ID
Identity Governance & Administration
Govern identity lifecycle, ownership and access accountability for human and machine actors.
- Human, NHI and AI agent identities
- Identity lifecycle and ownership
- Access requests and approvals
- Certification, roles and SoD
BA
Business Authority & Delegation
Define who is accountable, what authority exists and how that authority may be delegated.
- Accountable ownership
- Business Authority modeling
- Delegation and on-behalf-of
- Authority mining and drift
AZ
Fine-Grained Authorization
Evaluate authority at the level of the actual action, resource, relationship and runtime context.
- RBAC, ABAC, PBAC and ReBAC
- Purpose and intent-aware authorization
- Runtime policy evaluation
- Relationship-aware authority
AI
AI & Non-Human Identity Governance
Apply accountable lifecycle, purpose, ownership and authority controls to agents, NHIs and workloads.
- AI agent governance
- NHI and workload identity
- Agent ownership and purpose
- Controlled delegation and limits
DA
Data Authorization
Carry policy into the data operation itself so access can be scoped, filtered, masked or redacted.
- Row and column authorization
- Data-scope obligations
- Masking and redaction
- Policy-aware filtering
RT
Runtime Enforcement
Put authority in the execution path across MCP, APIs, applications, workloads and deep runtime resources.
- MCP and API enforcement
- Application and workload enforcement
- Distributed enforcement points
- Deep Runtime Resource Authority
RC
Runtime Controls
Change or constrain authority as conditions change through step-up, limits, containment and adaptive controls.
- Step-up and re-authorization
- Limits, budgets and guardrails
- Kill switch and containment
- Adaptive/risk-based controls
EV
Evidence & Assurance
Keep decision, enforcement and execution as attributable facts that can be correlated into verifiable evidence.
- Authorization decisions
- Enforcement and execution outcomes
- Cryptographic proof
- Auditable evidence lineage