Skip to content
ECZ-IDService & Workload

ECZ-ID Service & Workload Passport™

An identity for your service that outlives every pod.

For teams that operate production services, workloads and data pipelines — in any cloud. Inside your cloud, a workload is identified by identifiers nobody outside can read. One public ECZ-ID names the enduring service and who operates it, with no cloud account identifiers in the public record.

£0 · No card required · Permanent, not a trial.

One Service & Workload Passport

Identity
ECZ-XX-XXXXXX::SERVICE_WORKLOAD_PASSPORT-XXXXXX
Operator
Your organisation, on the record as its Parent
Public proof
A Resolver record anyone can open, and its JSON
Price
£0 — no card required

Identifier shown as a pattern, not a real record. DECLARED information is self-declared; re-check the live record before you rely on it.

Four reasons to be here. Pick yours.

I operate thisYou run a service or workload and want it to have an identity anyone can check.
I need to check thisSomeone gave you an ECZ-ID, or did not, and you have to decide whether to rely on it.

The Resolver is the only authority on an ECZ-ID’s public state, and no answer it gives is a judgement about safety. Re-check before you rely on it.

I build with thisYou want the machine surface: the record, the schema, and how to publish an identity from code.

Every public record has a machine form at https://api.ecocitizenz.com/api/p/{ecz_id}.json — no account, no key, no rate card for reading it.

I operate a platformYou have an estate, a marketplace or a fleet, and you are deciding whether this belongs in it.

Large estates, procurement evidence, OEM and distribution are a conversation, not a checkout.

Multi-Cloud Identity Graph

Every native identity inside. One that is readable outside.

Inside your infrastructure a workload already has several identities, all short-lived and none legible to anyone without access to it. The Passport replaces none of them — it is the one a counterparty can read.

Internal identities, the logical service, and what it exposes

  1. The identities it already has

    Issued by your clusters and cloud accounts, rotated on their own schedule, and meaningless to anyone outside them.

  2. all identify

    Service & Workload Passport

    One Service & Workload Passport is one logical service or workload your organisation operates.

  3. operated by

    Your organisation

    One ECZ-ID Business Passport, created free the first time you acquire any Passport. Every Passport below hangs from it, and it never changes.

  4. exposes

    API Passport

    Services expose APIs. Each API is identified separately from the workload that serves it.

None of your internal identifiers — cluster names, account numbers, SVIDs, role ARNs — reaches the public record, and holding a Passport grants nothing inside your infrastructure. Linking those identities to the ECZ-ID is a separate, optional capability.

The full graph, and what a line never means

Included free: Basic Graph participation and a current one-hop view.

Stays native. Nothing is replaced.

Nothing below is replaced or proxied. Each keeps issuing exactly what it issues today, and keeps governing access on its own terms.

  • SPIFFE and SPIRE
  • Kubernetes service accounts
  • Microsoft Entra Agent ID and workload identities
  • AWS IAM
  • Google Cloud IAM and workload identity federation

Rebuild the cluster, move the region, scale to zero and back — the ECZ-ID stays the same.

Illustrative identifier shape

ECZ-XX-XXXXXX::SERVICE_WORKLOAD_PASSPORT-XXXXXX

Pods, replicas, regions, environments and deployments of that workload are not separate Passports.

Bindings, versions, replicas, endpoints and deployments never consume AEC and never become a second Passport.

Illustrative. This is the shape a record of this kind can take, not a live estate — a new Passport starts with no bindings and no relationships, and shows only what its operator chooses to publish.

Reading a record is on demand, with no account and no key. Nothing here watches an entity for you; ongoing monitoring is a separate, optional capability.

A partner integrating with your service today has a hostname and nothing else. Give them an identity that survives your next migration.

Free Service & Workload Passport

What your free Service & Workload Passport establishes.

One Service & Workload Passport is one logical service or workload your organisation operates. Pods, replicas, regions, environments and deployments of that workload are not separate Passports.

Included, at £0

  • A persistent ECZ-ID for the service or workload.
  • Your organisation on the record as its operator — a free DECLARED Parent is created if you do not already have one.
  • A public Resolver record anyone can open, and the same record as machine-readable JSON.
  • A badge, a QR code and a share link.
  • Basic bindings to the public places your service or workload already appears.
  • Lifecycle and current public state, evaluated on demand.
  • Claim and recovery.
  • Basic participation in the Digital Entity Graph.
  • Essential lifecycle evidence, kept in LedgerCore.

Publishing the record is your decision. Nothing becomes public until you consent, and you can withdraw publication later.

What the record never blurs

DECLARED ≠ VERIFIED
A DECLARED record states what your organisation says about itself, with the date it said it. It is not the outcome of an independent check.
Identity ≠ Binding
The Passport identifies the service or workload. A binding records a public place it already appears. Adding a binding never creates a second identity.
Binding ≠ Authority
A binding shows that a relationship has been declared. It does not grant, prove or imply authority to act.
Parent verification ≠ Service & Workload verification
A VERIFIED or ASSURED Parent verifies your organisation. It does not verify the service or workload.

How it works

From identity to proof, in five steps.

  1. Create or claim the identity

    Start in TrustOps with one sign-in. Your organisation's free DECLARED Parent is reused or created, and the service or workload gets its ECZ-ID.

  2. Configure and bind

    Add the public places your service or workload already appears — a published service or status page or public documentation for the service. Each binding records where it was learned.

  3. Prove it on the Resolver

    Anyone can open the public record and its JSON, with no account and no API key — and re-check it before relying on it.

  4. Operate

    Publish the ECZ-ID where people and machines already look, and manage it from your ECZ-ID console.

  5. Strengthen, only if useful

    Parent verification, monitoring, evidence and authority are optional. None is needed to hold a Passport.

Interoperability

Works alongside what you already run.

A Service & Workload Passport complements cloud and workload identity. SPIFFE, IAM and service accounts govern access inside your infrastructure; the Passport is readable outside it.

Native where you operate. ECZ-ID where you interoperate.Keep the identities your platforms need. Add the identity everyone else can resolve.

  • SPIFFE and SPIRE

    What it does: Issue short-lived workload identities inside your infrastructure.

    What ECZ-ID adds beside it: A stable public identifier for the enduring service, rather than a rotating internal one for a running process.

  • Kubernetes service accounts

    What it does: Identify pods to the cluster and to other workloads in it.

    What ECZ-ID adds beside it: One identity for the logical workload that stays the same while pods, replicas and clusters change.

  • Microsoft Entra Agent ID and workload identities

    What it does: Govern what an agent or workload may do inside your Microsoft tenant.

    What ECZ-ID adds beside it: An identity that resolves outside the tenant, for parties with no access to it.

  • AWS IAM

    What it does: Governs what a role or workload may call inside your AWS accounts.

    What ECZ-ID adds beside it: A public identity a counterparty can read without any access to your accounts.

  • Google Cloud IAM and workload identity federation

    What it does: Govern access to your Google Cloud projects.

    What ECZ-ID adds beside it: A public identity readable outside your projects, naming the organisation that operates the subject.

ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path.

Read the interoperability boundaries in full

Digital Entity Graph

Service & Workload Passports, and what they connect to.

One identity, the representations it is bound to, and the other identities it legitimately relates to. Each is a separate ECZ-ID with its own operator — never a copy of this one.

Operator

  • Your organisation

    One ECZ-ID Business Passport, created free the first time you acquire any Passport. Every Passport below hangs from it, and it never changes.

Identity

  • Service & Workload Passport

    One Service & Workload Passport is one logical service or workload your organisation operates.

Bound representations

  • a published service or status page

    A representation of the same subject. It never becomes a second Passport.

  • public documentation for the service

    A representation of the same subject. It never becomes a second Passport.

  • a public endpoint you declare

    A representation of the same subject. It never becomes a second Passport.

Relates to — separate identities, separately operated

Illustrative. This is the shape a record of this kind can take, not a live estate — a new Passport starts with no bindings and no relationships, and shows only what its operator chooses to publish.

A relationship is not permission

Every line above says two things are connected. None of them says one is allowed to act for the other. Authority is granted in your own systems, and ECZ-ID does not grant it, infer it or enforce it.

What the record does establish

  • Which organisation operates this entity, named on the public record.
  • The organisation's own tier, and exactly what that tier covers.
  • Which representations the operator has bound to this one identity.
  • What the record said at the moment you resolved it.

What it never establishes

  • That the entity is safe, correct, approved or certified.
  • That a connected entity may act on this one's behalf.
  • That any permission, scope or credential has been delegated.
  • That a relationship shown here is currently active in production.

Live proof

Don't take our word for it. Resolve us.

EcoCitizenz Ltd runs this site and holds its own ECZ-ID. Everything below is read from the public record, by anyone, with no account and no key — including the parts that are empty.

ECZ-ID

active

EcoCitizenz

ECZ-GB-RBS1NW

Operated by
ECOCITIZENZ LTD
Organisation tier
VERIFIED
Bound representations
None published
Public relationships
None published

The parent organisation's identity is verified. This machine is not.

Evidence available

  • Not revoked
  • Ledger-anchored
  • No live PulseGuard monitor
  • No receipts in 30 days
Read from the public record on 2026-09-21. The Resolver is the authority; this page is a copy of what it said.

Check it yourself

The same record answers for humans and machines. One is a page, the other is JSON with no authentication in front of it.

curl -s https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json | jq .resolver_v2.state

What it does not prove

That this company is safe to deal with, that its software is correct, or that anyone has audited it. A record establishes who an entity is and who operates it. Everything else is your decision, and you should re-check before you rely on it.

Scale

AEC — Active Entity Capacity

A free Passport exists and resolves whether or not you use any AEC. AEC is the capacity to actively manage entities in production.

What one AEC is

One AEC is one actively managed production entity with live bindings and current state.

For Service & Workload Passports: A logical service or workload you actively manage in production, with live bindings and current state.

One pool across families

AEC is one pool shared across your Agent, MCP, Plugin, API, SDK and logical Service & Workload identities, and your IoT product, model and fleet identities.

What AEC never does

  • AEC never makes an identity more verified.
  • AEC never replaces a Passport.
  • AEC never changes an ECZ-ID. Your ECZ-ID does not change.
  • Running out of AEC never deletes, revokes or unpublishes an identity.

Individual IoT device instances are counted separately, in IoT Fleet Capacity, and never consume AEC.

Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. Your organisation’s included AEC and any additional capacity are configured there.

Products

Built for Service & Workload Passports

When the free Passport is not enough, these are the Service & Workload products that extend it. Everything is bought and billed in TrustOps.

Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. What you see here is what it published on .

Strengthen

Strengthen only when it is useful.

Nothing here is needed to hold a Passport, and not taking it never downgrades an identity you already hold.

  • Parent VERIFIED and ASSURED

    Independent verification of the organisation behind your Passports. VERIFIED suits production use; ASSURED is the higher-assurance posture for larger or more sensitive estates.

    Boundary: It verifies your organisation. It never verifies an agent, a server or any other child identity, and it never changes an ECZ-ID.

    Included free: Every Passport starts with a free DECLARED Parent — created for you if your organisation has none.

  • Workload Identity Federation

    Links the ECZ-IDs of your logical services to the workload identities they already run under.

    Boundary: It never replaces or controls your cloud IAM, SPIFFE identities or service accounts.

Also relevant to Service & Workload Passports

  • PulseGuard

    Current-state evaluation for the entities you operate. Paid tiers extend evaluation across more entities and more evaluations each month.

    Included free: On-demand and event-driven evaluation of your own entities.

  • EvidenceCorePart of the ECZ-ID V2 build

    The evidence behind each claim on a record: what supports it, where it came from, when it was checked and who may see it.

    Included free: Essential evidence references are part of every free Passport.

  • LedgerCore

    Tamper-evident retention of decisive lifecycle evidence — issuance, activation, material bindings, authority changes, suspension and revocation — with eligible evidence anchored to a permissioned, append-only ledger.

    Included free: Essential LedgerCore evidence is kept for every identity, free ones included.

  • Digital Entity Graph and Graph Intelligence

    The public-safe relationships between your organisation, its Passports and their bindings. Graph Pro, Graph Business and Enterprise Graph Intelligence add scale, history and custom analysis above the free view.

    Included free: Basic Graph participation and a current one-hop view.

Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal.

One identity layer

Seven kinds of machine-economy entity.

Each is a separate subject with its own Passport, its own operator and its own public record. They are the same identity layer, not seven products.

When to give something its own Passport

When it is a different logical subject with its own operator and its own lifecycle. Something operated by someone else is a second subject. The same thing in three regions, versions or listings is still one.

Never mint a second Passport for another representation of the same thing — a version, a replica, an endpoint or a listing. Those are bindings, and they cost no capacity.

From here, the ones that most often turn out to be separate subjects are API, SDK and Agent.

See how they relate

Start with the identity. Everything else is optional.

£0 · No card required · Permanent, not a trial.

Current availability

The Service & Workload door is not open yet.

The Service & Workload Passport is free — £0, permanently, and never sold. That is the price, and it is not what is missing. What is not ready is the door: ECZ-ID Core is not issuing Service & Workload Passports yet, and the Resolver is not projecting Service & Workload records yet.

So this site publishes no start link, no waiting list and no date. When both are live, the family is opened through one configuration value in the Website Factory and the control appears on every page here at once. No page on this site is rewritten to do it.

Nothing on this site can be bought in the meantime. Paid capabilities are described here and configured in TrustOps, which owns every purchase.

How an ECZ-ID resolves, and what a record is not