Control-plane architecture · compliance traceability

Which control-plane architectures actually line up with real standards.

A follow-up to the hands-on OpenShell/c=US demonstration: a structured, AI-assisted comparison of five candidate control-plane architectures against verified security and compliance standards, plus a sixth category testing OpenShell and c=US together rather than as competitors.

Method note. Numeric judgments below come from TypeSafe's Jev (System One) model, run once, on 2026-09-28. Facts stated as facts (standards bodies, publication numbers, dates) were independently verified by search, not judged by Jev — the two are kept visibly separate throughout, per this project's own convention.

Five architectures, four real standards

Every candidate checked against NIST SP 800-63 (Digital Identity Guidelines), the NIST AI Risk Management Framework plus its Generative AI Profile (AI 600-1), the OWASP Multi-Agentic System Threat Modeling Guide, and a combined ISO/IEC 27001 + CIS Controls category — all four already relevant to, or already listed on, this project's own compliance materials.

NIST SP 800-63
(identity)
NIST AI RMF /
AI 600-1
OWASP Agentic
Threat Modeling
ISO 27001 /
CIS Controls
c=US (X.500/LDAP + mTLS)0.760.510.720.65
OpenShell0.240.620.630.71
gVisor0.170.420.350.56
Firecracker / E2B0.170.420.350.47
SPIFFE/SPIRE0.760.590.760.66
OpenShell + c=US, combined0.820.770.830.84

Each cell: probability that adopting that architecture would meaningfully help satisfy, or provide relevant technical evidence toward, that standard. Darker = lower, brighter green = higher.

Two different jobs, and the standards notice

The pattern isn't noise. c=US's own design and SPIFFE/SPIRE — the two identity architectures — score highest on the identity standard and the threat-modeling guide, which explicitly covers identity and trust boundaries. The three sandboxing architectures all score low there, correctly, since none of them do identity work. Within the sandboxes, OpenShell separates from gVisor and Firecracker/E2B on every column, most sharply on general infosec controls, where its agent-aware policy language and credential-provider design map more directly onto CIS-style technical safeguards than a generic, non-agent-aware sandbox does.

OpenShell and c=US together, not versus each other

Every row above treats the candidates as alternatives — but that misses what this project actually runs: OpenShell sandboxing an agent's own reasoning while c=US's identity layer handles the mTLS and directory decision, exactly as demonstrated in the identity-vs-runtime case study. Scored as its own category against the same four standards, the combination beats both individual architectures on every standard — not just the better of the two:

Standardc=US aloneOpenShell aloneCombined
NIST SP 800-630.760.240.82
NIST AI RMF0.510.620.77
OWASP Agentic0.720.630.83
ISO 27001 / CIS0.650.710.84

Asked directly whether this reflects genuine complementarity or noise around the stronger score, Jev returned 1.87 out of 2 (confidence 0.80, 90% probability on “meaningfully stronger — the two genuinely complement each other's gaps”). c=US's weak spot (general infosec controls) sits close to OpenShell's strength there; OpenShell's weak spot (identity) is exactly c=US's strength.

What this checked, and what it found

The combined architecture is the strongest option on every standard tested

Not an average of the two, and not just the higher of the two — it exceeds both on all four, the numeric signature of two systems actually covering each other's gaps rather than sitting side by side.

X.500 is a real, ratified international standard

Dual-published as ITU-T X.500 and ISO/IEC 9594, jointly maintained by ITU-T and ISO/IEC JTC1, 9th edition (2019), active and current. Not a private product or single vendor's technology.

No NIST standard exists yet specifically for “agentic AI”

Verified by search, not assumed. Closest current NIST coverage: the AI Risk Management Framework 1.0 (2023) plus the Generative AI Profile, AI 600-1 (2024). This project's poster already says “TBD agentic AI requirements,” which is accurate as written.

Sources and underlying data

What this page draws on