Why IntentGateThe Missing LayerPlatformCapabilitiesLive DemoPricing
More
ArchitectureCAPA Reference ArchitectureSolutionsIndustriesGovernancePartnersResourcesAPIsDocsBlog Talk to us
Enterprise Reference Architecture

Continuous Authority Propagation Architecture

CAPA defines how governed business authority moves from trusted identity through executable policy and runtime decisions into controlled execution and verifiable evidence.

DocumentReference Architecture
VersionCAPA v1.0
ScopeHuman + Non-Human Authority
Control ChainIdentity → Authority → Decision → Evidence
Architectural Thesis

Access is assigned once. Authority must survive execution.

Enterprise IAM and IGA already establish identities, roles, attributes and standing access. CAPA extends that foundation by preserving business authority as an action moves from governance into execution.

Purpose, scope, conditions, limits and accountability become executable policy, are re-evaluated at runtime, and remain linked to the evidence generated after execution.

01Trusted Identity
02Business Authority
03Executable Policy
04Runtime Decision
05Controlled Execution
06Evidence
Reference Blueprint

The authority propagation chain.

Instead of another static architecture matrix, CAPA is shown as four connected control stages. Each stage receives governed information, transforms it, and passes a more executable artifact forward.

L1 · Identity

Trusted Identity Foundation

Establish the canonical actor and trusted enterprise context.

  • Humans and workforce identities
  • AI agents and workloads
  • Service identities and devices
  • Business and environment attributes
PropagatesTrusted identity + business context
L2 · Authority

Authority Governance

Turn standing access and business responsibility into executable authority. Policy is the executable representation of that authority.

  • Roles, attributes and entitlements
  • Purpose, scope and limits
  • Delegation and approval
  • Certification and accountability
PropagatesExecutable policy + authority boundaries
L3 · Decision

Runtime Authorization

Evaluate the real action under live conditions before execution.

  • Identity and authority context
  • Requested operation and parameters
  • Live environmental conditions
  • Permit · restrict · step-up · deny
PropagatesExecution decision
L4 · Evidence

Controlled Execution

Carry the approved decision into execution and preserve the proof.

  • Execute only approved actions
  • Just-in-time execution controls
  • Decision-to-action correlation
  • Tamper-resistant evidence
ProducesControlled execution + evidence
Governance feedback Runtime evidence closes the loop.

Observed execution feeds attestation, least-privilege recommendations, authority review and future policy refinement.

Establish the actor before governing authority.

CAPA starts with the identity foundation already trusted by the enterprise. This layer is intentionally broad enough for workforce identities, AI agents, service accounts, workloads and devices.

Identity Resolution

Canonical actor

Resolve the human or non-human subject that is responsible for the action.

Context

Trusted business attributes

Attach organization, environment, device, workload and delegated context.

Boundary

What this layer does not decide

Identity proves who or what is acting. It does not independently determine the business authority for the action.

Enterprise Fit

Use what already exists

Existing HR, IdP, directories and workload identity systems remain authoritative sources.

Layer outputTrusted identity + contextual attributes

Translate access into governed business authority.

Layer 2 is where existing access governance becomes a richer expression of what the actor may do, why the authority exists, where it applies and which boundaries must remain true.

Established Governance

Roles, attributes and entitlements

Roles, attributes, entitlements, access requests, certifications and SoD remain part of the governance foundation.

Business Authority

Purpose, scope and limits

Standing access is combined with explicit business purpose, scope, quantitative limits and contextual conditions.

Accountability

Ownership and approval

Authority is tied to accountable owners, approval paths, delegation and review cycles.

Transformation

Executable policy

The governance model is compiled into a form that the runtime control layer can evaluate deterministically.

Layer outputExecutable policy + authority boundaries

Re-evaluate authority at the moment of action.

The runtime layer receives governed authority from Layer 2 and evaluates the exact operation being attempted under live conditions. This is the shift from assignment-time governance to execution-time control.

Decision Input

Actual requested action

Evaluate the tool, operation, parameters, target resource and transaction details that are about to execute.

Live Context

Conditions at decision time

Re-evaluate authority against environment, risk, session, velocity and other runtime conditions.

Policy Decision

Deterministic outcome

Permit, restrict, redact, step-up, require approval or deny.

Control Point

Before execution

The decision is made immediately before the downstream system receives the action.

Layer outputExecution decision

Carry the decision into execution, and preserve the proof.

The final layer ensures that the action that actually executes remains bound to the decision that authorized it. That lineage is preserved as evidence for audit, compliance and forensics.

Execution

Only the approved action proceeds

Apply the decision to the actual downstream action and use temporary or scoped credentials where needed.

Correlation

Decision-to-action lineage

Preserve a direct relationship between actor, authority, policy, runtime decision and executed action.

Evidence

Tamper-resistant records

Produce records that support investigation, audit, compliance and non-repudiation.

Feedback

Improve future governance

Observed execution becomes evidence for attestation, authority optimization and least-privilege recommendations.

Layer outputControlled execution + immutable evidence
From Governed Access to Executable Authority

Govern access. Carry authority into execution.

CAPA does not ask enterprises to discard RBAC. It extends established identity and access governance into runtime authority and verifiable execution.

Assignment-Time Governance

The familiar model remains the enterprise foundation for structured access.

Birth-right, generalBroad baseline access
Mostly automatic
Birth-right, organizationalInherited by context
Automatic / inherited
Functional business roleProcess and task access
Mixed governance
Specialist roleElevated / exception access
Requested & approved

Execution-Time Authorization

CAPA extends the access model into the actual requested action.

01
Role / AccessExisting entitlement and assignment foundation
02
Business AuthorityPurpose, scope, limits, conditions and accountability
03
Runtime DecisionEvaluate the actual action under live conditions
04
EvidenceBind decision and execution into verifiable lineage
Identity & Access GovernanceBusiness AuthorityRuntime AuthorizationExecution Evidence
Reference Implementation

CAPA defines the architecture. The IntentGate platform operationalizes it.

The model remains vendor-neutral. Existing enterprise controls map into the architecture, while IntentGrant and IntentGate provide an integrated implementation across governance and runtime.

IntentGrant → Authority Governance
IntentGate → Runtime Authorization
Proof → Execution Evidence
L1
Trusted IdentityExisting HR, IdP, directories, workload and device identity
Authoritative context consumed
L2
Authority GovernanceIGA, RBAC, ABAC, SoD, requests, certification, delegation
IntentGrant
L3
Runtime AuthorizationInline decision and enforcement
IntentGate
L4
Execution & EvidenceApplications, APIs, tools, credentials and audit
Built-in Proof

Map your existing architecture into CAPA.

Use CAPA as the reference model connecting identity governance, business authority, runtime authorization and execution evidence.

Architecture Briefing →