What problem does it solve?
Legacy identity and compliance frameworks (NIST 800-53, ISO 27001, SOC 2, etc.) were designed for pre-AI, network-centric environments and lack controls for AI agent-as-principal identity, phishing-resistant authentication requirements, and modern OAuth/JWT threat models. This skill fills that gap by providing a structured assessment process aligned with mid-2026 threat reality and current identity standards like NIST 800-63 rev4, FIDO2/WebAuthn, and RFC 9700.
Core Features & Use Cases
- Full Identity Assurance Assessment: Generates a complete scorecard covering per-principal AAL/IAL/FAL posture, phishing-resistant MFA coverage, token lifetime audits, JWT validation checks, and federation surface mapping.
- Compliance Gap Analysis: Maps identity control gaps to 20+ global regulatory frameworks (NIS2, DORA, UK CAF, AU ISM, ISO 27001, NY DFS, etc.) and MITRE ATT&CK/ATLAS TTPs to identify where paper compliance fails.
- Actionable Remediation Roadmap: Prioritizes fixes for critical gaps like agent identity inheritance, non-phishing-resistant MFA deployment, and non-compliant OAuth token lifetimes, with clear ownership and target dates.
- Use Case: A security team preparing for a SOC 2 audit can use this skill to run a full identity assessment, identify that 40% of privileged users are on TOTP instead of phishing-resistant MFA, and generate a prioritized roadmap to close the gap before the audit.
Quick Start
Use the identity-assurance skill to run a full identity assurance assessment for your organization, including principal inventory, phishing-resistant MFA coverage, and cross-jurisdictional compliance gap analysis.