Skip to content
ECZ-IDService & Workload

graph

ECZ-ID Graph Intelligence

See how your estate connects, and how the connections changed.

Graph Intelligence is a view of the relationships between the identities your organisation holds: which agent calls which MCP server, which workload runs which package, which Passports your organisation owns, and how each of those links looked before today. It reads material that already exists — Passports, the bindings recorded against them and the declared links between them — and answers questions about the shape of an estate rather than about any single entity. It is a commercial entitlement that sits on top of identity; a line in it records a declared relationship, and it is never an endorsement, a permission or a proof.

An estate is normally understood a record at a time, which is enough until somebody asks what depends on the thing you are about to change. That question is not about any single entity, so no single record answers it, and the usual substitute is a diagram somebody drew from memory and nobody has revised since. Graph Intelligence answers it from what has actually been recorded, and with history, so you can see when a relationship appeared and when it stopped. Be clear about the limits before you spend anything: it shows what has been declared and bound, so whatever nobody recorded is simply absent from it, and an absence is not a finding. There is also no free tier of this product — every tier in the ladder is paid, and the basic Graph view that comes with a Parent organisation is a separate thing that stays exactly as it is whether or not you hold one.

What this means for Service & Workload

Services and workloads are the layer that churns. The same logical service is redeployed, renamed and moved between platforms, and it hosts things with identities of their own — an agent running as a workload is a different subject from the workload that runs it, and both matter during an outage. Graph Intelligence keeps the hosting relationships legible: which workload runs which service, which API a service serves, which package it runs, and which identity sits beneath all of it. History carries the part that incident reviews need and nobody has to hand, because the question there is never who owns this now. It is who owned it then.

What you already have

ECZ-ID Graph Intelligence has no free allowance. Every tier is paid, and your ECZ-ID Passports and their Resolver records remain free and unaffected either way.

The ladder

The price is set, but online purchase is not open yet. There is no checkout route for it today. Agreed directly rather than bought online, so the scope and the price are settled with you.

How ECZ-ID Graph Intelligence works
  1. 1.The raw material is already yours. Every Passport your organisation holds, every binding recorded against it and every declared link between them is a node or an edge before any tier is involved; Graph Intelligence reads that material rather than asking you to describe your estate a second time.
  2. 2.A tier sets the ceilings: how many relationships the graph holds for your organisation, how many queries it answers each month, and how far back the history reaches. Those figures are shown beside each tier and read from the commercial registry, and they are real ceilings rather than guidance — usage is cost-governed, and no tier offers unlimited variable-cost activity.
  3. 3.You then ask questions of the shape instead of the record: what is connected to this, what would be affected if it changed, what has appeared recently, what has gone quiet. The answers name identities you already hold, so anything the graph returns can be opened as a record.
  4. 4.History makes the same questions answerable about the past, as far back as the tier retains. That is the difference between knowing what the estate looks like now and knowing what it looked like on the day something went wrong.
  5. 5.Nothing is published on your behalf. The picture is drawn from records that already exist, publication stays a deliberate act of yours, and the graph adds no claim to any record it draws on.
Limits and conditions
  • One paid tier at a time within a billing scope. Tiers replace one another rather than stacking.
  • An upgrade replaces the lower tier rather than adding to it: the higher tier's allowances become the ones that apply.
  • No tier offers unlimited variable-cost activity. Every plan states the volume it includes.
  • Usage is cost-governed: the included volumes are real ceilings, not a soft guideline, so the service cannot run up an unbounded bill on your behalf.
  • No VAT charged. EcoCitizenz Ltd is not VAT-registered, so no VAT is added and no VAT invoice is issued.
How ECZ-ID Graph Intelligence differs from the other ECZ-ID products
LedgerCore
LedgerCore keeps decisive lifecycle events in a form that shows they have not been altered since. Its subject is a sequence: what happened, in what order, and when. Graph Intelligence has no opinion about events; its subject is the shape of the estate — what is connected to what, and what that looked like before. Most estates want both, and neither answers the other's question.
PulseGuard
PulseGuard watches the current state of the entities you operate and tells you when that state changes. Its subject is the health of an entity, repeated across however many you have. Graph Intelligence says nothing about whether anything is healthy or reachable; it describes the relationships between entities and stays silent about state.
The public Resolver record
A Resolver record answers about one subject at a time: this identifier, what is currently declared about it, what evidence exists, read at a stated time. It is public, free and needs no account. Graph Intelligence is the view across many subjects at once, for the organisation that holds them. The Resolver stays where a reader goes to check a claim, and a graph is never proof of anything the record does not already say.
Active Entity Capacity
Capacity packs stack: buy more than one and the allowances add together, because capacity is a quantity. Graph Intelligence is a tier, not a pack. A single paid tier applies within a billing scope, and moving up replaces the tier below rather than adding to it. They also count different things — capacity counts the entities your organisation actively manages, and a Graph tier counts relationships, queries and retained history.
After you buy, and how to change or cancel

What happens after purchase

  • The tier's ceilings apply to your organisation, and the graph holds, answers and retains within them. The figures beside the tier are the figures that apply.
  • Your ECZ-ID does not change. No Passport is re-minted, replaced or moved, and no identifier anyone has already quoted stops working.
  • Your Parent organisation's tier is untouched. A DECLARED organisation stays DECLARED; this never makes an organisation VERIFIED or ASSURED, and no amount of it is a substitute for the checks that do.
  • No child Passport's assurance moves. Nothing in the graph makes any record more verified than it was the day before, and a relationship shown in it is not a trust claim about either end.
  • Identity truth, every Resolver record and the basic Graph view that comes with a Parent organisation all read exactly as they did. This is a commercial entitlement, and commercial entitlements are never identity.

Upgrading

Moving up replaces the tier you hold rather than adding to it: a single paid tier applies within a billing scope, so the higher tier's ceilings become your ceilings. Nothing about identity travels with the change — the same ECZ-IDs, the same organisation tier, the same assurance on every child Passport, the same Resolver records. TrustOps owns the purchase and states the terms of the change at the point you make it.

Downgrading

Moving down works the same way in reverse: the smaller tier replaces the one you hold, and what the graph will then hold, answer and look back through follows the tier you are on. The underlying records are not the tier's to take — Passports, their bindings and every Resolver record are unchanged by the move, and the published links a graph is drawn from stay where they were published. Timing and terms belong to TrustOps.

Cancelling

Ending the entitlement ends the entitlement and nothing else. Your ECZ-IDs stay, your organisation's tier stays, every child Passport's assurance stays, the Resolver records read as before, and the basic Graph view that comes with a Parent organisation remains. Capacity is never identity, and the end of a commercial entitlement never revokes, detaches or deletes anything already issued. The cancellation terms themselves live in TrustOps, because TrustOps is the merchant and this page is not.
ECZ-ID Graph Intelligence — frequently asked questions
Is there a free version of Graph Intelligence?
No. Unlike the other products in this section, this ladder has no free allowance on any tier — each one is paid. What every Parent organisation already carries is a basic Graph view of the current picture, and that is a separate inclusion: it is not a trial of this product, holding a tier does not take it away, and ending one does not either.
Does a line in the graph mean permission?
No, and this is the misreading worth naming. A relationship records that a link has been declared or recorded between identities. Delegated authority is not published on the public machine record, so the graph cannot show it and does not imply it. Connection is the claim; permission is not.
Can I hold more than one tier, or add one to another?
No. A single paid tier applies within a billing scope, and an upgrade replaces the lower tier rather than stacking with it. That is the opposite of capacity packs, which do add up — tiers replace, packs accumulate, and the registry treats them as different kinds of thing.
Does this use my organisation's entity capacity, or my IoT device capacity?
Neither. Graph Intelligence is metered on relationships, queries and retained history, shown beside each tier. Active Entity Capacity is a separate pool that belongs to your organisation and is shared across the Agent, MCP, Plugin, API, SDK and Service & Workload families; IoT device instances are metered separately again, in IoT Device Fleet Capacity, and never draw on that pool. Holding a Graph tier neither adds to those meters nor spends them.
What happens when I reach a ceiling?
The ceiling holds. Usage is cost-governed so the service cannot run up an unbounded bill on your behalf, which is why no tier offers unlimited variable-cost activity. Reaching a limit means you cannot add more until there is room; it never revokes, deletes or detaches an identity, and nothing already published changes because a meter is full.
What do I need before it is any use?
A signed-in Parent organisation at DECLARED or above, and something recorded for the graph to read. A DECLARED organisation is enough — this never requires VERIFIED or ASSURED, and it never creates an organisation for you or changes the one you have. A new estate with little published yet will see a thin picture, which is the normal state of a new estate rather than a fault.
Can I take it from this page?
The control beside each tier tells you what is open today, and the reason is stated where it is not: a price can be set while the online route is not yet built, and the largest arrangement is agreed with you directly rather than taken from a page. What the product does is the same either way, which is why this description does not depend on which control you see.
Where do the prices and the terms live?
Every price, allowance and purchase control in this section is read live from the ECZ-ID commercial registry, so what you see here is what the registry currently says rather than a copy somebody kept by hand. Terms of purchase — billing, cancellation, anything contractual — belong to TrustOps, which is where a purchase is made. This page describes the product and states none of them.