{
 "acronym": "WIMSE",
 "adoption": {
  "by": null,
  "level": "unmeasured",
  "probe_run": null
 },
 "aliases": [
  "Workload Identity in a Multi System Environment"
 ],
 "analog": "Cross-domain workload identity and token-exchange architecture",
 "collisions": [],
 "discovery": {
  "mechanism": "Workload identity issuance and cross-trust-domain token exchange (architecture defines roles and flows; concrete wire mechanics are in sibling WIMSE WG documents)",
  "path": "none"
 },
 "dispute": {
  "claims": [
   "This architecture document alone does not define a probeable wire protocol; the concrete mechanics live in sibling WIMSE WG drafts not reviewed here."
  ],
  "summary": "Like SPIFFE, WIMSE is a general workload-identity architecture; its relevance to agent identity comes from a separate, unaffiliated IETF individual draft that proposes applying it to AI agents. Unlike the Signature Agent Card, WIMSE IS a chartered-WG document, giving it a firmer governance footing than several other records in this step."
 },
 "evidence": [
  {
   "claim": "WIMSE architecture draft-ietf-wimse-arch is an active WG Document of the IETF wimse Working Group, RFC stream IETF, currently at revision -08 (last updated 2026-07-06), replacing the earlier individual draft-salowey-wimse-arch",
   "date": "2026-07-06",
   "label": "REPORTED",
   "url": "https://datatracker.ietf.org/doc/draft-ietf-wimse-arch/08/"
  },
  {
   "claim": "The IETF individual draft on AI-agent authentication (draft-klrc-aiagent-auth-03) explicitly proposes using the WIMSE architecture, alongside SPIFFE and OAuth 2.0, as the basis for agent authentication rather than defining new protocols",
   "date": "2026-07-06",
   "label": "VERIFIED",
   "url": "https://www.ietf.org/ietf-ftp/internet-drafts/draft-klrc-aiagent-auth-03.html"
  }
 ],
 "form": "endpoint",
 "governance": "IETF wimse Working Group (chartered WG; RFC stream IETF)",
 "group": null,
 "history": [
  {
   "date": "2026-09-05",
   "note": "seeded from Exa Agent research run"
  },
  {
   "date": "2026-09-06",
   "note": "verified against draft-ietf-wimse-arch-08's datatracker status page, confirming chartered WG status and 2026-07-06 update"
  }
 ],
 "id": "wimse",
 "implementation": "prototype",
 "last_verified": "2026-09-06",
 "name": "Workload Identity in Multi System Environments (WIMSE) Architecture",
 "native_status": "Active Internet-Draft, WG Document, Intended Status: Informational",
 "origin": {
  "date": "2024-03",
  "org": "J. Salowey (Palo Alto Networks), Y. Rosomakho (Zscaler), H. Tschofenig (UniBw M.)"
 },
 "part_of": null,
 "parties": [
  "agent-site"
 ],
 "phase": "working-group",
 "probe": {
  "method": "n/a",
  "on_absent": "Absence of a site artifact means nothing; WIMSE governs workload-to-workload identity, not a site-facing endpoint.",
  "parse": "n/a",
  "path": "n/a (workload identity architecture; no fixed origin artifact)"
 },
 "question": "How do workloads — including, per a related draft, AI agents — authenticate to each other and to services across platforms and trust domains?",
 "scope": "general",
 "spec_url": "https://datatracker.ietf.org/doc/draft-ietf-wimse-arch/",
 "step": "identify",
 "summary_md": "WIMSE (Workload Identity in Multi System Environments) is an IETF architecture for how software workloads authenticate to each other and to services when they span multiple platforms, cloud providers, or trust domains — a scope broader than SPIFFE's original single-organization workload identity model [1]. It is relevant to the Identify layer of this map because a separate IETF individual draft on AI-agent authentication explicitly proposes using WIMSE (together with SPIFFE and OAuth 2.0) as the basis for how an agent authenticates, rather than inventing a new agent-specific protocol [2].\n\nIt solves cross-domain workload authentication architecture: defining the roles, trust relationships and token-exchange flows needed when a workload in one organization's environment needs to prove its identity to a service in another's. It does not itself define a single concrete wire protocol usable end to end — as an architecture document, its concrete mechanics (issuance formats, token exchange endpoints) are specified in sibling documents produced by the same WIMSE Working Group, which this pass did not review in depth. It also makes no agent-specific claims on its own; \"AI agent\" does not appear to be native vocabulary of the WIMSE WG's charter as reviewed here — the agent application again comes from the outside aiagent-auth draft.\n\nCurrent state: this is a genuine chartered IETF Working Group document — draft-ietf-wimse-arch, currently at revision -08, last updated 2026-07-06, on the IETF RFC stream — which gives it firmer standards-track footing than several of the individual-submission drafts elsewhere in this map [1]. It replaces the authors' earlier individual submission, draft-salowey-wimse-arch, first published in March 2024 [1].\n\nWho implements it: no concrete implementation was verified in this pass; the wimse WG maintains its work in a public GitHub organization (ietf-wg-wimse) referenced from the datatracker page [1], but this check did not survey deployed implementations.\n\nDisputed or unknown: whether or when WIMSE will produce a companion document specifically profiling AI agents (as opposed to the outside aiagent-auth draft doing so unofficially), and what concrete, probeable endpoint the architecture resolves to in practice, are both open.",
 "track": "ietf",
 "version": {
  "date": "2026-07-06",
  "label": "draft-ietf-wimse-arch-08, last updated 2026-07-06 (supersedes draft-salowey-wimse-arch, first published 2024-03)"
 }
}