NIST SP 800-207 zero trust for agents

Locate policy decision and enforcement near the resource; re-evaluate subject, action and context

01 / Source and scope

Who acts, and what changes?

Principal and authority origin

Agent or workload requesting a protected resource. Organization policy administrator and task issuer.

Consequential action

Invoke an API that changes resource state.

02 / Action-time control

Make the requested effect testable.

SP 800-207 is architectural guidance; network location and valid identity alone do not authorize a specific effect. Locate policy decision and enforcement near the resource; re-evaluate subject, action and context.

OriginOrganization policy administrator and task issuer
RequestInvoke an API that changes resource state
DecisionEvaluate and enforce before effect

03 / Evidence and responsibility

Permission, execution, and outcome are separate.

Policy version, decision, enforcement event and resource result.

ProofGrid can help express and record authority decisions; the organization owns its zero-trust architecture and enforcement coverage.

Primary source

Check the governing material.

Architecture discussion

Map one consequential action from origin to observed outcome.

Request a Conversation