PDF whitepaper
From Agent Pilots to Governed Operations
How EmpowerID Agent Teams operates AI agents as durable, chartered teams on the Identity Fabric—explicit authority, deterministic run lifecycle, autonomy matched to consequence, human confirmation that stops execution, and evidence from charter to result.
Agent Governance whitepaper — From Agent Pilots to Governed Operations
This whitepaper describes EmpowerID Agent Teams as the governed operations application and runtime on the Identity Fabric—durable team charters, heartbeat-driven work, deterministic stages, Contract-Driven Autonomy confirmation gates, fleet controls, and correlated evidence from covered model, tool, and execution paths. It does not claim automatic learning from outcomes, universal receipts, a connector marketplace, or fully autonomous customer communication as a default. Feature availability, studio surfaces, Local Worker connectors, and template scope vary by edition and deployment.
Summary
Agents now monitor conditions, plan multi-step tasks, coordinate with other agents, and propose or execute changes across business systems. That work raises questions an agent builder cannot answer: who owns the agent after deployment, what is the team chartered to do, whose authority does it exercise, which steps may run under policy and which must wait for a human, who can stop it—and what evidence connects charter, decision, approval, and result. EmpowerID Agent Teams is the governed operations application and runtime on the EmpowerID Identity Fabric. Heartbeats initiate proactive work; runs and stages give model reasoning a deterministic lifecycle; Contract-Driven Autonomy turns consequential steps into structured decisions; Agent Teams Studio gives operators fleet, run, approval, and stop controls. The surrounding fabric separately governs identity, delegation, model calls, tool calls, execution, credentials, and evidence. One principle organizes the architecture: the model contributes intelligence; the platform owns the operating lifecycle.
Agent Teams consumes Identity Fabric authentication, delegation, Governed Authorization (OpenID AuthZEN), LLM Gateway, MCP Gateway, and Orchestration services. It correlates evidence from those paths—it does not replace their enforcement semantics.
What's inside
-
A team is a charter, not a group chat
Durable teams with graph-backed authority—distinct from any run, conversation, or prompt. Team, run, and stage stay separate so state never lives in the transcript.
-
Autonomy matched to consequence
Contract-Driven Autonomy resolves each step to execute, need input, wait for confirmation, or fail—with a side-effect ledger, pre-mutation controls, and explicit failure semantics before external systems change.
-
The model proposes. The platform owns the lifecycle.
Worker-tier determinism: models contribute typed artifact content; the graph executor owns claim, stages, schema validation, handoffs, and terminal state.
-
The operate layer of the Identity Fabric
AI Agent Discovery registers actors. LLM and MCP Gateways govern model and tool calls. Orchestration + CDA executes. Agent Teams operates teams over time on the same policy plane.
-
Evidence that survives the transcript
Governance timeline linking charter, delegation, policy decision, approval, execution, and result—signed receipts on covered model and tool paths only.