Trusted Identity Foundation
Establish the canonical actor and trusted enterprise context.
- Humans and workforce identities
- AI agents and workloads
- Service identities and devices
- Business and environment attributes
CAPA defines how governed business authority moves from trusted identity through executable policy and runtime decisions into controlled execution and verifiable evidence.
Enterprise IAM and IGA already establish identities, roles, attributes and standing access. CAPA extends that foundation by preserving business authority as an action moves from governance into execution.
Purpose, scope, conditions, limits and accountability become executable policy, are re-evaluated at runtime, and remain linked to the evidence generated after execution.
Instead of another static architecture matrix, CAPA is shown as four connected control stages. Each stage receives governed information, transforms it, and passes a more executable artifact forward.
Establish the canonical actor and trusted enterprise context.
Turn standing access and business responsibility into executable authority. Policy is the executable representation of that authority.
Evaluate the real action under live conditions before execution.
Carry the approved decision into execution and preserve the proof.
Observed execution feeds attestation, least-privilege recommendations, authority review and future policy refinement.
↶CAPA starts with the identity foundation already trusted by the enterprise. This layer is intentionally broad enough for workforce identities, AI agents, service accounts, workloads and devices.
Resolve the human or non-human subject that is responsible for the action.
Attach organization, environment, device, workload and delegated context.
Identity proves who or what is acting. It does not independently determine the business authority for the action.
Existing HR, IdP, directories and workload identity systems remain authoritative sources.
Layer 2 is where existing access governance becomes a richer expression of what the actor may do, why the authority exists, where it applies and which boundaries must remain true.
Roles, attributes, entitlements, access requests, certifications and SoD remain part of the governance foundation.
Standing access is combined with explicit business purpose, scope, quantitative limits and contextual conditions.
Authority is tied to accountable owners, approval paths, delegation and review cycles.
The governance model is compiled into a form that the runtime control layer can evaluate deterministically.
The runtime layer receives governed authority from Layer 2 and evaluates the exact operation being attempted under live conditions. This is the shift from assignment-time governance to execution-time control.
Evaluate the tool, operation, parameters, target resource and transaction details that are about to execute.
Re-evaluate authority against environment, risk, session, velocity and other runtime conditions.
Permit, restrict, redact, step-up, require approval or deny.
The decision is made immediately before the downstream system receives the action.
The final layer ensures that the action that actually executes remains bound to the decision that authorized it. That lineage is preserved as evidence for audit, compliance and forensics.
Apply the decision to the actual downstream action and use temporary or scoped credentials where needed.
Preserve a direct relationship between actor, authority, policy, runtime decision and executed action.
Produce records that support investigation, audit, compliance and non-repudiation.
Observed execution becomes evidence for attestation, authority optimization and least-privilege recommendations.
CAPA does not ask enterprises to discard RBAC. It extends established identity and access governance into runtime authority and verifiable execution.
The familiar model remains the enterprise foundation for structured access.
CAPA extends the access model into the actual requested action.
The model remains vendor-neutral. Existing enterprise controls map into the architecture, while IntentGrant and IntentGate provide an integrated implementation across governance and runtime.
Use CAPA as the reference model connecting identity governance, business authority, runtime authorization and execution evidence.