nhi.sgit.ai / options

The options

Each option answers the same scenario in the same columns. The first three are chosen to be different in kind rather than three of the same category. More options will be added over time — each dated, each re-runnable.

Evidence status

All current assessments are preliminary. They are drawn from published, cited analysis and the corpus's own documented experience — they have not yet been re-run hands-on against the scenario. Each page states its verification date and what a full re-run requires. The re-run queue is tracked on the comms page.

OptionKindWorks for rented agents?Status
SPIFFE / SPIREOpen standard, self-hostedNoPreliminary · verified 18 Aug 2026
A commercial workload-identity brokerCommercial productPartiallyPreliminary · verified 18 Aug 2026
Do nothing — broad credential + hopeThe baseline almost everybody runsYes — that is the problemPreliminary · verified 18 Aug 2026

Beyond the anchor scenario

The same method applied to a different concrete scenario: shared drives for agents (verified 16 Aug 2026) — two sessions sharing a file area. Four option families mapped; per-agent identity, agent-level attribution and per-agent encryption were unavailable in all of them, and the only granularity was segregation.

Why these three first