In November 2016, I gave a presentation at CISA that proposed something simple: every enterprise, regardless of size or sector, needs to be able to answer four questions about every principal operating on its networks.
Not at onboarding. Not at audit time. Continuously.
Those four questions became the foundation of the CDM program’s Identity and Access Management capability — a framework used across U.S. federal agencies to govern who has access to what, under what conditions, and whether they’re behaving accordingly. We called the four dimensions TRUST, CRED, PRIV, and BEHAVE and they were central to the CDM Program Phase 2.
Over the next decade, I watched that framework grow. We extended it from human employees to contractors to non-person entities — service accounts, devices, software processes. We rewired it for cloud architectures. We anchored it to Zero Trust. Each evolution required rethinking some assumptions. None of them required a new framework.
Then agentic AI arrived.
Not chatbots. Not RPA scripts. I mean autonomous AI systems that perceive context, form plans, invoke tools, take consequential actions, and — critically — spawn and delegate to other AI agents. Systems that can traverse your entire privilege landscape in seconds. Systems that can be manipulated mid-task by content they encounter in the environment. Systems that are being deployed in production environments right now, largely without the governance scaffolding they require.
I’ve been thinking hard about whether TRUST, CRED, PRIV, and BEHAVE are sufficient for this new class of principal. My answer is yes — but only if we’re willing to rethink what each dimension actually means when the principal has no background investigation, lives for 30 seconds, acquires privilege at runtime, and can’t tell you why it did what it did.
That’s what this series is about.
Over the next six topics, I’ll make a specific argument: the four dimensions of identity governance are necessary and sufficient for governing agentic AI. Most assumptions we originally built into each dimension were built for a human — and agents are not humans and the assumptions will necessarily change.
Here’s the series:
- Topic 1: What the four dimensions actually are — and why “dimensions” is the right word
- Topic 2: Why agentic AI is a category break, not an incremental extension of NPE governance
- Topic 3: What TRUST and CRED mean when your principal has no vetting history and lives in milliseconds
- Topic 4: What PRIV means when privilege is acquired at runtime and needs to be recomputed with each additional agent that is instantiated
- Topic 5: What BEHAVE means when behavior is defined by task and the AI’s goal achievement changes the behavior it exhibits
- Topic 6: The Master Agent Record — the governance artifact that operationalizes all four dimensions for agents
I’m writing this as someone who spent years inside CISA building the framework — and who believes it was designed to be durable precisely because it was built around the right questions, not the current technology.
The framework holds. But the work ahead is significant.
— Ross Foard