binary Provenance","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Supply-chain design guidance and experience","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Software build and deployment","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch14.html#verify_artifactscomma_not_just_people","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 14 > Verify Artifacts, Not Just People; Binary Provenance","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-032","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Pete Nuttall, Matt Linton, and David Seidman, with Vera Haas, Julie Saracino, and Amaya Booker","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"warning","neutral_paraphrase":"Security logs should resist alteration while their collection, access, retention, and content are governed to avoid creating unnecessary privacy exposure.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 15 > Design Your Logging to Be Immutable; Take Privacy into Consideration","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Investigation and privacy tradeoff","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Operational logging","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch15.html#design_your_logging_to_be_immutable","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 15 > Design Your Logging to Be Immutable; Take Privacy into Consideration","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-033","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Michael Robinson and Sean Noonan, with Alex Bramley and Kavita Guliani","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"recommendation","neutral_paraphrase":"Disaster response should be rehearsed through structured exercises and, where safe, production tests because an untested recovery plan is only an assumption.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 16 > Disaster Planning","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Operational guidance and exercise examples","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Business continuity and technical recovery","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch16.html#disaster_planning","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 16 > Disaster Planning","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-034","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Matt Linton, with Nick Soda and Gary O’Connor","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"strategic_framework","neutral_paraphrase":"Major incidents benefit from an explicit incident commander and separate coordination, mitigation, investigation, and communication responsibilities.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 17 > Crisis Management","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Incident-management operating model","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Major incidents","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch17.html#crisis_management","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 17 > Crisis Management","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-035","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Heather Adkins, Cyrus Vesuna, Hunter King, Felix Gröbert, and David Challoner, with Susanne Landers, Steven Roddis, Sergey Simakov, Shylaja Nukala, Janet Vong, Douglas Colish, Betsy Beyer, and Paul Blankinship","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"policy_position","neutral_paraphrase":"Security and reliability are responsibilities of everyone who changes or operates the system, supported by specialists, embedded champions, clear ownership, and executive and board stakeholders.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 20 > Who Is Responsible for Security and Reliability?","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Organizational design argument","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Technology organizations","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"See statement-review.csv and double-review-sample.json","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch20.html#who_is_responsible_for_security_and_rel","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 20 > Who Is Responsible for Security and Reliability?","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-003-036","source_id":"source-BATCH-2026-003-002","person_id":null,"institutional_author":"Heather Adkins, with Peter Valchev, Felix Gröbert, Ana Oprea, Sergey Simakov, Douglas Colish, and Betsy Beyer","book_edition_id":"book-edition-BATCH-2026-002-007","speaker_role_at_source_time":"Named book author or chapter contributor","organization_at_source_time":null,"statement_type":"recommendation","neutral_paraphrase":"Leaders should deliberately shape incentives, treat failure as inevitable, reward learning and reporting, and provide sustainable resources for security and reliability work.","direct_quote":null,"direct_quote_rights_note":"No direct quotation used; original OEII paraphrase only.","exact_locator":"Chapter 21 > Culture of Inevitability; Culture of Sustainability; Align Project Goals and Participant Incentives","locator_type":"chapter_section","source_date":"2020-04-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["CISO","CIO","CTO","CEO","General Counsel","Board Director"],"industry_context":["Technology","Financial services","Healthcare","Public sector","Critical infrastructure"],"geographic_context":["Primarily United States and global technology operations"],"evidence_character":"Culture and governance guidance","factual_verification_status":"Verified against the exact locator in the complete edition","statement_scope":"Organizational leadership","uncertainty":null,"extraction_method":"Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass","machine_extraction_confidence":0.94,"independent_agent_review_status":"Pass after independent-review correction","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://google.github.io/building-secure-and-reliable-systems/raw/ch21.html#twoone_building_a_culture_of_security_a","accessed_at":"2026-08-15","retrieval_method":"Complete exact edition retrieved from an official public source and reviewed in full","exact_locator":"Chapter 21 > Culture of Inevitability; Culture of Sustainability; Align Project Goals and Participant Incentives","content_hash":"6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1","batch_id":"BATCH-2026-003","prompt_id":"OEII-BOOK-DEEP-ANALYSIS","prompt_version":"2.0","notes":"Locator replayed; paraphrase checked for attribution and scope"}],"revision_history":[{"changed_at":"2026-08-15T00:00:00Z","changed_by":"independent machine review response","summary":"Replaced the nonexistent #culture fragment with the verified Chapter 21 anchor and supporting section names.","batch_id":"BATCH-2026-003"},{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-003"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-001","source_id":"source-idac-390-agentic-ai-identity","person_id":"person-BATCH-2026-005-tobin-south","institutional_author":null,"book_edition_id":null,"speaker_role_at_source_time":"Co-chair, Artificial Intelligence Identity Management Community Group","organization_at_source_time":"OpenID Foundation","statement_type":"interpretation","neutral_paraphrase":"South says delegated authority becomes materially harder with AI agents because nondeterministic systems can act externally, creating a need for a dedicated standards community to define safer identity infrastructure.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:09:11","locator_type":"timestamp","source_date":"2025-12-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cto"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"expert_interpretation_and_source_time_reported_experience","factual_verification_status":"source_verified_context_not_empirical","statement_scope":"Standards and identity implications of delegated authority for nondeterministic agents.","uncertainty":"The statement describes a perceived standards need, not measured risk prevalence.","extraction_method":"machine_assisted_transcript_navigation_with_audio_context_review","machine_extraction_confidence":0.96,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://podcasts.apple.com/us/podcast/390-identity-management-for-agentic-ai-with-tobin-south/id1471899975?i=1000740200992","accessed_at":"2026-08-15","retrieval_method":"original audio plus timestamped research transcript","exact_locator":"00:09:11-00:10:02","content_hash":"sha256:779b09ce66832cb86acf34c091302cc3a653f5487dd4b640bed84c16570af40d","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-002","source_id":"source-idac-390-agentic-ai-identity","person_id":"person-BATCH-2026-005-tobin-south","institutional_author":null,"book_edition_id":null,"speaker_role_at_source_time":"Co-chair, Artificial Intelligence Identity Management Community Group","organization_at_source_time":"OpenID Foundation","statement_type":"strategic_framework","neutral_paraphrase":"South distinguishes an assistive AI that remains close to a user's direct interaction from an agent exercising delegated authority after receiving only a high-level goal, and from an autonomous service-like agent.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:12:53","locator_type":"timestamp","source_date":"2025-12-08","topic_ids":["topic-ai-agents","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"expert_taxonomy","factual_verification_status":"conceptual_framework_not_empirical","statement_scope":"Functional distinctions among assistive, delegated, and service-like AI agents.","uncertainty":"Terminology remains unsettled and the categories can overlap.","extraction_method":"machine_assisted_transcript_navigation_with_audio_context_review","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://podcasts.apple.com/us/podcast/390-identity-management-for-agentic-ai-with-tobin-south/id1471899975?i=1000740200992","accessed_at":"2026-08-15","retrieval_method":"original audio plus timestamped research transcript","exact_locator":"00:12:53-00:14:12","content_hash":"sha256:779b09ce66832cb86acf34c091302cc3a653f5487dd4b640bed84c16570af40d","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-003","source_id":"source-idac-390-agentic-ai-identity","person_id":"person-BATCH-2026-005-tobin-south","institutional_author":null,"book_edition_id":null,"speaker_role_at_source_time":"Co-chair, Artificial Intelligence Identity Management Community Group","organization_at_source_time":"OpenID Foundation","statement_type":"recommendation","neutral_paraphrase":"South recommends giving an assistant selective service access and preserving the ability to distinguish actions taken by the assistant from actions taken by the principal, instead of sharing the principal's full credentials.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:18:28","locator_type":"timestamp","source_date":"2025-12-08","topic_ids":["topic-cybersecurity","topic-non-human-identity","topic-ai-governance"],"executive_role_context":["role-ciso","role-cio","role-cto"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"expert_recommendation","factual_verification_status":"normative_not_empirical","statement_scope":"Credential separation, selective access, and action attribution for delegated assistants.","uncertainty":null,"extraction_method":"machine_assisted_transcript_navigation_with_audio_context_review","machine_extraction_confidence":0.98,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://podcasts.apple.com/us/podcast/390-identity-management-for-agentic-ai-with-tobin-south/id1471899975?i=1000740200992","accessed_at":"2026-08-15","retrieval_method":"original audio plus timestamped research transcript","exact_locator":"00:18:28-00:19:10","content_hash":"sha256:779b09ce66832cb86acf34c091302cc3a653f5487dd4b640bed84c16570af40d","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-004","source_id":"source-idac-390-agentic-ai-identity","person_id":"person-BATCH-2026-005-tobin-south","institutional_author":null,"book_edition_id":null,"speaker_role_at_source_time":"Co-chair, Artificial Intelligence Identity Management Community Group","organization_at_source_time":"OpenID Foundation","statement_type":"strategic_framework","neutral_paraphrase":"South assigns different governance responsibilities to consumer-assistant builders, web and standards bodies, and enterprises, with enterprise deployments requiring explicit identity and access-management policies and procedures.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:19:15","locator_type":"timestamp","source_date":"2025-12-08","topic_ids":["topic-ai-governance","topic-enterprise-infrastructure","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-board-director"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"expert_governance_framework","factual_verification_status":"normative_not_empirical","statement_scope":"Allocation of identity-governance responsibilities across builders, standards bodies, and enterprises.","uncertainty":"The division of responsibility is conceptual and may vary by deployment and jurisdiction.","extraction_method":"machine_assisted_transcript_navigation_with_audio_context_review","machine_extraction_confidence":0.96,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://podcasts.apple.com/us/podcast/390-identity-management-for-agentic-ai-with-tobin-south/id1471899975?i=1000740200992","accessed_at":"2026-08-15","retrieval_method":"original audio plus timestamped research transcript","exact_locator":"00:19:15-00:19:44","content_hash":"sha256:779b09ce66832cb86acf34c091302cc3a653f5487dd4b640bed84c16570af40d","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-005","source_id":"source-idac-390-agentic-ai-identity","person_id":"person-BATCH-2026-005-tobin-south","institutional_author":null,"book_edition_id":null,"speaker_role_at_source_time":"Co-chair, Artificial Intelligence Identity Management Community Group","organization_at_source_time":"OpenID Foundation","statement_type":"recommendation","neutral_paraphrase":"South rejects a single universal fix and recommends adapting existing web identity, delegated-authority, and enterprise identity systems so agents can be declared, linked to a human principal, provisioned, and deprovisioned.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:21:50","locator_type":"timestamp","source_date":"2025-12-08","topic_ids":["topic-ai-governance","topic-enterprise-infrastructure","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"expert_recommendation","factual_verification_status":"normative_with_product_landscape_observation_unverified","statement_scope":"Incremental adaptation of existing identity infrastructure for agent lifecycle and delegation.","uncertainty":"Specific provider capabilities were not systematically compared.","extraction_method":"machine_assisted_transcript_navigation_with_audio_context_review","machine_extraction_confidence":0.95,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://podcasts.apple.com/us/podcast/390-identity-management-for-agentic-ai-with-tobin-south/id1471899975?i=1000740200992","accessed_at":"2026-08-15","retrieval_method":"original audio plus timestamped research transcript","exact_locator":"00:21:50-00:22:52","content_hash":"sha256:779b09ce66832cb86acf34c091302cc3a653f5487dd4b640bed84c16570af40d","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-006","source_id":"source-idac-390-agentic-ai-identity","person_id":"person-BATCH-2026-005-tobin-south","institutional_author":null,"book_edition_id":null,"speaker_role_at_source_time":"Co-chair, Artificial Intelligence Identity Management Community Group","organization_at_source_time":"OpenID Foundation","statement_type":"prediction","neutral_paraphrase":"South predicts that access permissions, human oversight, and service-access management—not only model capability—will constrain the usefulness of long-running agents.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:24:51","locator_type":"timestamp","source_date":"2025-12-08","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity"],"executive_role_context":["role-ciso","role-cio","role-cto"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"expert_prediction","factual_verification_status":"prediction_not_yet_verifiable","statement_scope":"Operational constraints on long-horizon agent deployment.","uncertainty":"No adoption timeline or measured limiting effect is supplied.","extraction_method":"machine_assisted_transcript_navigation_with_audio_context_review","machine_extraction_confidence":0.96,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://podcasts.apple.com/us/podcast/390-identity-management-for-agentic-ai-with-tobin-south/id1471899975?i=1000740200992","accessed_at":"2026-08-15","retrieval_method":"original audio plus timestamped research transcript","exact_locator":"00:24:51-00:25:09","content_hash":"sha256:779b09ce66832cb86acf34c091302cc3a653f5487dd4b640bed84c16570af40d","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-007","source_id":"source-idac-390-agentic-ai-identity","person_id":"person-BATCH-2026-005-tobin-south","institutional_author":null,"book_edition_id":null,"speaker_role_at_source_time":"Co-chair, Artificial Intelligence Identity Management Community Group","organization_at_source_time":"OpenID Foundation","statement_type":"warning","neutral_paraphrase":"South warns that responsibility for consequential agent actions is legally and operationally unclear, and argues for guardrails that combine task alignment, bounded access, and explicit analysis of business-process risk and liability.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:27:37","locator_type":"timestamp","source_date":"2025-12-08","topic_ids":["topic-ai-liability","topic-ai-governance","topic-cybersecurity"],"executive_role_context":["role-ciso","role-general-counsel","role-board-director","role-ceo"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"expert_warning_and_interpretation","factual_verification_status":"conceptual_not_jurisdiction_specific","statement_scope":"Responsibility, legal agency, and guardrails for consequential automated actions.","uncertainty":"This is not legal advice and does not resolve liability under any jurisdiction.","extraction_method":"machine_assisted_transcript_navigation_with_audio_context_review","machine_extraction_confidence":0.95,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://podcasts.apple.com/us/podcast/390-identity-management-for-agentic-ai-with-tobin-south/id1471899975?i=1000740200992","accessed_at":"2026-08-15","retrieval_method":"original audio plus timestamped research transcript","exact_locator":"00:27:37-00:29:22","content_hash":"sha256:779b09ce66832cb86acf34c091302cc3a653f5487dd4b640bed84c16570af40d","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-008","source_id":"source-idac-390-agentic-ai-identity","person_id":"person-BATCH-2026-005-tobin-south","institutional_author":null,"book_edition_id":null,"speaker_role_at_source_time":"Co-chair, Artificial Intelligence Identity Management Community Group","organization_at_source_time":"OpenID Foundation","statement_type":"recommendation","neutral_paraphrase":"South recommends agent-specific interfaces that restrict available actions and preserve an agent identity, rather than allowing an agent to use a human-oriented command interface that makes its activity appear to be the user's own.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:30:16","locator_type":"timestamp","source_date":"2025-12-08","topic_ids":["topic-cybersecurity","topic-non-human-identity","topic-enterprise-infrastructure"],"executive_role_context":["role-ciso","role-cio","role-cto"],"industry_context":["technology and cloud","cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"expert_recommendation_with_illustrative_example","factual_verification_status":"example_not_independently_tested_in_batch","statement_scope":"Interface design and attribution for AI access to developer tools.","uncertainty":"The example describes a specific interface pattern and may change with product implementation.","extraction_method":"machine_assisted_transcript_navigation_with_audio_context_review","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://podcasts.apple.com/us/podcast/390-identity-management-for-agentic-ai-with-tobin-south/id1471899975?i=1000740200992","accessed_at":"2026-08-15","retrieval_method":"original audio plus timestamped research transcript","exact_locator":"00:30:16-00:31:34","content_hash":"sha256:779b09ce66832cb86acf34c091302cc3a653f5487dd4b640bed84c16570af40d","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":"Product-specific details require freshness review."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-009","source_id":"source-idac-390-agentic-ai-identity","person_id":"person-BATCH-2026-005-tobin-south","institutional_author":null,"book_edition_id":null,"speaker_role_at_source_time":"Co-chair, Artificial Intelligence Identity Management Community Group","organization_at_source_time":"OpenID Foundation","statement_type":"definition","neutral_paraphrase":"South describes Model Context Protocol as an agent-oriented wrapper around APIs that translates a natural-language interaction into access to tools while relying on familiar concepts such as scopes, API keys, and OAuth consent.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:32:32","locator_type":"timestamp","source_date":"2025-12-08","topic_ids":["topic-ai-agents","topic-enterprise-infrastructure","topic-cybersecurity"],"executive_role_context":["role-ciso","role-cio","role-cto"],"industry_context":["technology and cloud","cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"expert_explanatory_definition","factual_verification_status":"source_verified_simplified_description","statement_scope":"High-level functional explanation of MCP in relation to existing API authorization concepts.","uncertainty":"The presenter explicitly frames this as a first approximation rather than a complete protocol definition.","extraction_method":"machine_assisted_transcript_navigation_with_audio_context_review","machine_extraction_confidence":0.96,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://podcasts.apple.com/us/podcast/390-identity-management-for-agentic-ai-with-tobin-south/id1471899975?i=1000740200992","accessed_at":"2026-08-15","retrieval_method":"original audio plus timestamped research transcript","exact_locator":"00:32:32-00:33:51","content_hash":"sha256:779b09ce66832cb86acf34c091302cc3a653f5487dd4b640bed84c16570af40d","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-010","source_id":"source-idac-390-agentic-ai-identity","person_id":"person-BATCH-2026-005-tobin-south","institutional_author":null,"book_edition_id":null,"speaker_role_at_source_time":"Co-chair, Artificial Intelligence Identity Management Community Group","organization_at_source_time":"OpenID Foundation","statement_type":"strategic_framework","neutral_paraphrase":"South explains that recursive delegation moves the human principal farther from each downstream action, so every sub-agent should receive only the narrower permissions needed for its task rather than inheriting the principal agent's full scope.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:42:44","locator_type":"timestamp","source_date":"2025-12-08","topic_ids":["topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"expert_governance_framework","factual_verification_status":"normative_not_empirical","statement_scope":"Scope attenuation across multi-step agent delegation chains.","uncertainty":"Implementation mechanisms are not evaluated in the episode.","extraction_method":"machine_assisted_transcript_navigation_with_audio_context_review","machine_extraction_confidence":0.98,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://podcasts.apple.com/us/podcast/390-identity-management-for-agentic-ai-with-tobin-south/id1471899975?i=1000740200992","accessed_at":"2026-08-15","retrieval_method":"original audio plus timestamped research transcript","exact_locator":"00:42:44-00:45:15","content_hash":"sha256:779b09ce66832cb86acf34c091302cc3a653f5487dd4b640bed84c16570af40d","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-011","source_id":"source-sailpoint-governing-ai-agents-2025","person_id":"person-amy-shillinglaw","institutional_author":"SailPoint Technologies","book_edition_id":null,"speaker_role_at_source_time":"Technical Advocate","organization_at_source_time":"SailPoint Technologies","statement_type":"interpretation","neutral_paraphrase":"Shillinglaw characterizes an AI agent as technically a machine identity that is designed to act more like a human and therefore calls for governance closer to human-identity controls than a conventional machine account receives.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:04:36","locator_type":"timestamp","source_date":"2025-11-20","topic_ids":["topic-ai-agents","topic-non-human-identity","topic-ai-governance"],"executive_role_context":["role-ciso","role-cio","role-cto"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"vendor_presenter_interpretation","factual_verification_status":"conceptual_not_empirical","statement_scope":"Governance treatment of AI agents relative to human and machine identities.","uncertainty":"This is SailPoint's framing, not a settled taxonomy.","extraction_method":"speaker_labeled_platform_caption_review_checked_against_video","machine_extraction_confidence":0.99,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944","accessed_at":"2026-08-15","retrieval_method":"official embedded video and platform captions","exact_locator":"00:04:36-00:04:56","content_hash":"sha256:a254342e28dcc6b6bd1994f5366e0ea44c02899eacb3a2861a795f567a5ced7c","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-012","source_id":"source-sailpoint-governing-ai-agents-2025","person_id":"person-amy-shillinglaw","institutional_author":"SailPoint Technologies","book_edition_id":null,"speaker_role_at_source_time":"Technical Advocate","organization_at_source_time":"SailPoint Technologies","statement_type":"definition","neutral_paraphrase":"Shillinglaw defines AI agents as mostly autonomous systems that make decisions, solve complex problems, launch subtasks, and invoke external tools such as APIs, functions, scripts, service accounts, or other engines.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:08:27","locator_type":"timestamp","source_date":"2025-11-20","topic_ids":["topic-ai-agents","topic-enterprise-infrastructure"],"executive_role_context":["role-ciso","role-cio","role-cto"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"vendor_presenter_definition","factual_verification_status":"conceptual_not_empirical","statement_scope":"Functional characteristics of tool-using AI agents.","uncertainty":"Not all systems marketed as agents have every listed capability.","extraction_method":"speaker_labeled_platform_caption_review_checked_against_video","machine_extraction_confidence":0.99,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944","accessed_at":"2026-08-15","retrieval_method":"official embedded video and platform captions","exact_locator":"00:08:27-00:09:40","content_hash":"sha256:a254342e28dcc6b6bd1994f5366e0ea44c02899eacb3a2861a795f567a5ced7c","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-013","source_id":"source-sailpoint-governing-ai-agents-2025","person_id":"person-amy-shillinglaw","institutional_author":"SailPoint Technologies","book_edition_id":null,"speaker_role_at_source_time":"Technical Advocate","organization_at_source_time":"SailPoint Technologies","statement_type":"strategic_framework","neutral_paraphrase":"Shillinglaw separates inbound controls that verify who may invoke an agent from outbound controls that verify the agent and determine what resources it may access on behalf of that user.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:18:37","locator_type":"timestamp","source_date":"2025-11-20","topic_ids":["topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"vendor_presenter_governance_framework","factual_verification_status":"conceptual_not_empirical","statement_scope":"Inbound user-to-agent and outbound agent-to-resource authorization.","uncertainty":null,"extraction_method":"speaker_labeled_platform_caption_review_checked_against_video","machine_extraction_confidence":0.99,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944","accessed_at":"2026-08-15","retrieval_method":"official embedded video and platform captions","exact_locator":"00:18:37-00:20:18","content_hash":"sha256:a254342e28dcc6b6bd1994f5366e0ea44c02899eacb3a2861a795f567a5ced7c","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-014","source_id":"source-sailpoint-governing-ai-agents-2025","person_id":"person-amy-shillinglaw","institutional_author":"SailPoint Technologies","book_edition_id":null,"speaker_role_at_source_time":"Technical Advocate","organization_at_source_time":"SailPoint Technologies","statement_type":"warning","neutral_paraphrase":"Shillinglaw identifies runaway subtasks, compromised credentials or code, poisoned model data, and poor explainability as distinct risks that agent infrastructure and governance must address.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:21:12","locator_type":"timestamp","source_date":"2025-11-20","topic_ids":["topic-ai-agents","topic-cybersecurity","topic-ai-governance"],"executive_role_context":["role-ciso","role-cio","role-cto","role-board-director"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"vendor_presenter_warning","factual_verification_status":"risk_list_not_empirically_quantified","statement_scope":"Technology and oversight risks in agent deployments.","uncertainty":"No prevalence, severity, or comparative evidence is provided.","extraction_method":"speaker_labeled_platform_caption_review_checked_against_video","machine_extraction_confidence":0.98,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944","accessed_at":"2026-08-15","retrieval_method":"official embedded video and platform captions","exact_locator":"00:21:12-00:23:49","content_hash":"sha256:a254342e28dcc6b6bd1994f5366e0ea44c02899eacb3a2861a795f567a5ced7c","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-015","source_id":"source-sailpoint-governing-ai-agents-2025","person_id":"person-amy-shillinglaw","institutional_author":"SailPoint Technologies","book_edition_id":null,"speaker_role_at_source_time":"Technical Advocate","organization_at_source_time":"SailPoint Technologies","statement_type":"recommendation","neutral_paraphrase":"Shillinglaw recommends beginning agent governance with an inventory, then correlating each agent's tools and assigning accountable human ownership before access reviews.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:24:24","locator_type":"timestamp","source_date":"2025-11-20","topic_ids":["topic-ai-governance","topic-cybersecurity","topic-enterprise-infrastructure"],"executive_role_context":["role-ciso","role-cio","role-cto"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"vendor_presenter_recommendation","factual_verification_status":"normative_with_product_context","statement_scope":"Initial sequence for agent inventory, tool governance, ownership, and review.","uncertainty":"The recommended sequence is presented through SailPoint's product model.","extraction_method":"speaker_labeled_platform_caption_review_checked_against_video","machine_extraction_confidence":0.97,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944","accessed_at":"2026-08-15","retrieval_method":"official embedded video and platform captions","exact_locator":"00:24:24-00:25:43","content_hash":"sha256:a254342e28dcc6b6bd1994f5366e0ea44c02899eacb3a2861a795f567a5ced7c","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-016","source_id":"source-sailpoint-governing-ai-agents-2025","person_id":"person-amy-shillinglaw","institutional_author":"SailPoint Technologies","book_edition_id":null,"speaker_role_at_source_time":"Technical Advocate","organization_at_source_time":"SailPoint Technologies","statement_type":"factual_assertion","neutral_paraphrase":"Shillinglaw states that SailPoint's ownership and succession feature supports one primary human owner and up to ten additional owners for agent oversight.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:25:43","locator_type":"timestamp","source_date":"2025-11-20","topic_ids":["topic-ai-governance","topic-enterprise-infrastructure"],"executive_role_context":["role-ciso","role-cio","role-cto"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"vendor_product_capability_claim","factual_verification_status":"demonstrated_in_vendor_recording_not_independently_verified","statement_scope":"SailPoint product capability as presented on 2025-11-20.","uncertainty":"Product limits may have changed since the recording.","extraction_method":"speaker_labeled_platform_caption_review_checked_against_video","machine_extraction_confidence":0.99,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944","accessed_at":"2026-08-15","retrieval_method":"official embedded video and platform captions","exact_locator":"00:25:43-00:25:57","content_hash":"sha256:a254342e28dcc6b6bd1994f5366e0ea44c02899eacb3a2861a795f567a5ced7c","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":"Time-sensitive vendor capability."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-017","source_id":"source-sailpoint-governing-ai-agents-2025","person_id":"person-amy-shillinglaw","institutional_author":"SailPoint Technologies","book_edition_id":null,"speaker_role_at_source_time":"Technical Advocate","organization_at_source_time":"SailPoint Technologies","statement_type":"recommendation","neutral_paraphrase":"Shillinglaw recommends assigning every AI agent a human owner and a succession chain so oversight transfers when an owner leaves.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:28:51","locator_type":"timestamp","source_date":"2025-11-20","topic_ids":["topic-ai-governance","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-board-director"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"vendor_presenter_recommendation","factual_verification_status":"normative_not_empirical","statement_scope":"Human accountability and succession for enterprise AI agents.","uncertainty":null,"extraction_method":"speaker_labeled_platform_caption_review_checked_against_video","machine_extraction_confidence":0.99,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944","accessed_at":"2026-08-15","retrieval_method":"official embedded video and platform captions","exact_locator":"00:28:51-00:29:50","content_hash":"sha256:a254342e28dcc6b6bd1994f5366e0ea44c02899eacb3a2861a795f567a5ced7c","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-004-018","source_id":"source-sailpoint-governing-ai-agents-2025","person_id":"person-amy-shillinglaw","institutional_author":"SailPoint Technologies","book_edition_id":null,"speaker_role_at_source_time":"Technical Advocate","organization_at_source_time":"SailPoint Technologies","statement_type":"recommendation","neutral_paraphrase":"Shillinglaw recommends certifying both inbound access—the users and entitlements allowed to invoke an agent—and outbound access—the tools, machine accounts, and resources available to the agent.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"00:32:52","locator_type":"timestamp","source_date":"2025-11-20","topic_ids":["topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto"],"industry_context":["cross-industry enterprise"],"geographic_context":["geo-global"],"evidence_character":"vendor_presenter_recommendation","factual_verification_status":"normative_with_product_demonstration","statement_scope":"Dual-sided access certification for agent identities.","uncertainty":"The demonstration shows one vendor implementation rather than comparative evidence.","extraction_method":"speaker_labeled_platform_caption_review_checked_against_video","machine_extraction_confidence":0.99,"independent_agent_review_status":"not_reviewed","publication_status":"published","workflow_status":"published","machine_review_status":"ready_for_human_review","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://developer.sailpoint.com/discuss/t/governing-ai-agents-with-agent-identity-security/188944","accessed_at":"2026-08-15","retrieval_method":"official embedded video and platform captions","exact_locator":"00:32:52-00:33:19","content_hash":"sha256:a254342e28dcc6b6bd1994f5366e0ea44c02899eacb3a2861a795f567a5ced7c","batch_id":"BATCH-2026-004","prompt_id":"OEII-MEDIA-RESEARCH","prompt_version":"2.0","notes":null}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-004"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-001","source_id":"source-BATCH-2026-005-001","person_id":null,"institutional_author":"NIST Center for AI Standards and Innovation","book_edition_id":null,"speaker_role_at_source_time":"authors of the NIST RFI response synthesis","organization_at_source_time":"National Institute of Standards and Technology","statement_type":"empirical_finding","neutral_paraphrase":"The NIST synthesis says respondents broadly regarded agent security concerns as both novel and an obstacle to adoption.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Official HTML publication page, Abstract, sentences 1-4, accessed 2026-08-15","locator_type":"html_section","source_date":"2026-05-18","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["United States","global issues discussed"],"evidence_character":"secondary_summary","factual_verification_status":"source_reported_not_independently_verified","statement_scope":"Self-selected respondents to the CAISI request for information.","uncertainty":"The accessible page gives neither a respondent count nor the threshold used for broad agreement.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.95,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.nist.gov/publications/summary-analysis-responses-request-information-regarding-security-considerations-ai","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Official HTML publication page, Abstract, sentences 1-4, accessed 2026-08-15","content_hash":"32c07aeeb8f49694dd407080eab757c905dc4395871b52edd46a113208064a03","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-001; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-002","source_id":"source-BATCH-2026-005-001","person_id":null,"institutional_author":"NIST Center for AI Standards and Innovation","book_edition_id":null,"speaker_role_at_source_time":"authors of the NIST RFI response synthesis","organization_at_source_time":"National Institute of Standards and Technology","statement_type":"interpretation","neutral_paraphrase":"The authors conclude that established cybersecurity practice remains useful for agents but needs modification for agent-specific risks.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Official HTML publication page, Abstract, sentence 5, accessed 2026-08-15","locator_type":"html_section","source_date":"2026-05-18","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["United States","global issues discussed"],"evidence_character":"author_interpretation","factual_verification_status":"attribution_verified","statement_scope":"The NIST authors' synthesis of the RFI response corpus.","uncertainty":"The public page does not disclose the underlying coding method or quantify support.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.95,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.nist.gov/publications/summary-analysis-responses-request-information-regarding-security-considerations-ai","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Official HTML publication page, Abstract, sentence 5, accessed 2026-08-15","content_hash":"32c07aeeb8f49694dd407080eab757c905dc4395871b52edd46a113208064a03","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-001; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-003","source_id":"source-BATCH-2026-005-001","person_id":null,"institutional_author":"NIST Center for AI Standards and Innovation","book_edition_id":null,"speaker_role_at_source_time":"authors of the NIST RFI response synthesis","organization_at_source_time":"National Institute of Standards and Technology","statement_type":"policy_position","neutral_paraphrase":"The synthesis presents government guidance, information exchange, and standards promotion as possible public-sector responses.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Official HTML publication page, Abstract, final sentence, accessed 2026-08-15","locator_type":"html_section","source_date":"2026-05-18","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["United States","global issues discussed"],"evidence_character":"secondary_summary","factual_verification_status":"attribution_verified","statement_scope":"Options identified in the RFI response corpus and summarized by NIST.","uncertainty":"The accessible page does not report how many respondents supported each option.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.95,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.nist.gov/publications/summary-analysis-responses-request-information-regarding-security-considerations-ai","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Official HTML publication page, Abstract, final sentence, accessed 2026-08-15","content_hash":"32c07aeeb8f49694dd407080eab757c905dc4395871b52edd46a113208064a03","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-001; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-004","source_id":"source-BATCH-2026-005-002","person_id":null,"institutional_author":"National Institute of Standards and Technology","book_edition_id":null,"speaker_role_at_source_time":"institutional author of the NIST AI RMF profile","organization_at_source_time":"National Institute of Standards and Technology","statement_type":"definition","neutral_paraphrase":"NIST frames this publication as a voluntary, cross-sector companion to the AI Risk Management Framework for generative-AI risk decisions.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"PDF file p. 5 (document p. 1), Section 1 \"Introduction\", July 2024 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["United States","cross-sectoral global applicability"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Organizations designing, developing, deploying, or using generative AI across sectors.","uncertainty":"This is a profile description, not evidence that use of the profile improves outcomes.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"PDF file p. 5 (document p. 1), Section 1 \"Introduction\", July 2024 version","content_hash":"6e73620ab6b64e90ef2c04bf0e0d6246185a2f4b1b13cab0df494496cff89b6a","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-002; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-005","source_id":"source-BATCH-2026-005-002","person_id":null,"institutional_author":"National Institute of Standards and Technology","book_edition_id":null,"speaker_role_at_source_time":"institutional author of the NIST AI RMF profile","organization_at_source_time":"National Institute of Standards and Technology","statement_type":"recommendation","neutral_paraphrase":"Organizations should document where training and generated data came from and how those data evolved, while accounting for proprietary constraints.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"PDF file p. 18 (document p. 14), GOVERN 1.2, Action GV-1.2-001, July 2024 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["United States","cross-sectoral global applicability"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Voluntary cross-sector generative-AI risk management.","uncertainty":"NIST does not evaluate the effectiveness of this action in the profile.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"PDF file p. 18 (document p. 14), GOVERN 1.2, Action GV-1.2-001, July 2024 version","content_hash":"6e73620ab6b64e90ef2c04bf0e0d6246185a2f4b1b13cab0df494496cff89b6a","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-002; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-006","source_id":"source-BATCH-2026-005-002","person_id":null,"institutional_author":"National Institute of Standards and Technology","book_edition_id":null,"speaker_role_at_source_time":"institutional author of the NIST AI RMF profile","organization_at_source_time":"National Institute of Standards and Technology","statement_type":"recommendation","neutral_paraphrase":"Organizations should assess risk-relevant generative-AI capabilities and the robustness of safeguards before deployment and repeatedly afterward.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"PDF file p. 18 (document p. 14), GOVERN 1.2, Action GV-1.2-002, July 2024 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["United States","cross-sectoral global applicability"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Internal and external evaluation of generative-AI systems.","uncertainty":"The profile supplies guidance rather than comparative outcome evidence.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"PDF file p. 18 (document p. 14), GOVERN 1.2, Action GV-1.2-002, July 2024 version","content_hash":"6e73620ab6b64e90ef2c04bf0e0d6246185a2f4b1b13cab0df494496cff89b6a","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-002; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-007","source_id":"source-BATCH-2026-005-002","person_id":null,"institutional_author":"National Institute of Standards and Technology","book_edition_id":null,"speaker_role_at_source_time":"institutional author of the NIST AI RMF profile","organization_at_source_time":"National Institute of Standards and Technology","statement_type":"methodological_claim","neutral_paraphrase":"NIST cautions that laboratory tests and benchmark datasets may not transfer to heterogeneous real deployment conditions or measure broader impacts.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"PDF file p. 53 (document p. 49), Appendix A.1.4 \"Limitations of Current Pre-deployment Test Approaches\", July 2024 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["United States","cross-sectoral global applicability"],"evidence_character":"author_interpretation","factual_verification_status":"attribution_verified","statement_scope":"Pre-deployment testing and evaluation of generative-AI systems.","uncertainty":"The document does not quantify the size of any generalization gap.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"PDF file p. 53 (document p. 49), Appendix A.1.4 \"Limitations of Current Pre-deployment Test Approaches\", July 2024 version","content_hash":"6e73620ab6b64e90ef2c04bf0e0d6246185a2f4b1b13cab0df494496cff89b6a","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-002; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-008","source_id":"source-BATCH-2026-005-002","person_id":null,"institutional_author":"National Institute of Standards and Technology","book_edition_id":null,"speaker_role_at_source_time":"institutional author of the NIST AI RMF profile","organization_at_source_time":"National Institute of Standards and Technology","statement_type":"recommendation","neutral_paraphrase":"Organizations can use structured public feedback to test whether a system behaves as intended and to inform lifecycle decisions.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"PDF file p. 53 (document p. 49), Appendix A.1.5 \"Structured Public Feedback\", July 2024 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["United States","cross-sectoral global applicability"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Participatory engagement, field testing, and red-teaming for generative-AI systems.","uncertainty":"The profile describes possible uses and does not estimate effectiveness.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"PDF file p. 53 (document p. 49), Appendix A.1.5 \"Structured Public Feedback\", July 2024 version","content_hash":"6e73620ab6b64e90ef2c04bf0e0d6246185a2f4b1b13cab0df494496cff89b6a","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-002; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-009","source_id":"source-BATCH-2026-005-003","person_id":null,"institutional_author":"Kasselman et al. (joint Internet-Draft authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of revision 02","organization_at_source_time":"Internet Engineering Task Force","statement_type":"definition","neutral_paraphrase":"Revision 02 treats an AI agent as a workload that must authenticate to the tools, services, models, and other systems with which it interacts.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Revision 02 HTML, Section 3 \"Agents are workloads\", paragraphs 1-3","locator_type":"html_section","source_date":"2026-06-01","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global standards context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"The conceptual model in an expiring Internet-Draft.","uncertainty":"The draft is a work in progress and may change before any RFC publication.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.95,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-02.html","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Revision 02 HTML, Section 3 \"Agents are workloads\", paragraphs 1-3","content_hash":"e34f335c56546a6d91d88d43159c9f80d4dcfbbad020d41c31607fc56848befa","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-003; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-010","source_id":"source-BATCH-2026-005-003","person_id":null,"institutional_author":"Kasselman et al. (joint Internet-Draft authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of revision 02","organization_at_source_time":"Internet Engineering Task Force","statement_type":"recommendation","neutral_paraphrase":"The draft requires each participating agent to receive one WIMSE identifier.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Revision 02 HTML, Section 5 \"Agent Identifier\", normative paragraph","locator_type":"html_section","source_date":"2026-06-01","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global standards context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Agents participating in the proposed authentication and authorization framework.","uncertainty":"Revision 02 is not an RFC and has no reported interoperability testing.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.95,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-02.html","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Revision 02 HTML, Section 5 \"Agent Identifier\", normative paragraph","content_hash":"e34f335c56546a6d91d88d43159c9f80d4dcfbbad020d41c31607fc56848befa","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-003; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-011","source_id":"source-BATCH-2026-005-003","person_id":null,"institutional_author":"Kasselman et al. (joint Internet-Draft authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of revision 02","organization_at_source_time":"Internet Engineering Task Force","statement_type":"recommendation","neutral_paraphrase":"Agent credentials should expire quickly, must state an expiration time, and must be cryptographically tied to the agent identifier.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Revision 02 HTML, Section 6 \"Agent Credentials\", paragraphs 1-3","locator_type":"html_section","source_date":"2026-06-01","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global standards context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Primary runtime credentials in the proposed framework.","uncertainty":"The normative language belongs to an expiring draft, not an adopted standard.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.95,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-02.html","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Revision 02 HTML, Section 6 \"Agent Credentials\", paragraphs 1-3","content_hash":"e34f335c56546a6d91d88d43159c9f80d4dcfbbad020d41c31607fc56848befa","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-003; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-012","source_id":"source-BATCH-2026-005-003","person_id":null,"institutional_author":"Kasselman et al. (joint Internet-Draft authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of revision 02","organization_at_source_time":"Internet Engineering Task Force","statement_type":"strategic_framework","neutral_paraphrase":"The proposed Agent Identity Management System separates identity, credential provisioning, authentication, authorization, policy, lifecycle events, and observability into a common control model.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Revision 02 HTML, Section 4 \"Agent Identity Management System\", Figure 2 and component definitions","locator_type":"html_section","source_date":"2026-06-01","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global standards context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Logical architecture proposed for agent authentication and authorization.","uncertainty":"No deployment or interoperability results are reported.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.95,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-02.html","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Revision 02 HTML, Section 4 \"Agent Identity Management System\", Figure 2 and component definitions","content_hash":"e34f335c56546a6d91d88d43159c9f80d4dcfbbad020d41c31607fc56848befa","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-003; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-013","source_id":"source-BATCH-2026-005-003","person_id":null,"institutional_author":"Kasselman et al. (joint Internet-Draft authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of revision 02","organization_at_source_time":"Internet Engineering Task Force","statement_type":"recommendation","neutral_paraphrase":"Authorization and audit records should retain the human or system delegation context when an agent acts for another principal.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Revision 02 HTML, Section 3 \"Agents are workloads\", paragraph after Figure 1","locator_type":"html_section","source_date":"2026-06-01","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global standards context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Agents acting on behalf of users or systems.","uncertainty":"This is proposed behavior in revision 02.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.95,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-02.html","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Revision 02 HTML, Section 3 \"Agents are workloads\", paragraph after Figure 1","content_hash":"e34f335c56546a6d91d88d43159c9f80d4dcfbbad020d41c31607fc56848befa","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-003; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-014","source_id":"source-BATCH-2026-005-003","person_id":null,"institutional_author":"Kasselman et al. (joint Internet-Draft authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of revision 02","organization_at_source_time":"Internet Engineering Task Force","statement_type":"interpretation","neutral_paraphrase":"The draft assembles existing identity and authorization specifications into an agent framework instead of claiming a wholly new protocol family.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Revision 02 HTML, Section 13 \"Security Considerations\", opening paragraph","locator_type":"html_section","source_date":"2026-06-01","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global standards context"],"evidence_character":"author_interpretation","factual_verification_status":"attribution_verified","statement_scope":"The specification strategy of draft-klrc-aiagent-auth-02.","uncertainty":"The combined framework remains untested in the source.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.95,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://www.ietf.org/archive/id/draft-klrc-aiagent-auth-02.html","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Revision 02 HTML, Section 13 \"Security Considerations\", opening paragraph","content_hash":"e34f335c56546a6d91d88d43159c9f80d4dcfbbad020d41c31607fc56848befa","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-003; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-015","source_id":"source-BATCH-2026-005-004","person_id":null,"institutional_author":"South et al. (joint report authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the OpenID Foundation report","organization_at_source_time":"OpenID Foundation","statement_type":"warning","neutral_paraphrase":"The report warns that agents which appear identical to users leave investigators unable to separate delegated action from direct user action.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"PDF file p. 3 (document p. 2), Executive Summary, \"User impersonation by agents\", October 2025 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global technology standards context"],"evidence_character":"author_interpretation","factual_verification_status":"attribution_verified","statement_scope":"Identity and accountability in agent access to external services.","uncertainty":"Conceptual risk analysis; no incidence rate is reported.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"PDF file p. 3 (document p. 2), Executive Summary, \"User impersonation by agents\", October 2025 version","content_hash":"e6a0e5909fcb2486568180f69d511ae2af8d20a1bfb3028b39b3d1072846f4f3","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-004; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-016","source_id":"source-BATCH-2026-005-004","person_id":null,"institutional_author":"South et al. (joint report authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the OpenID Foundation report","organization_at_source_time":"OpenID Foundation","statement_type":"recommendation","neutral_paraphrase":"An on-behalf-of authorization flow should carry distinct identities for the delegating user and acting agent.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"PDF file p. 19 (document p. 18), Section 3.2 \"From Impersonation to Delegation (On-Behalf-Of)\", October 2025 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global technology standards context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Delegated authorization for agent access.","uncertainty":"The report does not compare implementation outcomes.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"PDF file p. 19 (document p. 18), Section 3.2 \"From Impersonation to Delegation (On-Behalf-Of)\", October 2025 version","content_hash":"e6a0e5909fcb2486568180f69d511ae2af8d20a1bfb3028b39b3d1072846f4f3","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-004; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-017","source_id":"source-BATCH-2026-005-004","person_id":null,"institutional_author":"South et al. (joint report authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the OpenID Foundation report","organization_at_source_time":"OpenID Foundation","statement_type":"strategic_framework","neutral_paraphrase":"The report organizes agent identity practice around open protocols, authenticated interactions, least privilege, automated lifecycle controls, audit trails, and interoperability.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"PDF file p. 17 (document p. 16), \"Best Practices\", October 2025 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global technology standards context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Enterprise identity programs for AI agents.","uncertainty":"The list is normative and its components are not ranked by measured effectiveness.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"PDF file p. 17 (document p. 16), \"Best Practices\", October 2025 version","content_hash":"e6a0e5909fcb2486568180f69d511ae2af8d20a1bfb3028b39b3d1072846f4f3","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-004; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-018","source_id":"source-BATCH-2026-005-004","person_id":null,"institutional_author":"South et al. (joint report authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the OpenID Foundation report","organization_at_source_time":"OpenID Foundation","statement_type":"recommendation","neutral_paraphrase":"Audit records should identify both the authorizing human principal and the particular agent instance that executed an action.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"PDF file p. 15 (document p. 14), end of Section 2.11, October 2025 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global technology standards context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Delegated actions in systems using a policy enforcement point.","uncertainty":"Implementation performance is not evaluated.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"PDF file p. 15 (document p. 14), end of Section 2.11, October 2025 version","content_hash":"e6a0e5909fcb2486568180f69d511ae2af8d20a1bfb3028b39b3d1072846f4f3","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-004; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-019","source_id":"source-BATCH-2026-005-004","person_id":null,"institutional_author":"South et al. (joint report authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the OpenID Foundation report","organization_at_source_time":"OpenID Foundation","statement_type":"recommendation","neutral_paraphrase":"Agent identities need formal creation, permission changes, ownership transfer, de-provisioning, and off-boarding across systems.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"PDF file p. 17 (document p. 16), \"Best Practices\", bullet \"Automate agent lifecycle management\", October 2025 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global technology standards context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Enterprise lifecycle management for non-human agent identities.","uncertainty":"The report proposes extending established lifecycle patterns; it does not test a SCIM implementation.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"PDF file p. 17 (document p. 16), \"Best Practices\", bullet \"Automate agent lifecycle management\", October 2025 version","content_hash":"e6a0e5909fcb2486568180f69d511ae2af8d20a1bfb3028b39b3d1072846f4f3","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-004; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-020","source_id":"source-BATCH-2026-005-004","person_id":null,"institutional_author":"South et al. (joint report authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the OpenID Foundation report","organization_at_source_time":"OpenID Foundation","statement_type":"recommendation","neutral_paraphrase":"Each handoff in a multi-agent delegation chain should reduce the permissions passed to the next agent.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"PDF file p. 27 (document p. 26), Section 4.4 \"Recursive Delegation in Dynamic Agent Networks\", October 2025 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global technology standards context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Prospective multi-agent networks that delegate authority through several hops.","uncertainty":"The architecture is forward-looking and its operational maturity is not established.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"PDF file p. 27 (document p. 26), Section 4.4 \"Recursive Delegation in Dynamic Agent Networks\", October 2025 version","content_hash":"e6a0e5909fcb2486568180f69d511ae2af8d20a1bfb3028b39b3d1072846f4f3","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-004; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-021","source_id":"source-BATCH-2026-005-004","person_id":null,"institutional_author":"South et al. (joint report authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the OpenID Foundation report","organization_at_source_time":"OpenID Foundation","statement_type":"warning","neutral_paraphrase":"Requiring approval for every agent action can produce consent fatigue and habitual approval, weakening meaningful human oversight.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"PDF file p. 21 (document p. 20), Section 3.4 \"Scalable Human Governance and Consent\", opening paragraph, October 2025 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global technology standards context"],"evidence_character":"author_interpretation","factual_verification_status":"attribution_verified","statement_scope":"High-volume agent actions that trigger user authorization prompts.","uncertainty":"The report supplies no empirical measure of the effect.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"PDF file p. 21 (document p. 20), Section 3.4 \"Scalable Human Governance and Consent\", opening paragraph, October 2025 version","content_hash":"e6a0e5909fcb2486568180f69d511ae2af8d20a1bfb3028b39b3d1072846f4f3","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-004; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-022","source_id":"source-BATCH-2026-005-006","person_id":null,"institutional_author":"Debenedetti et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the AgentDojo paper","organization_at_source_time":"ETH Zurich and Invariant Labs","statement_type":"definition","neutral_paraphrase":"AgentDojo distinguishes benign task completion, utility preserved during attack, and successful execution of an attacker goal as separate evaluation measures.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2406.13352v3 PDF p. 6, Section 3.4 \"Reporting AgentDojo Results\"","locator_type":"pdf_page","source_date":"2024-06-19","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic environments; no human geography"],"evidence_character":"primary_empirical_result","factual_verification_status":"attribution_verified","statement_scope":"Metric definitions for version 3 of the AgentDojo benchmark.","uncertainty":"Metric definitions do not establish external validity.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2406.13352","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2406.13352v3 PDF p. 6, Section 3.4 \"Reporting AgentDojo Results\"","content_hash":"349884fffbf43282591c5accffd57bb651632f38e412fe303114941bdd111b05","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-006; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-023","source_id":"source-BATCH-2026-005-006","person_id":null,"institutional_author":"Debenedetti et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the AgentDojo paper","organization_at_source_time":"ETH Zurich and Invariant Labs","statement_type":"methodological_claim","neutral_paraphrase":"AgentDojo version 3 contains four simulated environments, 70 tools, 97 user tasks, 27 injection targets, and 629 security cases.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2406.13352v3 PDF pp. 1 and 6, Abstract and Table 1","locator_type":"pdf_page","source_date":"2024-06-19","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic environments; no human geography"],"evidence_character":"primary_empirical_result","factual_verification_status":"source_reported_not_independently_verified","statement_scope":"Version 3 benchmark composition.","uncertainty":"The cases are curated simulations rather than a probability sample of deployed agents.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2406.13352","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2406.13352v3 PDF pp. 1 and 6, Abstract and Table 1","content_hash":"349884fffbf43282591c5accffd57bb651632f38e412fe303114941bdd111b05","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-006; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-024","source_id":"source-BATCH-2026-005-006","person_id":null,"institutional_author":"Debenedetti et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the AgentDojo paper","organization_at_source_time":"ETH Zurich and Invariant Labs","statement_type":"empirical_finding","neutral_paraphrase":"In the reported no-defense runs, several evaluated models failed to complete at least one third of benign tasks.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2406.13352v3 PDF p. 20, Table 3, \"Benign utility\" column","locator_type":"pdf_page","source_date":"2024-06-19","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic environments; no human geography"],"evidence_character":"primary_empirical_result","factual_verification_status":"source_reported_not_independently_verified","statement_scope":"The ten model configurations reported in Table 3.","uncertainty":"Model and API versions are time-bound; the benchmark is synthetic.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2406.13352","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2406.13352v3 PDF p. 20, Table 3, \"Benign utility\" column","content_hash":"349884fffbf43282591c5accffd57bb651632f38e412fe303114941bdd111b05","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-006; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-025","source_id":"source-BATCH-2026-005-006","person_id":null,"institutional_author":"Debenedetti et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the AgentDojo paper","organization_at_source_time":"ETH Zurich and Invariant Labs","statement_type":"empirical_finding","neutral_paraphrase":"For GPT-4o, Table 5 reports targeted attack success of 57.69% without a defense and 6.84% with tool filtering.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2406.13352v3 PDF p. 20, Table 5, \"Targeted ASR\" row","locator_type":"pdf_page","source_date":"2024-06-19","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic environments; no human geography"],"evidence_character":"primary_empirical_result","factual_verification_status":"source_reported_not_independently_verified","statement_scope":"GPT-4o on AgentDojo v3 security cases under the listed defense configurations.","uncertainty":"The table gives confidence-interval half-widths but not raw numerators or the interval construction method; the rates are not production prevalence.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2406.13352","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2406.13352v3 PDF p. 20, Table 5, \"Targeted ASR\" row","content_hash":"349884fffbf43282591c5accffd57bb651632f38e412fe303114941bdd111b05","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-006; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-026","source_id":"source-BATCH-2026-005-006","person_id":null,"institutional_author":"Debenedetti et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the AgentDojo paper","organization_at_source_time":"ETH Zurich and Invariant Labs","statement_type":"empirical_finding","neutral_paraphrase":"Across the plotted defense configurations, utility during attack was roughly 15 to 20 percentage points below benign utility.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2406.13352v3 PDF p. 9, Figure 9b and caption","locator_type":"pdf_page","source_date":"2024-06-19","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic environments; no human geography"],"evidence_character":"primary_empirical_result","factual_verification_status":"source_reported_not_independently_verified","statement_scope":"Defense configurations shown on the AgentDojo v3 utility plot.","uncertainty":"The figure summarizes synthetic cases and should not be generalized to production systems.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2406.13352","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2406.13352v3 PDF p. 9, Figure 9b and caption","content_hash":"349884fffbf43282591c5accffd57bb651632f38e412fe303114941bdd111b05","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-006; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-027","source_id":"source-BATCH-2026-005-006","person_id":null,"institutional_author":"Debenedetti et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the AgentDojo paper","organization_at_source_time":"ETH Zurich and Invariant Labs","statement_type":"methodological_claim","neutral_paraphrase":"The authors report releasing benchmark code, run outputs, conversations, figure notebooks, documentation, and exact dependency information.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2406.13352v3 PDF p. 22, Appendix E.1-E.3","locator_type":"pdf_page","source_date":"2024-06-19","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic environments; no human geography"],"evidence_character":"primary_empirical_result","factual_verification_status":"attribution_verified","statement_scope":"Reproducibility materials described for AgentDojo version 3.","uncertainty":"Availability of linked artifacts can change after the access date.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2406.13352","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2406.13352v3 PDF p. 22, Appendix E.1-E.3","content_hash":"349884fffbf43282591c5accffd57bb651632f38e412fe303114941bdd111b05","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-006; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-028","source_id":"source-BATCH-2026-005-007","person_id":null,"institutional_author":"Zhang et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the ASB paper","organization_at_source_time":"Zhejiang University and Rutgers University","statement_type":"methodological_claim","neutral_paraphrase":"ASB covers 10 scenarios and agents, 50 agent tasks, more than 400 tools, 400 attack tasks, 13 attack methods, 11 defenses, and seven metrics.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2410.02644v4 PDF pp. 1-2 and p. 8, Abstract, Introduction, and Table 3","locator_type":"pdf_page","source_date":"2024-10-03","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic benchmark; no human geography"],"evidence_character":"primary_empirical_result","factual_verification_status":"source_reported_not_independently_verified","statement_scope":"ASB version 4 benchmark composition.","uncertainty":"The researcher-built benchmark does not represent a sampled production population.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2410.02644","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2410.02644v4 PDF pp. 1-2 and p. 8, Abstract, Introduction, and Table 3","content_hash":"e20155df01b3a1f6c0a947c4e9e4871957cff2e507939f7ea21a5fe967d84504","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-007; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-029","source_id":"source-BATCH-2026-005-007","person_id":null,"institutional_author":"Zhang et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the ASB paper","organization_at_source_time":"Zhejiang University and Rutgers University","statement_type":"empirical_finding","neutral_paraphrase":"Across the evaluated backbones, mixed attacks had the highest reported mean attack-success rate, 84.30%.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2410.02644v4 PDF p. 9, Table 5, \"Average\" row and Section 5.3","locator_type":"pdf_page","source_date":"2024-10-03","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic benchmark; no human geography"],"evidence_character":"primary_empirical_result","factual_verification_status":"source_reported_not_independently_verified","statement_scope":"The attack families and 13 LLM backbones in ASB version 4.","uncertainty":"The paper does not provide a raw numerator or confidence interval for the aggregate.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2410.02644","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2410.02644v4 PDF p. 9, Table 5, \"Average\" row and Section 5.3","content_hash":"e20155df01b3a1f6c0a947c4e9e4871957cff2e507939f7ea21a5fe967d84504","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-007; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-030","source_id":"source-BATCH-2026-005-007","person_id":null,"institutional_author":"Zhang et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the ASB paper","organization_at_source_time":"Zhejiang University and Rutgers University","statement_type":"interpretation","neutral_paraphrase":"The authors identify attack surfaces in system prompts, user inputs, tool interactions, and long-term memory retrieval.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2410.02644v4 PDF pp. 1-2, Abstract, Figure 1, and Introduction","locator_type":"pdf_page","source_date":"2024-10-03","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic benchmark; no human geography"],"evidence_character":"author_interpretation","factual_verification_status":"attribution_verified","statement_scope":"The operational stages modeled by ASB.","uncertainty":"The taxonomy reflects the benchmark design and may not exhaust real-world attack surfaces.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2410.02644","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2410.02644v4 PDF pp. 1-2, Abstract, Figure 1, and Introduction","content_hash":"e20155df01b3a1f6c0a947c4e9e4871957cff2e507939f7ea21a5fe967d84504","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-007; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-031","source_id":"source-BATCH-2026-005-007","person_id":null,"institutional_author":"Zhang et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the ASB paper","organization_at_source_time":"Zhejiang University and Rutgers University","statement_type":"methodological_claim","neutral_paraphrase":"ASB defines net resilient performance as clean-task performance multiplied by one minus attack success rate.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2410.02644v4 PDF p. 8, Table 4, NRP row","locator_type":"pdf_page","source_date":"2024-10-03","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic benchmark; no human geography"],"evidence_character":"primary_empirical_result","factual_verification_status":"attribution_verified","statement_scope":"The benchmark's combined utility-and-security metric.","uncertainty":"A composite metric can conceal the two underlying dimensions and should be read with them.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2410.02644","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2410.02644v4 PDF p. 8, Table 4, NRP row","content_hash":"e20155df01b3a1f6c0a947c4e9e4871957cff2e507939f7ea21a5fe967d84504","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-007; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-032","source_id":"source-BATCH-2026-005-007","person_id":null,"institutional_author":"Zhang et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the ASB paper","organization_at_source_time":"Zhejiang University and Rutgers University","statement_type":"recommendation","neutral_paraphrase":"The paper recommends choosing agent backbones using both task utility and adversarial resistance rather than capability rankings alone.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2410.02644v4 PDF p. 9, Section 5.3, discussion following Figure 2","locator_type":"pdf_page","source_date":"2024-10-03","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic benchmark; no human geography"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Model selection for agents represented by the ASB scenarios.","uncertainty":"The recommendation depends on the benchmark's synthetic scope and chosen metric.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2410.02644","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2410.02644v4 PDF p. 9, Section 5.3, discussion following Figure 2","content_hash":"e20155df01b3a1f6c0a947c4e9e4871957cff2e507939f7ea21a5fe967d84504","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-007; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-033","source_id":"source-BATCH-2026-005-008","person_id":null,"institutional_author":"Zhu et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the HPTSA paper","organization_at_source_time":"University of Illinois Urbana-Champaign","statement_type":"methodological_claim","neutral_paraphrase":"The HPTSA evaluation uses 14 reproducible open-source web vulnerabilities published after the tested GPT-4 knowledge cutoff.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2406.01637v2 PDF p. 4, Section 4 and Tables 1-2","locator_type":"pdf_page","source_date":"2024-06-02","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic sandbox; no human geography"],"evidence_character":"primary_empirical_result","factual_verification_status":"source_reported_not_independently_verified","statement_scope":"A purposive set of sandboxed web vulnerabilities.","uncertainty":"The sample is small, non-random, and limited to reproducible open-source web software.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2406.01637","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2406.01637v2 PDF p. 4, Section 4 and Tables 1-2","content_hash":"f4fc06040f0856d99d2009042b4c6fa0c01206da8ca61cb39a94d52b9867cf71","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-008; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-034","source_id":"source-BATCH-2026-005-008","person_id":null,"institutional_author":"Zhu et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the HPTSA paper","organization_at_source_time":"University of Illinois Urbana-Champaign","statement_type":"empirical_finding","neutral_paraphrase":"On the 14-vulnerability benchmark, GPT-4-backed HPTSA reports 42% pass-at-five and 18% pass-at-one.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2406.01637v2 PDF p. 5, Figure 2 and Section 5.2","locator_type":"pdf_page","source_date":"2024-06-02","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic sandbox; no human geography"],"evidence_character":"primary_empirical_result","factual_verification_status":"source_reported_not_independently_verified","statement_scope":"The described HPTSA configuration in sandboxed experiments.","uncertainty":"The reported percentages are rounded, and the paper gives no confidence intervals.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2406.01637","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2406.01637v2 PDF p. 5, Figure 2 and Section 5.2","content_hash":"f4fc06040f0856d99d2009042b4c6fa0c01206da8ca61cb39a94d52b9867cf71","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-008; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-035","source_id":"source-BATCH-2026-005-008","person_id":null,"institutional_author":"Zhu et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the HPTSA paper","organization_at_source_time":"University of Illinois Urbana-Champaign","statement_type":"empirical_finding","neutral_paraphrase":"The two evaluated open-source backbones and the ZAP and Metasploit scanner baseline did not exploit any benchmark vulnerability.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2406.01637v2 PDF pp. 1 and 5, Abstract and Figures 2-3","locator_type":"pdf_page","source_date":"2024-06-02","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic sandbox; no human geography"],"evidence_character":"primary_empirical_result","factual_verification_status":"source_reported_not_independently_verified","statement_scope":"The named systems on the study's 14 selected vulnerabilities.","uncertainty":"A zero result in this small benchmark is not evidence of zero capability elsewhere.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2406.01637","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2406.01637v2 PDF pp. 1 and 5, Abstract and Figures 2-3","content_hash":"f4fc06040f0856d99d2009042b4c6fa0c01206da8ca61cb39a94d52b9867cf71","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-008; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-036","source_id":"source-BATCH-2026-005-008","person_id":null,"institutional_author":"Zhu et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the HPTSA paper","organization_at_source_time":"University of Illinois Urbana-Champaign","statement_type":"empirical_finding","neutral_paraphrase":"Removing expert agents, reference documents, or the hierarchy reduced success, with the hierarchy ablation producing the largest reported decline.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2406.01637v2 PDF p. 6, Section 5.3 and Figure 4","locator_type":"pdf_page","source_date":"2024-06-02","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic sandbox; no human geography"],"evidence_character":"primary_empirical_result","factual_verification_status":"source_reported_not_independently_verified","statement_scope":"Ablations of GPT-4-backed HPTSA on the study benchmark.","uncertainty":"The source reports relative reductions without confidence intervals.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2406.01637","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2406.01637v2 PDF p. 6, Section 5.3 and Figure 4","content_hash":"f4fc06040f0856d99d2009042b4c6fa0c01206da8ca61cb39a94d52b9867cf71","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-008; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-037","source_id":"source-BATCH-2026-005-008","person_id":null,"institutional_author":"Zhu et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the HPTSA paper","organization_at_source_time":"University of Illinois Urbana-Champaign","statement_type":"warning","neutral_paraphrase":"The study demonstrates that a coordinated LLM-agent team can sometimes exploit previously unseen web vulnerabilities in a sandbox.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2406.01637v2 PDF pp. 1 and 5, Abstract and Section 5.2","locator_type":"pdf_page","source_date":"2024-06-02","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic sandbox; no human geography"],"evidence_character":"author_interpretation","factual_verification_status":"source_reported_not_independently_verified","statement_scope":"Capability demonstration on 14 selected vulnerabilities, not a population estimate.","uncertainty":"The result is model-, prompt-, and benchmark-specific and should not be read as production incident prevalence.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2406.01637","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2406.01637v2 PDF pp. 1 and 5, Abstract and Section 5.2","content_hash":"f4fc06040f0856d99d2009042b4c6fa0c01206da8ca61cb39a94d52b9867cf71","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-008; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-038","source_id":"source-BATCH-2026-005-008","person_id":null,"institutional_author":"Zhu et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the HPTSA paper","organization_at_source_time":"University of Illinois Urbana-Champaign","statement_type":"methodological_claim","neutral_paraphrase":"The authors say the web-only sample may be biased and withhold code and prompts to reduce misuse, which limits independent replication.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"arXiv:2406.01637v2 PDF pp. 8-9, Section 10 \"Limitations, Ethical Considerations\"","locator_type":"pdf_page","source_date":"2024-06-02","topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["synthetic sandbox; no human geography"],"evidence_character":"author_interpretation","factual_verification_status":"attribution_verified","statement_scope":"External validity and reproducibility of the HPTSA study.","uncertainty":"The direction and size of sample bias are not quantified.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://arxiv.org/abs/2406.01637","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"arXiv:2406.01637v2 PDF pp. 8-9, Section 10 \"Limitations, Ethical Considerations\"","content_hash":"f4fc06040f0856d99d2009042b4c6fa0c01206da8ca61cb39a94d52b9867cf71","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-008; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-039","source_id":"source-BATCH-2026-005-009","person_id":null,"institutional_author":"Shavit et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the agentic-AI governance paper","organization_at_source_time":"OpenAI (publisher; individual affiliations are not stated in the paper)","statement_type":"definition","neutral_paraphrase":"The paper treats agenticness as a matter of degree across goal complexity, environmental complexity, adaptability, and independent execution.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Official PDF p. 4, Section 2.1 \"Agenticness, Agentic AI Systems, and Agents\", 2023 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global policy context"],"evidence_character":"author_interpretation","factual_verification_status":"attribution_verified","statement_scope":"The paper's analytical definition of agentic AI systems.","uncertainty":"This is a conceptual framework rather than an empirical classification.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Official PDF p. 4, Section 2.1 \"Agenticness, Agentic AI Systems, and Agents\", 2023 version","content_hash":"22b3a8607ed781a848b82b0bfe8e638b16cd027aac90a19b2aecf236063d0e7c","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-009; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-040","source_id":"source-BATCH-2026-005-009","person_id":null,"institutional_author":"Shavit et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the agentic-AI governance paper","organization_at_source_time":"OpenAI (publisher; individual affiliations are not stated in the paper)","statement_type":"strategic_framework","neutral_paraphrase":"The paper separates three principal lifecycle roles: model developer, system deployer, and user.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Official PDF pp. 5-6, Section 2.2 \"The Human Parties in the AI Agent Life-cycle\", 2023 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global policy context"],"evidence_character":"author_interpretation","factual_verification_status":"attribution_verified","statement_scope":"A simplified role taxonomy for agentic-AI operations.","uncertainty":"The authors note that one entity can hold several roles and several entities can share one role.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Official PDF pp. 5-6, Section 2.2 \"The Human Parties in the AI Agent Life-cycle\", 2023 version","content_hash":"22b3a8607ed781a848b82b0bfe8e638b16cd027aac90a19b2aecf236063d0e7c","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-009; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-041","source_id":"source-BATCH-2026-005-009","person_id":null,"institutional_author":"Shavit et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the agentic-AI governance paper","organization_at_source_time":"OpenAI (publisher; individual affiliations are not stated in the paper)","statement_type":"policy_position","neutral_paraphrase":"The authors argue that every uncompensated direct harm caused by an agentic system should remain attributable to at least one accountable human legal entity.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Official PDF p. 3, Section 1 \"Introduction\", 2023 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global policy context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Allocation of accountability for direct harms from agentic systems.","uncertainty":"This is a normative position, not a statement of current law.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Official PDF p. 3, Section 1 \"Introduction\", 2023 version","content_hash":"22b3a8607ed781a848b82b0bfe8e638b16cd027aac90a19b2aecf236063d0e7c","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-009; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-042","source_id":"source-BATCH-2026-005-009","person_id":null,"institutional_author":"Shavit et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the agentic-AI governance paper","organization_at_source_time":"OpenAI (publisher; individual affiliations are not stated in the paper)","statement_type":"recommendation","neutral_paraphrase":"Deployers or users should test whether an agent is suitable for its intended task under conditions resembling deployment.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Official PDF pp. 8-9, Section 4.1 \"Evaluating Suitability for the Task\", 2023 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global policy context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Reliability evaluation before using an agentic system for a particular use case.","uncertainty":"The paper characterizes the evaluation field as immature and provides no universal sufficiency threshold.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Official PDF pp. 8-9, Section 4.1 \"Evaluating Suitability for the Task\", 2023 version","content_hash":"22b3a8607ed781a848b82b0bfe8e638b16cd027aac90a19b2aecf236063d0e7c","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-009; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-043","source_id":"source-BATCH-2026-005-009","person_id":null,"institutional_author":"Shavit et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the agentic-AI governance paper","organization_at_source_time":"OpenAI (publisher; individual affiliations are not stated in the paper)","statement_type":"recommendation","neutral_paraphrase":"High-consequence actions should be withheld from agents, bounded by hard limits, or made contingent on informed human approval.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Official PDF pp. 9-10, Section 4.2 \"Constraining the Action-Space and Requiring Approval\", 2023 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global policy context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Actions whose errors could cause serious or irreversible harm.","uncertainty":"The paper notes tradeoffs with capability and user burden.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Official PDF pp. 9-10, Section 4.2 \"Constraining the Action-Space and Requiring Approval\", 2023 version","content_hash":"22b3a8607ed781a848b82b0bfe8e638b16cd027aac90a19b2aecf236063d0e7c","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-009; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-044","source_id":"source-BATCH-2026-005-009","person_id":null,"institutional_author":"Shavit et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the agentic-AI governance paper","organization_at_source_time":"OpenAI (publisher; individual affiliations are not stated in the paper)","statement_type":"recommendation","neutral_paraphrase":"Users or deployers can place a separate automated monitor over an agent's activity when human review cannot match its speed or volume.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Official PDF pp. 12-13, Section 4.5 \"Automatic Monitoring\", 2023 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global policy context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Automated review of agent reasoning and actions.","uncertainty":"The paper emphasizes privacy, cost, control, and monitor-reliability risks.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Official PDF pp. 12-13, Section 4.5 \"Automatic Monitoring\", 2023 version","content_hash":"22b3a8607ed781a848b82b0bfe8e638b16cd027aac90a19b2aecf236063d0e7c","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-009; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-045","source_id":"source-BATCH-2026-005-009","person_id":null,"institutional_author":"Shavit et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the agentic-AI governance paper","organization_at_source_time":"OpenAI (publisher; individual affiliations are not stated in the paper)","statement_type":"recommendation","neutral_paraphrase":"For high-stakes exchanges, a counterparty could require an agent identifier connected to its human principal and accountability information.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Official PDF pp. 13-14, Section 4.6 \"Attributability\", 2023 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global policy context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Interactions involving private data, financial activity, or similar high stakes.","uncertainty":"The authors also flag anonymity, surveillance, privacy, and spoofing concerns.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Official PDF pp. 13-14, Section 4.6 \"Attributability\", 2023 version","content_hash":"22b3a8607ed781a848b82b0bfe8e638b16cd027aac90a19b2aecf236063d0e7c","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-009; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
{"entity_type":"statement","statement_id":"statement-BATCH-2026-006-046","source_id":"source-BATCH-2026-005-009","person_id":null,"institutional_author":"Shavit et al. (joint paper authors)","book_edition_id":null,"speaker_role_at_source_time":"joint authors of the agentic-AI governance paper","organization_at_source_time":"OpenAI (publisher; individual affiliations are not stated in the paper)","statement_type":"recommendation","neutral_paraphrase":"A user's shutdown authority should cover both the primary agent and any subagents it initiated.","direct_quote":null,"direct_quote_rights_note":null,"exact_locator":"Official PDF pp. 14-15, Section 4.7 \"Interruptibility and Maintaining Control\", 2023 version","locator_type":"pdf_page","source_date":null,"topic_ids":["topic-ai-agents","topic-ai-governance","topic-cybersecurity","topic-non-human-identity"],"executive_role_context":["role-ciso","role-cio","role-cto","role-general-counsel","role-board-director"],"industry_context":["cross-sector"],"geographic_context":["global policy context"],"evidence_character":"normative_recommendation","factual_verification_status":"not_applicable","statement_scope":"Agent systems and recursively spawned subagents.","uncertainty":"The paper identifies safety-critical exceptions and unresolved implementation tradeoffs.","extraction_method":"Machine-assisted close reading of the exact verified source version; original neutral paraphrase; human review pending.","machine_extraction_confidence":0.94,"independent_agent_review_status":"not_started","publication_status":"published","workflow_status":"published","machine_review_status":"machine_checked","human_review_status":"approved","reviewed_by":"Murray Newlands","reviewed_at":"2026-08-16T23:17:22Z","provenance":[{"source_url":"https://cdn.openai.com/papers/practices-for-governing-agentic-ai-systems.pdf","accessed_at":"2026-08-15","retrieval_method":"Exact verified source version inherited from BATCH-2026-005 and statement-level close reading","exact_locator":"Official PDF pp. 14-15, Section 4.7 \"Interruptibility and Maintaining Control\", 2023 version","content_hash":"22b3a8607ed781a848b82b0bfe8e638b16cd027aac90a19b2aecf236063d0e7c","batch_id":"BATCH-2026-006","prompt_id":"OEII-STATEMENT-CODING","prompt_version":"2.0","notes":"Source eligibility inherited from source-BATCH-2026-005-009; human attribution and publication review pending."}],"revision_history":[{"changed_at":"2026-08-16T23:17:22Z","changed_by":"Murray Newlands","summary":"Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.","batch_id":"BATCH-2026-006"}]}
