The options
Each option answers the same scenario in the same columns. The first three are chosen to be different in kind rather than three of the same category. More options will be added over time — each dated, each re-runnable.
All current assessments are preliminary. They are drawn from published, cited analysis and the corpus's own documented experience — they have not yet been re-run hands-on against the scenario. Each page states its verification date and what a full re-run requires. The re-run queue is tracked on the comms page.
| Option | Kind | Works for rented agents? | Status |
|---|---|---|---|
| SPIFFE / SPIRE | Open standard, self-hosted | No | Preliminary · verified 18 Aug 2026 |
| A commercial workload-identity broker | Commercial product | Partially | Preliminary · verified 18 Aug 2026 |
| Do nothing — broad credential + hope | The baseline almost everybody runs | Yes — that is the problem | Preliminary · verified 18 Aug 2026 |
Beyond the anchor scenario
The same method applied to a different concrete scenario: shared drives for agents (verified 16 Aug 2026) — two sessions sharing a file area. Four option families mapped; per-agent identity, agent-level attribution and per-agent encryption were unavailable in all of them, and the only granularity was segregation.
Why these three first
- The open standard is the mature answer for agents you run — assessed so its real cost and its real precondition are on the record.
- A commercial broker is the buy-side of the same population, plus the vendors' partial answers for SaaS access.
- The do-nothing baseline is what almost everybody is actually doing, and it deserves the same honest columns as everything else — the brief's open question "does the do-nothing baseline get assessed properly?" is answered yes.