Gazebo
    ServicesAgentsDocsSpecWritingPricing
    Log inSign up
    Log in

    Overview

    • Introduction
    • Changelog
    • Implementations

    Identity

    • Identity declaration
    • Scope syntax

    Consent

    • The consent token
    • Verification

    Runtime

    • Overview
    • Access policy
    • Audit log
    • Credential broker
    • Compliance mappings

    Implementing AIP

    • Compatibility guide
    AIP Specification

    Overview

    • Introduction
    • Changelog
    • Implementations

    Identity

    • Identity declaration
    • Scope syntax

    Consent

    • The consent token
    • Verification

    Runtime

    • Overview
    • Access policy
    • Audit log
    • Credential broker
    • Compliance mappings

    Implementing AIP

    • Compatibility guide
    SpecRuntimeCompliance mappings

    Compliance Mappings

    AIP Runtime is designed to satisfy the technical safeguard requirements of common security frameworks. The mappings below indicate which spec behaviours satisfy which criteria.

    These are reference mappings only. A conforming AIP implementation meets the technical requirements; achieving certification requires organisational controls outside the scope of this specification.

    SOC 2

    CriterionAIP Runtime mechanism
    CC6.1 — Logical access controlsPolicy document restricts agent access to declared, consented scope
    CC6.2 — Access provisioned appropriatelyVersioning rule requires re-consent for any scope expansion
    CC6.3 — Access removalInstant revocation via broker; install ID refused on next request
    CC7.2 — Monitoring for security eventsAudit log records every credential retrieval and gated operation
    CC9.2 — Vendor and partner risk managementIdentity declaration provides verifiable scope declaration for third-party agents

    HIPAA

    Technical SafeguardAIP Runtime mechanism
    §164.312(a)(1) — Access controlPolicy document enforces minimum necessary access per agent installation
    §164.312(b) — Audit controlsAudit log records access events with required minimum fields
    §164.312(c)(1) — IntegrityAudit log immutability — append-only, no retroactive modification
    §164.312(d) — AuthenticationConsent token + install ID authenticate the agent on every broker request
    §164.312(e)(2)(ii) — Encryption in transitCredential transport must use TLS 1.2 or higher; storage encryption is implementation-defined
    Credential brokerCompatibility guide
    Gazebo

    IAM for AI agents. Scoped credentials, access policies, and audit trails — without rotating keys.

    Product

    • Pricing
    • Status

    Explore

    • Services
    • Agents
    • Workflows
    • Integrations

    Content

    • Writing
    • Topics
    • Blog
    • Docs

    Free Tools

    • Scanner

    Company

    • About
    • [email protected]
    • [email protected]

    © 2026 Gazebo. All rights reserved.

    PrivacyTermsSecurity