Control-plane architecture · compliance traceability
Which control-plane architectures actually line up with real standards.
A follow-up to the hands-on OpenShell/c=US demonstration: a structured, AI-assisted comparison of five candidate control-plane architectures against verified security and compliance standards, plus a sixth category testing OpenShell and c=US together rather than as competitors.
Method note. Numeric judgments below come from TypeSafe's Jev (System One) model, run once, on 2026-09-28. Facts stated as facts (standards bodies, publication numbers, dates) were independently verified by search, not judged by Jev — the two are kept visibly separate throughout, per this project's own convention.
Five architectures, four real standards
Every candidate checked against NIST SP 800-63 (Digital Identity Guidelines), the NIST AI Risk Management Framework plus its Generative AI Profile (AI 600-1), the OWASP Multi-Agentic System Threat Modeling Guide, and a combined ISO/IEC 27001 + CIS Controls category — all four already relevant to, or already listed on, this project's own compliance materials.
| NIST SP 800-63 (identity) | NIST AI RMF / AI 600-1 | OWASP Agentic Threat Modeling | ISO 27001 / CIS Controls | |
|---|---|---|---|---|
| c=US (X.500/LDAP + mTLS) | 0.76 | 0.51 | 0.72 | 0.65 |
| OpenShell | 0.24 | 0.62 | 0.63 | 0.71 |
| gVisor | 0.17 | 0.42 | 0.35 | 0.56 |
| Firecracker / E2B | 0.17 | 0.42 | 0.35 | 0.47 |
| SPIFFE/SPIRE | 0.76 | 0.59 | 0.76 | 0.66 |
| OpenShell + c=US, combined | 0.82 | 0.77 | 0.83 | 0.84 |
Each cell: probability that adopting that architecture would meaningfully help satisfy, or provide relevant technical evidence toward, that standard. Darker = lower, brighter green = higher.
Two different jobs, and the standards notice
The pattern isn't noise. c=US's own design and SPIFFE/SPIRE — the two identity architectures — score highest on the identity standard and the threat-modeling guide, which explicitly covers identity and trust boundaries. The three sandboxing architectures all score low there, correctly, since none of them do identity work. Within the sandboxes, OpenShell separates from gVisor and Firecracker/E2B on every column, most sharply on general infosec controls, where its agent-aware policy language and credential-provider design map more directly onto CIS-style technical safeguards than a generic, non-agent-aware sandbox does.
OpenShell and c=US together, not versus each other
Every row above treats the candidates as alternatives — but that misses what this project actually runs: OpenShell sandboxing an agent's own reasoning while c=US's identity layer handles the mTLS and directory decision, exactly as demonstrated in the identity-vs-runtime case study. Scored as its own category against the same four standards, the combination beats both individual architectures on every standard — not just the better of the two:
| Standard | c=US alone | OpenShell alone | Combined |
|---|---|---|---|
| NIST SP 800-63 | 0.76 | 0.24 | 0.82 |
| NIST AI RMF | 0.51 | 0.62 | 0.77 |
| OWASP Agentic | 0.72 | 0.63 | 0.83 |
| ISO 27001 / CIS | 0.65 | 0.71 | 0.84 |
Asked directly whether this reflects genuine complementarity or noise around the stronger score, Jev returned 1.87 out of 2 (confidence 0.80, 90% probability on “meaningfully stronger — the two genuinely complement each other's gaps”). c=US's weak spot (general infosec controls) sits close to OpenShell's strength there; OpenShell's weak spot (identity) is exactly c=US's strength.
What this checked, and what it found
The combined architecture is the strongest option on every standard tested
Not an average of the two, and not just the higher of the two — it exceeds both on all four, the numeric signature of two systems actually covering each other's gaps rather than sitting side by side.
X.500 is a real, ratified international standard
Dual-published as ITU-T X.500 and ISO/IEC 9594, jointly maintained by ITU-T and ISO/IEC JTC1, 9th edition (2019), active and current. Not a private product or single vendor's technology.
No NIST standard exists yet specifically for “agentic AI”
Verified by search, not assumed. Closest current NIST coverage: the AI Risk Management Framework 1.0 (2023) plus the Generative AI Profile, AI 600-1 (2024). This project's poster already says “TBD agentic AI requirements,” which is accurate as written.
Sources and underlying data
What this page draws on
- Identity vs. runtime: an agentic control plane — the hands-on OpenShell/c=US demonstration this analysis follows from.
- NVIDIA/OpenShell · Google/gVisor · Firecracker microVM · SPIFFE/SPIRE
- NIST SP 800-63 · NIST AI RMF · OWASP GenAI Security Project
- Full raw request/response data for every Jev call referenced here is kept in this project's own research folder, alongside the written interpretation of each result, deliberately kept separate from the AI-generated numbers.