Identity Fabric whitepaper · PDF · August 2026
Proof, Not Logs
How EmpowerID Continuous Evidence turns governed actions into causal, integrity-checked proof — authority, decision, dispatch, and observed outcome linked on declared paths, configuration changes ledgered beside them, and every gap labeled instead of painted green.
Enterprises drown in telemetry and still fail audits. Continuous Evidence treats proof as a first-class product of governance — produced at the moment of action on declared paths, exportable, and independently verifiable.
EmpowerIDAugust 202620 min read432 KB PDFIdentity Fabric whitepaper — Proof, Not Logs
Proof pack
Illustrative causal proof pack with labeled gap
Scope
This whitepaper describes EmpowerID Continuous Evidence as Identity Fabric services that bind authority, policy decisions, dispatch, signed receipts, configuration-change ledger rows, and target read-back into exportable, integrity-checked proof on declared paths. It does not claim coverage of every enterprise action, SIEM replacement, immutable storage without verification, automatic regulatory compliance (DORA, NIS2, SOX, CPS 230), or retention schedules set by EmpowerID. Gaps are labeled product behavior. Feature availability varies by edition, deployment, and connected systems.
Executive summary
Most “audit trails” flatten authentication, apparent permission, a call, and a status code into one success string. Under agentic systems, connector automation, and privileged configuration change, that collapse fails: an AI agent can propose, a gateway can return 200, a SIEM can correlate a packet, and still nobody can answer under which authority, which policy version, which consumed permit, and with what observed outcome. EmpowerID Continuous Evidence binds Identity Fabric artifacts — authority lineage, AuthZEN decisions, governed directives and jobs, signed receipts, Config-Change Ledger rows, and target read-back where connectors support it — into integrity-checked proof on declared paths. Coverage is a product feature: full, partial, or gap — never a silent green. Logs help investigate; causal receipts account for declared governed actions.
What's inside
Causal proof, not flattened success strings
Authority, policy version, consumed permit, dispatch, and observed outcome stay distinct — so an auditor can answer who acted for whom, what was permitted, and what was verified.
Declared paths, labeled gaps
Evidence is complete where enforcement and producers are installed. Everywhere else shows as a labeled gap — never painted green.
Tamper-evident and independently verifiable
Exported records verify against published keys without trusting the vendor console. Alterations break hash chains; truncation fails checkpoints — when the verifier is actually run.
Config-Change Ledger beside action receipts
Loosen–act–restore stories surface as twin records: before/after configuration changes ledgered next to the actions they enabled.
Supports control evidence — not compliance claims
Maps selected control objectives on declared paths. Change approval, testing, incident reporting, and access-review programs remain the customer’s.
Five questions to ask any evidence platform
- Can you export a proof pack that links authority, policy version, dispatch, and observed outcome — or only a success log line?
- Where coverage ends, is the gap labeled, or does the console paint missing paths as verified?
- Can an auditor verify integrity on their own machine against published keys — without trusting your operator console?
- Are configuration changes that loosen policy ledgered beside the actions they enable?
- Does the product claim compliance with DORA/NIS2/SOX, or only evidence for selected controls on declared paths?