Skip to content

blog: NIST agent overlays need task-scoped permissions [DO NOT MERGE before Aug 3]#781

Draft
amavashev wants to merge 2 commits into
mainfrom
blog/nist-agent-overlays
Draft

blog: NIST agent overlays need task-scoped permissions [DO NOT MERGE before Aug 3]#781
amavashev wants to merge 2 commits into
mainfrom
blog/nist-agent-overlays

Conversation

@amavashev

@amavashev amavashev commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

⚠️ DO NOT MERGE BEFORE AUGUST 3, 2026

This post is dated 2026-08-03. It now states the European Commission's published enforcement schedule without pretending the future date has already passed.

Pre-merge checklist (August 3)

Summary

New post: NIST Agent Overlays Need Task-Scoped Permissions (blog/nist-agent-overlays-need-task-scoped-permissions.md).

The revised article accurately presents COSAiS overlays as proposed, voluntary starting points. It maps CSA's task-scoping gap to a composition of short-lived credentials, OAuth/PBAC or capability policy, application validation, approvals, and consumable limits. Cycles is positioned as cumulative budget/exposure accounting that complements rather than replaces IAM, tool authorization, or argument validation.

The audit section now requires correlated identity, application, authorization, budget-decision, and outcome evidence, and explicitly states what Cycles evidence does not prove by itself.

Review trail

  • Comprehensive factual pass against NIST COSAiS, the NIST FAQ and initiative announcement, CSA's research note, and European Commission guidance
  • Independent link/SEO and terminology/style passes
  • Removed future-as-past wording, unsupported “first program”/audit anecdotes, categorical IAM and audit claims, and the singular “missing control” framing
  • Renamed the post and route to match the corrected scope
  • Review outcome: REVISE-MAJOR → ready after fixes, with publication-date verification still required

Test plan

  • npm install (0 vulnerabilities)
  • npm run build (VitePress + 9 PDFs)
  • npm test (93/93)
  • npm run check:implementation-drift (17/17 sources)
  • Targeted link reachability (26/26)
  • Frontmatter: title 48/51, description 151/160
  • GitHub CI and Documentation Health
  • Publication-day checklist above

amavashev added 2 commits July 6, 2026 11:54
Tier-2 post, publish date 2026-08-03 (hold merge until on/after Aug 2;
lede references GPAI enforcement commencing in past tense). COSAiS
agent overlays + CSA gap analysis with verbatim-verified blockquote;
the task-context-scoping gap mapped to consumable, per-run authority.
Fact-check fixes applied: "among the first US government programs...
security and interoperability standards" per CSA framing, corrected
initiative link to the NIST announcement, predictive-AI outline
scoping. Review cycles 1-2 + codex (2 rounds, SHIP) applied. Depends
on the agent-identity PR for one link.
Sync the draft with current main, qualify the proposed voluntary overlays,
separate IAM permissions from consumable budgets, and clarify the limits
of budget-lifecycle evidence.
@amavashev amavashev changed the title blog: NIST agent overlays and the missing control [DO NOT MERGE before Aug 2] blog: NIST agent overlays need task-scoped permissions [DO NOT MERGE before Aug 3] Jul 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant