Agent Authorization Your Auditors Can Verify

AIC binds every agent action to an accountable principal — with capability limits, delegation evidence, and offline-verifiable authorization, built on standards your security team already trusts.

draft-wei-aic-identity-cert-01 · draft-wei-aic-jwt-00 IPR 7553 · 7565 · Royalty-Free Open Source 13/13 Independent Interop

What Enterprises Get

AIC answers the question IAM leaves open: who authorized this agent action, why, and under what limits?

Accountability

Every agent action is cryptographically attributable to the principal who signed its delegation — traceable in audit, not just in policy.

Delegation with Bounds

Capabilities, constraints, and lifetime are signed into a DelegationAuthorization, so agents operate within a verifiable permission envelope.

Offline-Verifiable

Authorization evidence verifies without external database lookups — critical for edge, air-gapped, and intermittently connected deployments.

Standards-Based

Two IETF Experimental drafts with a Royalty-Free IPR commitment, and an independent implementation reproducing 13/13 conformance cases.

Performance at Scale

16,000+ regular and 8,000+ AIC certificates per second on one x86 machine, benchmarked against a modeled 500,000-agent workload.

Open & Auditable

Fully open-source reference implementation in five languages, with published security and gateway audit reports.

Measured, Not Promised

Public benchmarks on documented hardware, with MariaDB persistence — reproducible from the open repository.

16k+ /s
Regular certificate issuance
8k+ /s
AIC certificate issuance
500k
Modeled concurrent agents
13/13
Independent conformance cases

Fits Your Stack, Does Not Replace It

AIC extends your existing trust infrastructure rather than demanding a new one.

Existing PKI / CA & HSM

The X.509 profile rides your current CA chain and signing hardware; no new trust anchor required.

TLS / mTLS

AIC is a standard X.509 v3 extension — authentication stays in TLS, authorization verification happens at the gateway.

Web & OAuth

The AIC-JWT profile brings the same model to HTTP, SaaS, and browser pipelines.

Gateway Enforcement

A zero-trust gateway evaluates principal grant ∩ agent capabilities ∩ runtime policy on every request — TCP, HTTP, and UDP.

Capability Registry

Machine-readable, signed capability schemes let different organizations share a common authorization vocabulary.

AIC is additive: your IAM, PKI, and policy systems stay in place. AIC adds the cryptographically bound delegation layer between agent identity and authorization decisions.

Built for Compliance Conversations

The accountability and traceability properties enterprises are being asked to demonstrate.

EU AI Act

Effective human oversight and traceability for high-risk AI: agent actions map to the human who authorized them.

NIST AI RMF

Accountability and transparency as first-class properties, not afterthoughts.

Audit & Non-Repudiation

Immutable decision records with identity, principal, capability, decision, and timestamp.

Authority Separation

Issuer authority and principal delegation authority are cryptographically separated — a compromised CA cannot mint new principal grants.

Pilot Program

We work directly with a small number of design partners to deploy AIC in real infrastructure and shape the standard together.

01

Contact

Email the pilot team; tell us about your agent workloads and existing PKI/IAM.

02

Scoping

A short call to map AIC onto your architecture and pick a pilot use case.

03

Pilot

Joint integration with direct engineering support and conformance testing.

04

Evaluate

Review audit trails, performance, and fit; decide on production rollout.

What Partners Get

Direct Engineering Support

Hands-on integration help from the implementers — not a ticket queue.

Conformance Kit

Access to the independent interoperability test suite and joint conformance results.

Influence the Drafts

Real deployment feedback shapes the next IETF draft revisions.

Optional Case Study

Co-publish a public case study, or keep the engagement confidential.

Start the Conversation

We respond to every serious inquiry. Tell us where your agents act, and we will show you how AIC fits.

Licensing: engine and core are AGPL-3.0; all other repositories are Apache-2.0. Commercial licensing for proprietary embedding is available on request — ask us at pki@varwof.com.