Architecture

Identity and telemetry in. Governed execution and evidence out.

Six integrated layers turn fragmented enterprise events into portable, policy-bound trust records across identity, AI platforms, cloud and governance systems.

Reference architecture

A standards-based control plane.

Compute Passport owns CPID semantics, passport schemas, current status, policy obligations, verification profiles and evidence references. Cloud and identity platforms provide implementation primitives without defining the passport model.

01 · Identity Fabric

Humans, agents, models, tools, workloads and compute.

02 · Policy Engine

ABAC/ReBAC, obligations, approvals, risk gates and data boundaries.

03 · Trust Registry

Passport issuance, status, verification, trust anchors and revocation.

04 · Execution Guardrails

Gateways, tool interceptors, model endpoints, workloads and transaction controls.

05 · Evidence & Audit

Signed events, provenance, decisions, approvals, outcomes and audit packages.

06 · Enterprise APIs

IAM, SIEM, GRC, cloud, Kubernetes, AI platforms and business systems.

Open / portable

Integrate instead of replace.

IdentityMicrosoft Entra, Okta, Ping, AWS IAM Identity Center, PAM / IGA.
AI platformsAzure AI Foundry, Copilot Studio, Amazon Bedrock AgentCore and custom frameworks.
Cloud & computeAzure, AWS, Google Cloud, Kubernetes, containers, GPU clusters and edge.
SecuritySIEM, SOAR, EDR, gateways, secrets, DLP and vulnerability management.
GovernanceGRC, privacy, records, audit, procurement, CMDB and ITSM.
StandardsOIDC, OAuth 2.0, SCIM, SPIFFE/SPIRE, X.509, JWT/COSE and OpenTelemetry.
Design rule

No single product is mandatory. The customer boundary selects implementation services while Compute Passport preserves identity, policy, status, revocation and evidence semantics.