Trust Controller CBA vendor demonstration

CoverageTC-01 to TC-28

Objective coverage

Every objective CBA set, with its current status, who owns it, what proves it and where that artefact lives. 19 of 28 carry a linked artefact today.

This page is generated from objectives/tc-objectives.yaml each time it is served, which is also what the continuous integration gate reads. The gate fails a claimed status that carries no linked artefact. It cannot enforce that somebody read the artefact, so an objective moves to evidenced or recorded only when a person has actually opened it.

The same table as one file

  • 6Not startedNot started. No artefact is claimed and none is linked.
  • 3BuildingUnder construction. Part of it runs, and the rest is named in the entry.
  • 4BuiltIt runs, verified against the live stack.
  • 0RecordedA clip exists and someone has watched it end to end.
  • 15EvidencedAn authored artefact exists and someone has read it.
  • 0Not applicableOut of scope for this milestone, with the reason stated.
ObjectiveWhat CBA asked forStatusOwnerProven byArtefacts
TC-01Governance Control StrengthBoth

Registering an Agent in a marketplace or catalogue triggers the appropriate Agent Identity workflow based on an Agent Identity Manifest.

DemonstrateIntegrate

ID Partners handoff. ID Partners builds and shows the mock marketplace/catalogue and owns the Agent Identity Manifest schema. Raidiam shows the receiving half: a manifest committed to git drives the Connect API to create the software statement, assign roles and activate authority claims, with a rejected manifest producing a rejected outcome.

BuiltSharedscene-01-manifest-to-identitylive scenedoctracker-reconciliation.md
TC-02Strategic Architecture FitBoth

The Trust Controller is the control-plane governance layer for Agent Identity approval, suspension and withdrawal decisions.

Demonstrate

BuiltRaidiamscene-02-control-planelive scenedoccapability-envelope-spike.md
TC-03Integration FitBoth

Token flow with an Agent Identity trust check before access is granted to a protected service or resource.

DemonstrateIntegrate

BuildingRaidiamscene-03-token-trust-checklive scenenone yet
TC-04Governance Control StrengthBoth

An Agent lifecycle event such as suspension or retirement triggers revocation or disablement of associated Agent Identities.

DemonstrateIntegrate

Not startedRaidiamscene-06-revoke-and-propagatelive scenenone yet
TC-05Integration FitBoth

Agent Identity metadata service lifecycle control for publishing, updating and withdrawing OpenID Federation entity configuration or equivalent trust metadata, as the authoritative source for Agent Identity.

DemonstrateIntegrate

BuiltRaidiamscene-02-control-planelive scenedoccapability-envelope-spike.md
TC-06Strategic Architecture FitVendor demo

Clarify the marketplace or catalogue role as the authoritative Agent registration and discovery channel, separate from Agent Identity and trust authority.

EvidenceDemonstrate

ID Partners handoff. ID Partners owns the marketplace side of the responsibility model.

EvidencedSharedcontent-domain-boundaryauthored contentdoccontent-domain-boundary.md
TC-07Delivery FitBoth

Orchestration across Agent workflow events and Agent Identity workflows for registration, approval, publication, suspension and withdrawal.

DemonstrateIntegrate

ID Partners handoff. Marketplace-side workflow steps and RACI are ID Partners'.

Not startedSharedscene-01-manifest-to-identitylive scenenone yet
TC-08Governance Control StrengthBoth

Policy enforcement for Agent Identity trust decisions using roles, scopes, claims, attributes, environment context or risk signals.

DemonstrateIntegrate

Not startedRaidiamscene-05-guardrailslive scenenone yet
TC-09Compatibility FitProof of concept

Federation bridge capability for existing authorization servers, including trust-chain resolution, client metadata resolution and dynamic client onboarding for Agent Identities.

EvidenceIntegrate

ID Partners handoff. ID Partners owns the Ping Federate bridge. Mina confirmed on 6 August that ID Partners has a module that walks the trust chain. Raidiam supplies the federation surface and the written integration design; ID Partners confirms it against the CBA estate.

EvidencedID Partnerscontent-federation-bridgeauthored contentdoccontent-federation-bridge.md
TC-10Integration FitBoth

The Trust Controller is the authoritative source of Agent Identity trust metadata, with downstream Identity Providers consuming it to establish local client representations and perform runtime token issuance.

DemonstrateIntegrate

BuildingRaidiamscene-04-dynamic-onboardinglive scenedocdeployment-hostnames.md
TC-11Strategic Architecture FitBoth

Validate the strategic OpenID Federation target state by operating as the authoritative Trust Controller for Agent Identity trust publication, while demonstrating a credible transition from the near-term overlay deployment model to native federation.

EvidenceDemonstrate

EvidencedRaidiamcontent-target-stateauthored contentdoccontent-target-state.md
TC-12Compatibility FitBoth

Overlay compatibility with the current enterprise authorization server landscape.

EvidenceIntegrate

ID Partners handoff. ID Partners owns the Ping and Entra compatibility matrix and the required enterprise changes. David was explicit on 6 August that this belongs in the second presentation, not the vendor demo.

EvidencedID Partnerscontent-overlay-compatibilityauthored contentdoccontent-overlay-compatibility.md
TC-13Deployment Model FitBoth

Deployment model options and CBA boundary implications.

Evidence

EvidencedRaidiamcontent-deployment-modelauthored contentdoccontent-deployment-model.md
TC-14Security Risk FitBoth

Identity and authentication controls for PoC users, services, marketplace integrations, Trust Controller integrations and vendor access.

EvidenceDemonstrateIntegrate

EvidencedRaidiamcontent-access-controlsauthored contentdoccontent-access-controls.md
TC-15Security Risk FitProof of concept

Secure configuration and hardening of PoC components.

EvidenceIntegrate

EvidencedRaidiamcontent-hardeningauthored contentdoccontent-hardening.md
TC-16Security Risk FitProof of concept

Vulnerability identification and remediation approach for PoC components.

EvidenceIntegrate

EvidencedRaidiamcontent-vulnerability-managementauthored contentdoccontent-vulnerability-management.md
TC-17Security Risk FitProof of concept

Network protection, segmentation and isolation for the PoC deployment pattern.

EvidenceIntegrate

EvidencedRaidiamcontent-network-architectureauthored contentdoccontent-network-architecture.md
TC-18Security Risk FitBoth

Security logging for authentication, access, Agent workflow triggers, Agent Identity trust decisions, policy changes, errors and administrative actions.

DemonstrateIntegrate

BuildingRaidiamscene-07-audit-traillive scenenone yet
TC-19Delivery FitBoth

Observability and monitoring sufficient to operate and investigate the Trust Controller.

EvidenceDemonstrate

EvidencedRaidiamcontent-observabilityauthored contentdoccontent-observability.md
TC-20Security Risk FitProof of concept

Data protection and recovery controls for PoC data and trust artefacts.

EvidenceIntegrate

EvidencedRaidiamcontent-data-protectionauthored contentdoccontent-data-protection.md
TC-21Delivery FitProof of concept

Recoverability and rebuild approach for the PoC environment.

EvidenceIntegrate

EvidencedRaidiamcontent-recoveryauthored contentdoccontent-recovery.md
TC-22Delivery FitBoth

Support, operating model and vendor enablement for implementation and BAU transition.

Evidence

ID Partners handoff. ID Partners owns the in region support and enablement model as reseller.

EvidencedID Partnerscontent-support-modelauthored contentdoccontent-support-model.md
TC-23Commercial Procurement FitVendor demo

Commercial and procurement implications of the solution and deployment model.

Evidence

ID Partners handoff. ID Partners owns commercials as reseller. Raidiam supplies a capability inventory so nothing priceable is given away by accident: post quantum PKI, credential issuance, SSF publication, token status lists, federation hub.

EvidencedID Partnerscontent-commercialauthored contentdoccontent-commercial.md
TC-24Delivery FitBoth

Implementation gap severity and internal build effort for capability not available out of the box.

Evidence

EvidencedSharedcontent-gap-registerauthored contentdoccontent-gap-register.md
TC-25Governance Control StrengthBoth

Agent Identity metadata and external evidence handling, including manifest-sourced ownership, environment, version, grant types, endpoints, keys, hashes, repository links, SBOM references and other evidence pointers.

DemonstrateIntegrate

ID Partners handoff. ID Partners owns the manifest schema; Raidiam shows what Connect can record and return.

Not startedSharedscene-08-metadata-and-evidencelive scenenone yet
TC-26Security Risk FitBoth

Cryptographic assurance for Agent Identity trust metadata using enterprise-managed key material, without the Trust Controller storing private keys.

DemonstrateEvidence

Not startedRaidiamscene-09-kms-held-keyslive scenenone yet
TC-27Integration FitBoth

Govern, version and expose an approved capability envelope for an Agent Identity, and make that capability metadata available to downstream identity, policy, entitlement and enforcement platforms.

DemonstrateIntegrate

BuiltRaidiamscene-10-capability-envelopelive scenedoccapability-envelope-spike.mddoctc27-subordinate-statement.jwt
TC-28Integration FitBoth

Automated Workload Identity registration through APIs and integration with CBA's existing SPIFFE/SPIRE-based workload attestation capability.

DemonstrateEvidenceIntegrate

ID Partners handoff. SPIFFE and SPIRE integration deferred to ID Partners.

Not startedID Partnersscene-11-instance-attestationlive scenenone yet

Tracker last reviewed 2026-08-10. Demonstration 2026-08-24. Source document Agentic IDAM - Trust Controller PoC Objectives - FINAL (2).pdf, Robert Harkin, Technical Delivery Manager, CBA.