Partner onboarding and invitations
Guide a partner organization or invited user through verification, credential enrollment, approval, organizational binding, and role assignment while preserving the originating transaction.
EmpowerID Identity Fabric · Orchestration & Fulfillment
EmpowerID Identity Journey Orchestration connects policy obligations to governed workflows, hosted interactions, and typed evidence—then resumes the original OIDC or OAuth transaction without weakening its security context.
A user may need to provide attributes, enroll a credential, verify an email, accept terms, or obtain approval before access can continue. Traditional systems either deny and strand the user, or embed one-off logic inside each application. EmpowerID turns unmet requirements into governed identity journeys.
Preserve the original transaction. Fulfill policy requirements. Resume with evidence.
1
The PDP evaluates identity, application, resource, and organizational context. When additional requirements apply, it returns explicit obligations—not a blind denial.
2
EmpowerID pauses the identity transaction while preserving client, redirect, state, nonce, PKCE, subject, and session context.
3
Reviewed workflows, EmpowerID-hosted interactions, or registered external handlers complete verification, enrollment, approval, or profiling—without moving credentials into workflow state.
4
Each completed requirement returns structured evidence tied to the transaction and obligation. Replay controls, expiry, and idempotency protect multi-step journeys.
5
When obligations are satisfied, EmpowerID resumes the original authorization transaction through the standard session or authorization-code path.
Guide a partner organization or invited user through verification, credential enrollment, approval, organizational binding, and role assignment while preserving the originating transaction.
Collect only the attributes required by current policy. Users complete missing information in a resumable journey instead of a disconnected profile process.
Introduce WebAuthn or another approved credential at the appropriate point while the IdP retains ownership of credential and session operations.
Extend reviewed identity journeys using the same obligation-and-evidence model without embedding customer code inside the core trust boundary.
OIDC and OAuth bindings remain intact. The platform resumes the original transaction—not a synthetic replacement request.
The PDP determines what must be satisfied. Workflows do not grant themselves authority.
Enrollment, validation, and session issuance stay inside the Identity Provider. Passwords and secrets do not belong in workflow variables.
Completed steps produce typed evidence—not an unstructured success flag—for operations and governance.
Managed, themed, or headless presentation patterns share the same policy, transaction, and evidence contracts.
| Fabric capability | Responsibility |
|---|---|
| Policy Decision Point | Permits access and returns additional obligations when requirements remain |
| Identity Provider | Preserves the authorization transaction, owns credentials and sessions, and resumes processing |
| Orchestration & Fulfillment | Coordinates steps required to satisfy policy obligations |
| Identity graph and context | Supplies authoritative identity, organization, membership, and resource facts |
| Experience layer | Presents user interaction without becoming the authority for access |
| Evidence services | Correlates journey events and completed requirements for operations and governance |
Convert remediable policy failures into guided journeys that explain what must happen next.
Use one transaction, obligation, evidence, and resume model instead of rebuilding plumbing per application.
Front ends render the journey. Policy decides what may be created or skipped.
Carry correlation and evidence across the journey so teams can reconstruct how requirements were satisfied.
Identity Journey Orchestration is part of Orchestration & Fulfillment. Its transaction core is IdP-native because only the Identity Provider can safely preserve and resume authentication context. Its value spans the fabric because the journey is decided by policy, fulfilled through workflows and identity services, and recorded as correlated governance evidence.
Capability availability varies by deployment edition and integration scope. Maturity labels for specific obligation types, presentation modes, and federation paths should match the current commercial release at publication time.
EmpowerID includes broader workflow capabilities, but Identity Journey Orchestration is designed for security-sensitive identity transactions—preserving protocol context, interpreting policy obligations, collecting typed evidence, and resuming the originating transaction.
Transaction, credential, and session components are native to the EmpowerID Identity Provider. The complete capability also uses the PDP, identity graph, workflow, experience, and evidence services—presented as an Identity Fabric capability, not a standalone IdP SKU.
No. Applications initiate and render journeys; policy determines which requirements apply and the platform verifies completion.
Yes. EmpowerID retains original client and protocol bindings across the interaction and resumes only after required obligations are satisfied.
Yes. Presentation can be EmpowerID-managed, themed, or headless while the same policy and trust contracts remain in force.
Online
Powered by EmpowerID AI