CoverageTC-01 to TC-28
Objective coverage
Every objective CBA set, with its current status, who owns it, what proves it and where that artefact lives. 19 of 28 carry a linked artefact today.
This page is generated from objectives/tc-objectives.yaml each time it is served,
which is also what the continuous integration gate reads. The gate fails a claimed status that
carries no linked artefact. It cannot enforce that somebody read the artefact, so an objective
moves to evidenced or recorded only when a person has actually opened it.
- 6Not startedNot started. No artefact is claimed and none is linked.
- 3BuildingUnder construction. Part of it runs, and the rest is named in the entry.
- 4BuiltIt runs, verified against the live stack.
- 0RecordedA clip exists and someone has watched it end to end.
- 15EvidencedAn authored artefact exists and someone has read it.
- 0Not applicableOut of scope for this milestone, with the reason stated.
| Objective | What CBA asked for | Status | Owner | Proven by | Artefacts |
|---|---|---|---|---|---|
| TC-01Governance Control StrengthBoth | Registering an Agent in a marketplace or catalogue triggers the appropriate Agent Identity workflow based on an Agent Identity Manifest. DemonstrateIntegrate ID Partners handoff. ID Partners builds and shows the mock marketplace/catalogue and owns the Agent Identity Manifest schema. Raidiam shows the receiving half: a manifest committed to git drives the Connect API to create the software statement, assign roles and activate authority claims, with a rejected manifest producing a rejected outcome. | Built | Shared | scene-01-manifest-to-identitylive scene | doctracker-reconciliation.md |
| TC-02Strategic Architecture FitBoth | The Trust Controller is the control-plane governance layer for Agent Identity approval, suspension and withdrawal decisions. Demonstrate | Built | Raidiam | scene-02-control-planelive scene | doccapability-envelope-spike.md |
| TC-03Integration FitBoth | Token flow with an Agent Identity trust check before access is granted to a protected service or resource. DemonstrateIntegrate | Building | Raidiam | scene-03-token-trust-checklive scene | none yet |
| TC-04Governance Control StrengthBoth | An Agent lifecycle event such as suspension or retirement triggers revocation or disablement of associated Agent Identities. DemonstrateIntegrate | Not started | Raidiam | scene-06-revoke-and-propagatelive scene | none yet |
| TC-05Integration FitBoth | Agent Identity metadata service lifecycle control for publishing, updating and withdrawing OpenID Federation entity configuration or equivalent trust metadata, as the authoritative source for Agent Identity. DemonstrateIntegrate | Built | Raidiam | scene-02-control-planelive scene | doccapability-envelope-spike.md |
| TC-06Strategic Architecture FitVendor demo | Clarify the marketplace or catalogue role as the authoritative Agent registration and discovery channel, separate from Agent Identity and trust authority. EvidenceDemonstrate ID Partners handoff. ID Partners owns the marketplace side of the responsibility model. | Evidenced | Shared | content-domain-boundaryauthored content | doccontent-domain-boundary.md |
| TC-07Delivery FitBoth | Orchestration across Agent workflow events and Agent Identity workflows for registration, approval, publication, suspension and withdrawal. DemonstrateIntegrate ID Partners handoff. Marketplace-side workflow steps and RACI are ID Partners'. | Not started | Shared | scene-01-manifest-to-identitylive scene | none yet |
| TC-08Governance Control StrengthBoth | Policy enforcement for Agent Identity trust decisions using roles, scopes, claims, attributes, environment context or risk signals. DemonstrateIntegrate | Not started | Raidiam | scene-05-guardrailslive scene | none yet |
| TC-09Compatibility FitProof of concept | Federation bridge capability for existing authorization servers, including trust-chain resolution, client metadata resolution and dynamic client onboarding for Agent Identities. EvidenceIntegrate ID Partners handoff. ID Partners owns the Ping Federate bridge. Mina confirmed on 6 August that ID Partners has a module that walks the trust chain. Raidiam supplies the federation surface and the written integration design; ID Partners confirms it against the CBA estate. | Evidenced | ID Partners | content-federation-bridgeauthored content | doccontent-federation-bridge.md |
| TC-10Integration FitBoth | The Trust Controller is the authoritative source of Agent Identity trust metadata, with downstream Identity Providers consuming it to establish local client representations and perform runtime token issuance. DemonstrateIntegrate | Building | Raidiam | scene-04-dynamic-onboardinglive scene | docdeployment-hostnames.md |
| TC-11Strategic Architecture FitBoth | Validate the strategic OpenID Federation target state by operating as the authoritative Trust Controller for Agent Identity trust publication, while demonstrating a credible transition from the near-term overlay deployment model to native federation. EvidenceDemonstrate | Evidenced | Raidiam | content-target-stateauthored content | doccontent-target-state.md |
| TC-12Compatibility FitBoth | Overlay compatibility with the current enterprise authorization server landscape. EvidenceIntegrate ID Partners handoff. ID Partners owns the Ping and Entra compatibility matrix and the required enterprise changes. David was explicit on 6 August that this belongs in the second presentation, not the vendor demo. | Evidenced | ID Partners | content-overlay-compatibilityauthored content | doccontent-overlay-compatibility.md |
| TC-13Deployment Model FitBoth | Deployment model options and CBA boundary implications. Evidence | Evidenced | Raidiam | content-deployment-modelauthored content | doccontent-deployment-model.md |
| TC-14Security Risk FitBoth | Identity and authentication controls for PoC users, services, marketplace integrations, Trust Controller integrations and vendor access. EvidenceDemonstrateIntegrate | Evidenced | Raidiam | content-access-controlsauthored content | doccontent-access-controls.md |
| TC-15Security Risk FitProof of concept | Secure configuration and hardening of PoC components. EvidenceIntegrate | Evidenced | Raidiam | content-hardeningauthored content | doccontent-hardening.md |
| TC-16Security Risk FitProof of concept | Vulnerability identification and remediation approach for PoC components. EvidenceIntegrate | Evidenced | Raidiam | content-vulnerability-managementauthored content | doccontent-vulnerability-management.md |
| TC-17Security Risk FitProof of concept | Network protection, segmentation and isolation for the PoC deployment pattern. EvidenceIntegrate | Evidenced | Raidiam | content-network-architectureauthored content | doccontent-network-architecture.md |
| TC-18Security Risk FitBoth | Security logging for authentication, access, Agent workflow triggers, Agent Identity trust decisions, policy changes, errors and administrative actions. DemonstrateIntegrate | Building | Raidiam | scene-07-audit-traillive scene | none yet |
| TC-19Delivery FitBoth | Observability and monitoring sufficient to operate and investigate the Trust Controller. EvidenceDemonstrate | Evidenced | Raidiam | content-observabilityauthored content | doccontent-observability.md |
| TC-20Security Risk FitProof of concept | Data protection and recovery controls for PoC data and trust artefacts. EvidenceIntegrate | Evidenced | Raidiam | content-data-protectionauthored content | doccontent-data-protection.md |
| TC-21Delivery FitProof of concept | Recoverability and rebuild approach for the PoC environment. EvidenceIntegrate | Evidenced | Raidiam | content-recoveryauthored content | doccontent-recovery.md |
| TC-22Delivery FitBoth | Support, operating model and vendor enablement for implementation and BAU transition. Evidence ID Partners handoff. ID Partners owns the in region support and enablement model as reseller. | Evidenced | ID Partners | content-support-modelauthored content | doccontent-support-model.md |
| TC-23Commercial Procurement FitVendor demo | Commercial and procurement implications of the solution and deployment model. Evidence ID Partners handoff. ID Partners owns commercials as reseller. Raidiam supplies a capability inventory so nothing priceable is given away by accident: post quantum PKI, credential issuance, SSF publication, token status lists, federation hub. | Evidenced | ID Partners | content-commercialauthored content | doccontent-commercial.md |
| TC-24Delivery FitBoth | Implementation gap severity and internal build effort for capability not available out of the box. Evidence | Evidenced | Shared | content-gap-registerauthored content | doccontent-gap-register.md |
| TC-25Governance Control StrengthBoth | Agent Identity metadata and external evidence handling, including manifest-sourced ownership, environment, version, grant types, endpoints, keys, hashes, repository links, SBOM references and other evidence pointers. DemonstrateIntegrate ID Partners handoff. ID Partners owns the manifest schema; Raidiam shows what Connect can record and return. | Not started | Shared | scene-08-metadata-and-evidencelive scene | none yet |
| TC-26Security Risk FitBoth | Cryptographic assurance for Agent Identity trust metadata using enterprise-managed key material, without the Trust Controller storing private keys. DemonstrateEvidence | Not started | Raidiam | scene-09-kms-held-keyslive scene | none yet |
| TC-27Integration FitBoth | Govern, version and expose an approved capability envelope for an Agent Identity, and make that capability metadata available to downstream identity, policy, entitlement and enforcement platforms. DemonstrateIntegrate | Built | Raidiam | scene-10-capability-envelopelive scene | doccapability-envelope-spike.mddoctc27-subordinate-statement.jwt |
| TC-28Integration FitBoth | Automated Workload Identity registration through APIs and integration with CBA's existing SPIFFE/SPIRE-based workload attestation capability. DemonstrateEvidenceIntegrate ID Partners handoff. SPIFFE and SPIRE integration deferred to ID Partners. | Not started | ID Partners | scene-11-instance-attestationlive scene | none yet |
Tracker last reviewed 2026-08-10. Demonstration 2026-08-24. Source document Agentic IDAM - Trust Controller PoC Objectives - FINAL (2).pdf, Robert Harkin, Technical Delivery Manager, CBA.