Classify
Inline prompt classification exports high-confidence intent and data labels to policy—analytics topics stay separate so exploratory taxonomy never becomes an accidental deny engine.
Platform
Supporting detail for the platform outcomes on the Identity Fabric overview—authorization, collection, orchestration, gateways, and assurance.
Connect enterprise systems once. Reuse the same governed fabric for inventory, fulfillment, and agent action. For LDAP and SCIM protocol bridges, see Identity Fabric VDS .
Identity data
Inventories, normalizes, correlates, and compares identity and access state. Agent discovery begins here—observing and correlating agent principals before registration, ownership, and lifecycle extend across the Fabric.
Identity Fabric capability
AvailableFind every AI agent. Turn each into a governed identity.
A cross-Fabric capability—not a standalone collection connector. Discovery begins with inventory and reconciliation, then spans orchestration, Governed Authorization, the LLM and MCP Gateways, and evidence so registration connects to runtime control.
Discover existing agents
Agent discovery connectors observe candidate agent principals in supported environments and bring their evidence into the Identity Fabric for review, attribution, and enrollment.
Govern agents on arrival
Federated Agent Identity
When an external agent presents an identity assertion, EmpowerID validates the assertion and establishes a governed local identity, delegation, and lifecycle state before allowing it to act.
Discover
Find known, unknown, and externally introduced agent principals.
Register and attribute
Create a governed identity and associate its owner, origin, purpose, and environment.
Bind authority
Record delegation, permitted resources, and lifecycle policy.
Govern actions
Apply contextual authorization through the EmpowerID Authorization Service and MCP Gateway.
Prove and contain
Correlate events and receipts; revoke, quarantine, or retire when necessary.
Capability on EmpowerID Identity Fabric. Begins with Identity Collection & Reconciliation; spans orchestration, Governed Authorization, MCP Gateway, and evidence.
Execution plane
Turn identity policy into secure, resumable journeys.
Connect real-time policy decisions to the workflows, credentials, user interactions, and evidence needed to satisfy them—then safely resume the original identity transaction.
1
Decide what is required
The PDP evaluates identity, application, resource, and organizational context. When additional requirements apply, it returns explicit obligations—not a blind denial.
2
Preserve the transaction
EmpowerID pauses the identity transaction while preserving client, redirect, state, nonce, PKCE, subject, and session context.
3
Orchestrate the required steps
Reviewed workflows, EmpowerID-hosted interactions, or registered external handlers complete verification, enrollment, approval, or profiling—without moving credentials into workflow state.
Partner onboarding and invitations
Guide a partner organization or invited user through verification, credential enrollment, approval, organizational binding, and role assignment while preserving the originating transaction.
Progressive profiling
Collect only the attributes required by current policy. Users complete missing information in a resumable journey instead of a disconnected profile process.
Credential enrollment
Introduce WebAuthn or another approved credential at the appropriate point while the IdP retains ownership of credential and session operations.
Capability within Orchestration & Fulfillment. Transaction core is IdP-native; orchestration spans policy, workflows, experience, and correlated evidence.
Execution plane
Fabric catalog: EmpowerID LLM Gateway
Authorization is not a wrapper around inference. It is the decision that determines whether inference should occur.
Apply identity, delegated authority, prompt intent, model policy, and current spend state before a governed request reaches an LLM provider—then create signed evidence for completed allowed calls.
OpenAI- and Anthropic-compatible routes · Multi-provider control · AuthZEN-compatible policy
Classify
Inline prompt classification exports high-confidence intent and data labels to policy—analytics topics stay separate so exploratory taxonomy never becomes an accidental deny engine.
Authorize
AuthZEN-compatible PDP evaluation with subject, delegation status, model, intent labels, estimated cost, and spend state—every candidate model re-authorized, not config-substituted.
Budget
Estimated cost and authoritative consumed spend evaluated before the provider call—deny, clamp tokens, or route to a lower-cost permitted model before charges are incurred.
Prove
Signed, hash-linked receipts for completed allowed calls bind policy context to measured usage and the effective model actually used—not just the one requested.
Execution plane
Fabric catalog: EmpowerID Governed Tool Gateway
MCP carries the call. EmpowerID determines whether the call may become an enterprise action.
EmpowerID MCP Gateway is the MCP-aware Policy Enforcement Point of Identity Fabric. It verifies who an agent represents, scopes tool discovery, authorizes each invocation through Governed Authorization, enforces constraints, protects downstream credentials, and records correlated action evidence.
Delegation
Bounded authority—not a copied user role
A person or governed process grants an agent bounded capability. The agent does not inherit an unrestricted copy of the delegator’s access.
Discovery
Policy-scoped tool catalogs
Before an agent plans, EmpowerID exposes an appropriately scoped catalog from delegation and Identity Fabric context—including virtual MCP servers for different roles and use cases.
Invocation
Reauthorization before dispatch
Each tool call re-verifies binding, delegation, schema integrity, and PDP authorization. Policy change, revocation, or schema drift can stop the next governed invocation.
Inventories, normalizes, correlates, and compares identity and access state.
Collections & DGE: External Sync Policies, Resource Collections, ABAC membership sync to Entra ID and SAP IAS, with Proof Chain evidence.
Dynamic Group Management (preview) →Governed identity views over LDAP/SCIM and protocol bridges.
Coordinates approvals, workflows, connectors, and fulfillment—including Identity Journey Orchestration to turn policy obligations into secure, resumable identity journeys with typed evidence.
Identity Journey Orchestration →EmpowerID MCP Gateway—MCP-aware PEP that verifies delegation, scopes tool discovery, authorizes invocation through Governed Authorization, protects credentials, and records correlated action evidence.
MCP Gateway service page →Identity-aware model PEP—prompt classification, delegated authority, spend-aware authorization, managed provider credentials, and signed allow-path receipts before inference.
LLM Gateway service page →Reporting, dashboards, evidence queries, and analytics experiences.
Online
Powered by EmpowerID AI