02 / Tracking

Trace authority from sponsor to runtime action.

Build a live identity graph of agents, models, tools, workloads and compute, then resolve ownership, delegation, reachable actions and current status before sensitive requests proceed.

Identity graph

See the full operating context, not only the principal.

Discover

Ingest agents, accounts, roles, tokens, models, workloads, tools, clusters and enterprise metadata.

Resolve

Map ownership, sponsorship, delegation, model dependencies, tool calls, data access and execution paths.

Monitor

Check CPID status, credential proof, workload, model, region, destination and action context at sensitive points.

React

Trigger review, suspend the passport, revoke credentials or contain workloads after material change or anomalous activity.

Runtime binding

Identity for AI cannot stop at the model.

Runtime trust depends on the workload image, orchestrator, region, network, keys, compute and attestation context as well as the agent and model.

Agent
CPID + sponsor + authority

Who is acting and under whose mandate?

Model
Provider + version + approval

Which model is actually invoked?

Workload
Image + environment + attestation

Where is the authority executing?

Compute
Cloud + region + cluster + GPU

Does the execution environment match policy?

Tool / Data
Destination + class + action

Is the requested action inside the approved boundary?