Observe-only
Logs and alerts after the fact.
Correlated logs — not independently verifiable outcome.
Platform
Every category provides real value. Architectures stop at different stages. A decision is the door; controlled execution and proof are the room.
Nine stages run from knowing the subject and admitting it onto the fabric, through binding its purpose, observing the boundary, and evaluating the exact action, to preparing execution, keeping the reusable credential at the boundary, owning the dispatch, and recording the outcome. Architectures stop at different points along it: a decision is the door, while controlled execution and proof are the room.
Stage 1 of 9 — Identity and context
Establish who or what is acting and from which context.
Stage 2 of 9 — Identity and context
Register or federate the principal as a governed identity.
Stage 3 of 9 — Policy and decision
Mission, delegation, tools, and budgets attach to the work.
Stage 4 of 9 — Policy and decision
Traffic and requests are observed or mediated at the ingress.
Many architectures stop before the decision threshold.
Stage 5 of 9 — Policy and decision
Policy evaluates the exact action with current authority and signals.
A decision is the door — not the controlled effect.
Stage 6 of 9 — Execution
Permit consumption and execution authority are distinct states.
Stage 7 of 9 — Execution
The reusable secret does not cross into agent or model context on governed routes.
Stage 8 of 9 — Execution
Executor carries out the bound action — not the requester holding standing keys.
Stage 9 of 9 — Evidence and proof
Outcome read-back and causal evidence where verification exists.
Declared governed paths only — not every route in the estate.
Every bar represents real value. The distinction is where the architecture stops.
Architectural comparison — not a product-ranking claim. Review against your estate map.
Inventory and lifecycle
Registration without execution proof
Traffic-level decision
Partial execution control
Decision without credential mediation
Partial — patterned continuation
Detection without enforcement
Governed execution and proof on declared routes
Labeled: declared governed paths
Traffic observation sees requests, not whether delegation was still valid.
Required: Continuous authority state tied to the bounded work.
Evidence: Authority chain in the receipt.
Gateways may not mediate credential acquisition and injection.
Required: Execution boundary with credential mediator.
Evidence: Context inspection and denial-before-release records.
Allow/deny at tool name is not argument-level binding.
Required: Exact-action evaluation and permit consumption.
Evidence: Argument hash in decision record.
HTTP success is not target state.
Required: Independent verification or reconciliation.
Evidence: Observed target state vs expected.
Model-level filtering is not enterprise authorization.
Required: PEP at the effect boundary with obligations.
Evidence: Policy version and assurance steps in chain.
Same action: Approve supplier bank detail update
Logs and alerts after the fact.
Correlated logs — not independently verifiable outcome.
Allow or deny at the API boundary.
Decision log — outcome may be inferred.
Policy, credential mediation, dispatch, verification.
Causal chain through verified outcome where available.
Online
Powered by EmpowerID AI