PDF whitepaper
SSF / CAEP Continuous Access
How EmpowerID implements governed continuous access on the Identity Fabric
Analyst brief — product demonstration scope
This is an EmpowerID implementation brief describing how SSF and CAEP operate on the Identity Fabric. It assumes familiarity with the OpenID Shared Signals Framework and CAEP; it does not re-teach the standards and does not imply OpenID Foundation certification unless explicitly stated in a current EmpowerID conformance claim.
Summary
This brief describes how EmpowerID implements SSF and CAEP on the Identity Fabric and what is structurally different from a typical signal-distributor plus session-revoke deployment. Continuous access lives in governed effects—AuthZEN evaluation, dual enforcement surfaces, loop-safe topology, and a causal operator timeline—not in forwarding notifications alone.
SSF push (RFC 8935), CAEP receiver, and AuthZEN policy evaluation are described as supported implementation paths in this brief. SSF poll and formal transmitter conformance are on a defined roadmap.
What's inside
-
Governed effects, not a signal feed
SSF/CAEP as a governed-effects control plane on the same spine as IGA, authorization, orchestration, and agent execution.
-
Pre-dispatch denial
Block unsafe agent actions before tool or MCP dispatch—even when underlying credentials still look valid.
-
Separated evidence
Delivery fact, authorization disposition, and enforcement disposition as distinct immutable facts—not one handled flag.
-
Dual enforcement surfaces
Human path: BFF session invalidation. Agent path: authority guard at the execution boundary.