WHO?
Identity and standing authority
Establish identities, owners, relationships, entitlements, and provenance
Architecture
Purpose-bound authority governs the work. Governed Execution gates the deed. Shared signals keep authority current. Evidence proves the chain—for architects and security leaders who need the full picture.
EmpowerID synthesis building on KuppingerCole's Identity Fabric paradigm and AIdentity framing. Agentic Identity Fabric is EmpowerID's proposed extension—not KuppingerCole's published analyst model.
Purpose-bound authority governs the work. Governed Execution gates the deed. Shared signals keep authority current. Evidence proves the chain.
EmpowerID provides identity governance, authorization, purpose-bound authority, governed execution, and assurance services within the emerging Agentic Identity Fabric.
Runtime authorization for AI agents stops being reusable access and becomes a compiler — durable approved work, current conditions, and one concrete proposed effect compiled into a single-use execution authorization, enforced at the boundary and closed by evidence of the outcome.
Who authorized it?
Named principal, owner, and delegation chain — not an anonymous runtime.
What was in scope?
Purpose, limits, budgets, and tools at the moment of the action.
Was it enforced?
The action passed through policy at the boundary — or it did not happen.
Can you prove it?
A verifiable record an auditor can replay without trusting vendor logs alone.
Foreign-hosted agents enter through a governed path. Consequential actions pass policy at the boundary — or they stop. Proof closes the loop.
Discover
Find and federate agents from Entra, Okta, and Google Cloud.
Adopt
Assign owner, limits, budgets, and allowed tools.
Invoke
Run foreign-hosted agents through a governed entry point — no standing credentials.
Enforce
Every consequential action passes policy at the boundary, or it stops.
Prove
Signed receipts chain approval through action to outcome.
WHO?
Identity and standing authority
Establish identities, owners, relationships, entitlements, and provenance
WHY?
Purpose and delegated authority
Define the bounded undertaking, authority ceiling, lifecycle, and accountable delegator
WHETHER?
Dynamic authorization and current signals
Decide whether the exact proposed action is permitted now
HOW?
Governed Execution
Bind, consume, dispatch, protect credentials, reconcile, and fail closed
WHAT HAPPENED?
Evidence and assurance
Produce a verifiable chain from authority and decision through external outcome
| Conventional fabric | Agentic Identity Fabric |
|---|---|
| Access granted at login or issuance | Consequential actions re-evaluated at the moment of effect |
| Session lifetime approximates work lifetime | Bounded work lifecycle governs why work may continue |
| Application or user holds the credential | Governed execution mediates credentials without agent custody |
| A permit or API call ends the control story | Consumption, dispatch, outcome, and reconciliation are separate states |
| Logs correlate by user or request | Evidence joins the entire undertaking through purpose-bound authority |
EmpowerID synthesis building on KuppingerCole's Identity Fabric paradigm and AIdentity framing. Agentic Identity Fabric is EmpowerID's proposed extension—not KuppingerCole's published analyst model.
Separate from market taxonomy — shows product packaging boundaries
Identity Graph, Agent Identity, Ownership and Lineage
Purpose-bound authority
AuthZEN PDP and Dynamic Authorization
Governed Tool Gateway and Governed Execution
OAuth Vault: Credentials without Custody
Receipts, Proof Bundles and Independent Verification
Governed Workloads, including Agent Teams
Full technical depth
An EmpowerID Identity Fabric perspective—with full attribution, purpose-bound authority, signals-based runtime control, Governed Execution, and causal evidence—for architects and analyst review.
Download the working paper →Online
Powered by EmpowerID AI