PDF whitepaper
EmpowerID Governed Authorization
One decision authority. Every relevant fact.
Identity Fabric architecture whitepaper — Version 2.0
This whitepaper describes the canonical EmpowerID Governed Authorization architecture—one logical ABAC decision authority, graph super PIP context, and AuthZEN interfaces between PEPs and PDPs. Feature availability and enforcement coverage vary by product edition and integration scope.
Summary
Enterprise authorization breaks when every application, gateway, graph, and AI agent creates its own truth. EmpowerID Governed Authorization places one logical ABAC decision authority at the center of the authorization lifecycle—from business-defined capabilities and live context to enforcement, explanation, and safe change.
OpenID AuthZEN connects every PEP to the PDP. EmpowerID AuthZEN 1.0 certification covers PEP 01/02 and Search PEP 03. Evaluation, batch evaluation, and authorized search are supported integration patterns on the same decision authority.
What's inside
-
One logical ABAC authority
Applications define what access means through App Authorization Contracts. PIPs—including the graph/ReBAC super PIP—assemble facts. One governed policy model runs across distributed PDP instances.
-
Graph super PIP, not a second permit
Relationship intelligence feeds the ABAC decision. ReBAC contributes delegation, ownership, and membership facts—it never issues a competing authorization truth.
-
Contribution-aware revocation
The Grant Contribution Registry records every reason access exists. Remove one contribution; preserve every other legitimate reason—with present-state explanation distinct from change history.
-
Authorization before cognition
For AI agents: govern delegation creation, policy-scoped tool discovery, and invocation-time authorization as three distinct moments under the same logical authority.