Analyst brief · PDF · July 2026
SSF / CAEP Continuous Access
How EmpowerID implements governed continuous access on the Identity Fabric
Many vendors excel at collecting and delivering SETs. EmpowerID implements what happens after a trusted signal is accepted: policy evaluation, authority mutation, runtime enforcement, and auditable proof—on one fabric.
EmpowerIDJuly 202620 min read1.0 MB PDFAnalyst brief — product demonstration scope
Scope
This is an EmpowerID implementation brief describing how SSF and CAEP operate on the Identity Fabric. It assumes familiarity with the OpenID Shared Signals Framework and CAEP; it does not re-teach the standards and does not imply OpenID Foundation certification unless explicitly stated in a current EmpowerID conformance claim.
Executive summary
This brief describes how EmpowerID implements SSF and CAEP on the Identity Fabric and what is structurally different from a typical signal-distributor plus session-revoke deployment. Continuous access lives in governed effects—AuthZEN evaluation, dual enforcement surfaces, loop-safe topology, and a causal operator timeline—not in forwarding notifications alone.
What's inside
Governed effects, not a signal feed
SSF/CAEP as a governed-effects control plane on the same spine as IGA, authorization, orchestration, and agent execution.
Pre-dispatch denial
Block unsafe agent actions before tool or MCP dispatch—even when underlying credentials still look valid.
Separated evidence
Delivery fact, authorization disposition, and enforcement disposition as distinct immutable facts—not one handled flag.
Dual enforcement surfaces
Human path: BFF session invalidation. Agent path: authority guard at the execution boundary.