Govern every AI action. Accelerate every mission.

Nuggets is the trust layer for autonomous AI. We govern AI at the point of execution. Our solutions extend the Zero Trust architecture federal agencies are building under OMB M-22-09 to govern AI agents as they act, and support federal AI governance requirements under OMB M-25-22. Every action verified, every decision recorded, every outcome provable, without replacing the accredited systems agencies already run.

Nuggets' modular platform is available now to US federal agencies through Carahsoft on GSA Schedule 47QSWA18D008F. It integrates with existing IAM, PAM and cloud infrastructure, deploys multi-cloud or on premises, and lets agencies start with the highest-risk AI workflows first.

 


 

HOW NUGGETS GOVERNS AI

In autonomous systems, trust is not established at login. It is established at execution. Traditional access control answers one question well: who, or what, can reach a system. It cannot answer the question autonomous AI forces. Was this specific action, by this agent, under this authority, permitted to execute. Nuggets governs every AI action against four questions, evaluated at the moment it runs.

Identity


Who is acting. Cryptographically verifiable identity for every actor: humans (KYC and KYE), organizations (KYB), AI agents (KYA) and machines (KYM), across federal, state and local systems.

Authority


On whose authority. Every AI agent acts under explicit, provable delegated authority from a verified person or organization, enforced in real time.

Intent


What is being requested. The action the agent intends to take and the constraints it must stay within, established and checked before execution.

Action


Whether this action is permitted to proceed right now. Enforced at runtime and recorded as a verifiable action record with full provenance for audit, compliance and investigation on demand.

Compliance is the outcome of enforcing these four questions at the point of action. It is built in, not bolted on afterwards.




AI AGENT GOVERNANCE: LEAD SOLUTIONS

Know Your Agent (KYA) Identity Framework 

Establish unique, cryptographically verifiable digital identities for every AI agent operating in your environment. KYA links each agent to a verified human, role and organization through a provable chain of accountability, so every action the agent takes is attributable to a responsible principal. Without KYA, authority cannot be delegated, policy cannot be enforced, and AI deployment cannot be governed or defended under audit.

  • Cryptographic agent identity using Decentralized Identifiers (DIDs), bound to code and configuration
  • Clear attribution chains linking every AI action to a verified human and organization
  • Cross-platform verification across cloud environments, IAM systems and agency infrastructure
  • Anti-spoofing protection, so legitimate agents cannot be impersonated without access to bound cryptographic credentials

Governs: Identity · Authority

AI Agent Authentication and Action Control

Strong authentication and granular action-level controls for AI agents operating in government environments. Nuggets evaluates identity, authority, intent and policy at the moment each action executes, not just at deployment or login. Works alongside existing IAM systems to ensure agents operate within defined scope while maintaining productivity and a complete, verifiable action record.

  • Cryptographic authentication tied to verified agent identity, evaluated continuously
  • Action-level permission controls covering what an agent can do, not just what it can access
  • Employee consent verification for agent operations involving personal or sensitive data
  • Full action record for every operation: who acted, on whose authority, within what constraints

Governs: Identity · Authority · Intent · Action

Trusted AI with Human-in-the-Loop Control

Configurable approval workflows that keep agency staff in control of AI operations without breaking automation. AI agents handle routine tasks autonomously while pausing for explicit human authorization on high-risk or sensitive actions. Approval and consent decisions are cryptographically recorded, creating a defensible chain of human oversight for audit and regulatory purposes.

  • Real-time secure approvals via push notification for defined action types and risk thresholds
  • Configurable approval chains based on action type, data sensitivity and agency policy
  • Agents continue background operation while awaiting authorization, with no workflow disruption
  • Cryptographically recorded approval and consent decisions for audit, investigation and compliance reporting

Governs: Authority · Intent · Action

 


 

CITIZEN AND HUMAN IDENTITY

These solutions establish the verified human and organizational identity that the Identity and Authority checks depend on.

Identity Verification and Validation During Enrollment


Simple one-time capture and validation of a government-issued photo ID or NFC e-Passport with biometric face verification and liveness check, supporting NIST IAL2. Verified attributes are stored as verifiable credentials in a user-controlled wallet, enabling privacy-enhancing selective sharing across services without repeated enrollment.

Reusable and Portable Personal Identity


Once enrolled, citizens can selectively share verified identity attributes to any connected system without re-verification. High-assurance portability supporting NIST IAL2 removes duplicated identity infrastructure across agencies while giving citizens control over exactly what is shared and with whom.

Reusable and Portable Organizational Identity


Verified business identity credentials that can be selectively shared across supply chains, inter-agency partnerships and third-party systems. Reduces fraud risk in government procurement and data-sharing workflows by establishing cryptographically provable organizational identity at the point of interaction.




AUTHENTICATION AND ACCESS

Continuous, high-assurance authentication the Identity and Authority checks rely on at each action.

Strong Passwordless Authentication

Password-free login for agency staff and citizens using biometrics and cryptographic keys, something you have and something you are. Removes credential interception, replay and phishing attack vectors entirely. Supports NIST AAL2 without adding friction to the user experience.

Strong Multi-Factor Biometric Authentication

Standards-based cryptography combined with biometrics verified against government-issued photo IDs, delivering strong authentication that supports NIST AAL2. Suitable for high-assurance access scenarios including inter-agency data sharing, privileged operations and citizen-facing services handling sensitive records.

Seamless and Secure Biometric Single Sign-On

High-assurance single sign-on across connected applications, web services and transaction processing systems. Authentication via verified biometrics supports NIST AAL2 requirements and provides seamless access without repeated login friction, suitable for complex agency environments with multiple integrated systems.

Secure Account Reset and Recovery

Biometric verification for secure account reset and recovery, tied to the high-assurance identity established at enrollment. Reduces account takeover attempts during recovery by requiring the same biometric and verifiable credential standard as the original identity. Removes the social engineering vulnerability of knowledge-based recovery.

 


 

PRIVACY, DATA AND COMPLIANCE

The privacy-preserving data control and audit-grade evidence behind the Action record.

Share From Mobile Digital Wallet

Citizens and employees maintain complete ownership and control over their personal data through a self-sovereign identity wallet that securely stores verifiable credentials. Agencies never hold the underlying PII. They receive only the verified attributes they need, removing the honeypot databases that make breaches inevitable.

Privacy-Preserving Age Verification

Verify a user's age without revealing sensitive personal data, using zero-knowledge proofs to provide high-assurance attribute verification through selective disclosure. Suitable for government services with age-restricted access requirements where full identity disclosure is neither necessary nor appropriate.

Privacy-Enhancing Storage

Industry-standard public key cryptography provides a distributed approach to protecting personal data, reducing single points of failure and removing centralized attack surfaces. Agencies satisfy Privacy Act requirements without the liability of holding citizen PII on government servers.

Enhanced Compliance Support

Auditable records are encrypted with the private keys of transaction participants, providing simple and repeatable identity and data management that satisfies access and retention regulations. Supports NIST SP 800-63 IAL2/IAL3 and AAL2, FISMA-ready audit trails, and federal AI governance requirements under OMB M-25-22. Privacy-by-design architecture means compliance is built in, not bolted on.




INTEGRATION AND STANDARDS

How the trust layer plugs into accredited infrastructure without replacing it.

Simple to Integrate Verifiable Credentials

Nuggets is built on open standard specifications including W3C Verifiable Credentials (VCs), Decentralized Identifiers (DIDs), DIDComm Messaging, OAuth 2.0, OID4VC, OID4VCI and OID4VP, enabling global, private and secure interoperability for verified identity data. Integrates with existing CIAM services, IAM systems and identity providers without replacing accredited infrastructure.

Personal Data Storage Migration

Overlay Nuggets on existing identity provider infrastructure to add strong authentication, verifiable credential collection and IAL proofing data without rebuilding the identity stack. Securely migrate personal data to Nuggets' encrypted distributed wallet at the pace that suits the agency, preserving continuity of existing services throughout.

 


 

PAYMENTS

High-Assurance Identity-Authenticated Payments

Where payment capability is required, every transaction is tied to a verified digital identity to prevent fraud and reduce false positives. AI agents can process transactions within defined, auditable authority limits, with human-in-the-loop approval for operations above configured thresholds. Supports traditional and emerging payment rails with built-in compliance.

PROFESSIONAL SERVICES

Professional Services

Specialists in verifiable identity, AI governance, data privacy and security. Nuggets offers comprehensive digital and IT services through Carahsoft, including strategy, training, design, software engineering, deployment and delivery, with dedicated government support for agencies at every stage of their AI governance journey.




COMPLIANCE READY

  • Compliant with NIST SP 800-63 IAL2/IAL3 and AAL2 requirements
  • FISMA-ready architecture with comprehensive audit trails
  • Supports Privacy Act compliance, with no PII stored on agency servers
  • Supports federal AI governance (OMB M-25-22) and Zero Trust (OMB M-22-09) requirements
  • Built on W3C open standards, with ISO 27001 certification

 


 

WHY GOVERNMENT AGENCIES CHOOSE NUGGETS

Built for action, not just access

Zero Trust governs who and what can reach a system. Nuggets governs what an autonomous AI agent is permitted to do, the control layer agentic AI requires and that no existing IAM product provides.

Proven in regulated environments

Worked with the Bank of England and the European Commission. Recognized by Gartner as a global leader in Identity Wallets, alongside Apple, Google and Microsoft, across multiple categories.

 


 

READY FOR DEPLOYMENT

 

Nuggets is available to US federal agencies through Carahsoft GSA contracts (GSA Schedule 47QSWA18D008F), with dedicated government support and professional services. It extends your existing IAM, PAM and cloud infrastructure rather than replacing it, and deploys multi-cloud or on premises.

Contact Carahsoft today to begin governing your agency's AI at the point of execution.

Nuggets@carahsoft.com · (844) 214-4790