Platform

Identity Fabric Services

Supporting detail for the platform outcomes on the Identity Fabric overview—authorization, collection, orchestration, gateways, and assurance.

Connect enterprise systems once. Reuse the same governed fabric for inventory, fulfillment, and agent action. For LDAP and SCIM protocol bridges, see Identity Fabric VDS .

Identity data

EmpowerID Identity Collection & Reconciliation

Inventories, normalizes, correlates, and compares identity and access state. Agent discovery begins here—observing and correlating agent principals before registration, ownership, and lifecycle extend across the Fabric.

Identity Fabric capability

AI Agent Discovery and Registration

Find every AI agent. Turn each into a governed identity.

A cross-Fabric capability—not a standalone collection connector. Discovery begins with inventory and reconciliation, then spans orchestration, Governed Authorization, the LLM and MCP Gateways, and evidence so registration connects to runtime control.

Two ways agents enter governance

  • Discover existing agents

    Agent discovery connectors observe candidate agent principals in supported environments and bring their evidence into the Identity Fabric for review, attribution, and enrollment.

  • Govern agents on arrival

    Federated Agent Identity

    When an external agent presents an identity assertion, EmpowerID validates the assertion and establishes a governed local identity, delegation, and lifecycle state before allowing it to act.

Five-step journey

  1. 1

    Discover

    Find known, unknown, and externally introduced agent principals.

  2. 2

    Register and attribute

    Create a governed identity and associate its owner, origin, purpose, and environment.

  3. 3

    Bind authority

    Record delegation, permitted resources, and lifecycle policy.

  4. 4

    Govern actions

    Apply contextual authorization through the EmpowerID Authorization Service and MCP Gateway.

  5. 5

    Prove and contain

    Correlate events and receipts; revoke, quarantine, or retire when necessary.

Capability on EmpowerID Identity Fabric. Begins with Identity Collection & Reconciliation; spans orchestration, Governed Authorization, MCP Gateway, and evidence.

Decision plane

Governed Authorization

One decision engine. Every relevant fact. No parallel authorization truth.

Governed Authorization is not a request-in, permit-out chain. Applications declare what access means. PIPs—including the graph as a super PIP—assemble current facts. One logical ABAC authority decides through OpenID AuthZEN. PEPs enforce and may only narrow.

Authorization lifecycle

  1. 1

    Applications define meaning

    App Authorization Contracts declare features, operations, object requirements, and enforcement locations—before any runtime request.

  2. 2

    Business composes authority

    Bundles, personas, and governed assignments establish bounded capability. For agents: bounded delegation—never a copied human role.

  3. 3

    PIPs assemble facts

    Roles, grants, attributes, risk—and relationship facts from the graph super PIP. The graph contributes facts; it never issues a permit.

  4. 4

    One logical ABAC authority decides

    A PEP sends an AuthZEN request; a serving PDP instance in the governed fabric evaluates policy and returns decision context.

  5. 5

    PEPs enforce; the system explains

    UI, gateway, backend, search, and agent PEPs enforce the same decision. Present-state explanation stays distinct from change history.

Authorization before cognition. Reauthorization before action.

The same logical ABAC authority governs three distinct agent moments. Every stage can narrow. No stage can widen.

  • Delegation

    May this user delegate this tool to this agent?

    Delegatable tools = agent capability ceiling ∩ owner delegation authority.

  • Discovery

    Which tools are effective for this user, agent, and active delegation?

    Policy-scoped tool surface before the agent plans—not its full registered toolbelt.

  • Invocation

    May this agent use this tool on this resource now?

    Current delegation, graph, identity, trust, risk, and data-scope facts evaluated again at action time.

Integration patterns

Evaluation

API, backend, and object actions

Batch evaluation

UI capability loading and efficient multi-checks

Authorized search

Query predicates and consistent filtering—counts never leak denied records

Implementation SKU: EmpowerID Authorization Service — AuthZEN-compatible PDP fabric for apps, APIs, agents, and authorized search.

Execution plane

Identity Journey Orchestration

Turn identity policy into secure, resumable journeys.

Connect real-time policy decisions to the workflows, credentials, user interactions, and evidence needed to satisfy them—then safely resume the original identity transaction.

From policy obligation to verified completion

  1. 1

    Decide what is required

    The PDP evaluates identity, application, resource, and organizational context. When additional requirements apply, it returns explicit obligations—not a blind denial.

  2. 2

    Preserve the transaction

    EmpowerID pauses the identity transaction while preserving client, redirect, state, nonce, PKCE, subject, and session context.

  3. 3

    Orchestrate the required steps

    Reviewed workflows, EmpowerID-hosted interactions, or registered external handlers complete verification, enrollment, approval, or profiling—without moving credentials into workflow state.

Identity-critical journey examples

  • Partner onboarding and invitations

    Guide a partner organization or invited user through verification, credential enrollment, approval, organizational binding, and role assignment while preserving the originating transaction.

  • Progressive profiling

    Collect only the attributes required by current policy. Users complete missing information in a resumable journey instead of a disconnected profile process.

  • Credential enrollment

    Introduce WebAuthn or another approved credential at the appropriate point while the IdP retains ownership of credential and session operations.

Capability within Orchestration & Fulfillment. Transaction core is IdP-native; orchestration spans policy, workflows, experience, and correlated evidence.

Execution plane

EmpowerID LLM Gateway

Fabric catalog: EmpowerID LLM Gateway

Authorization is not a wrapper around inference. It is the decision that determines whether inference should occur.

Apply identity, delegated authority, prompt intent, model policy, and current spend state before a governed request reaches an LLM provider—then create signed evidence for completed allowed calls.

OpenAI- and Anthropic-compatible routes · Multi-provider control · AuthZEN-compatible policy

Classify

Inline prompt classification exports high-confidence intent and data labels to policy—analytics topics stay separate so exploratory taxonomy never becomes an accidental deny engine.

Authorize

AuthZEN-compatible PDP evaluation with subject, delegation status, model, intent labels, estimated cost, and spend state—every candidate model re-authorized, not config-substituted.

Budget

Estimated cost and authoritative consumed spend evaluated before the provider call—deny, clamp tokens, or route to a lower-cost permitted model before charges are incurred.

Prove

Signed, hash-linked receipts for completed allowed calls bind policy context to measured usage and the effective model actually used—not just the one requested.

Execution plane

EmpowerID MCP Gateway

Fabric catalog: EmpowerID Governed Tool Gateway

MCP carries the call. EmpowerID determines whether the call may become an enterprise action.

EmpowerID MCP Gateway is the MCP-aware Policy Enforcement Point of Identity Fabric. It verifies who an agent represents, scopes tool discovery, authorizes each invocation through Governed Authorization, enforces constraints, protects downstream credentials, and records correlated action evidence.

Delegation

Bounded authority—not a copied user role

A person or governed process grants an agent bounded capability. The agent does not inherit an unrestricted copy of the delegator’s access.

Discovery

Policy-scoped tool catalogs

Before an agent plans, EmpowerID exposes an appropriately scoped catalog from delegation and Identity Fabric context—including virtual MCP servers for different roles and use cases.

Invocation

Reauthorization before dispatch

Each tool call re-verifies binding, delegation, schema integrity, and PDP authorization. Policy change, revocation, or schema drift can stop the next governed invocation.

01

Decision

EmpowerID Authorization Service

Governed Authorization implementation—one logical ABAC authority with AuthZEN-compatible evaluation, graph super PIP context, contribution-aware revocation, and authorized search on a distributed PDP fabric.

Architecture whitepaper
02

Identity data

EmpowerID Identity Collection & Reconciliation

Inventories, normalizes, correlates, and compares identity and access state.

EmpowerID Dynamic Groups

Collections & DGE: External Sync Policies, Resource Collections, ABAC membership sync to Entra ID and SAP IAS, with Proof Chain evidence.

Dynamic Group Management (preview)

EmpowerID Identity Virtualization

Governed identity views over LDAP/SCIM and protocol bridges.

03

Execution

EmpowerID Orchestration & Fulfillment

Coordinates approvals, workflows, connectors, and fulfillment—including Identity Journey Orchestration to turn policy obligations into secure, resumable identity journeys with typed evidence.

Identity Journey Orchestration

EmpowerID Governed Tool Gateway

EmpowerID MCP Gateway—MCP-aware PEP that verifies delegation, scopes tool discovery, authorizes invocation through Governed Authorization, protects credentials, and records correlated action evidence.

MCP Gateway service page

EmpowerID LLM Gateway

Identity-aware model PEP—prompt classification, delegated authority, spend-aware authorization, managed provider credentials, and signed allow-path receipts before inference.

LLM Gateway service page
04

Assurance

EmpowerID Analytics & Evidence

Reporting, dashboards, evidence queries, and analytics experiences.

Get Started

Connect once. Govern consistently. Change safely.

EmpowerID Identity Fabric — governance, authorization, and execution for people, NHIs, and AI agents.

Request Demo See the platform in action
Talk to an Expert Technical consultation
EmpowerID AI

EmpowerID AI Assistant

Online

EmpowerID AI
EmpowerID AI
Hello! How can I help you today?
07:33 PM

Suggested questions:

Powered by EmpowerID AI