Skip to content
ECZ-IDService & Workload

Works alongside

What an ECZ-ID Service & Workload Passport sits beside

A Service & Workload Passport complements cloud and workload identity. SPIFFE, IAM and service accounts govern access inside your infrastructure; the Passport is readable outside it.

Adjacent systems

What each already does, and what the Passport adds

ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path.
  • SPIFFE and SPIRE

    What it does
    Issue short-lived workload identities inside your infrastructure.
    What an ECZ-ID adds
    A stable public identifier for the enduring service, rather than a rotating internal one for a running process.
  • Kubernetes service accounts

    What it does
    Identify pods to the cluster and to other workloads in it.
    What an ECZ-ID adds
    One identity for the logical workload that stays the same while pods, replicas and clusters change.
  • Microsoft Entra Agent ID and workload identities

    What it does
    Govern what an agent or workload may do inside your Microsoft tenant.
    What an ECZ-ID adds
    An identity that resolves outside the tenant, for parties with no access to it.
  • AWS IAM

    What it does
    Governs what a role or workload may call inside your AWS accounts.
    What an ECZ-ID adds
    A public identity a counterparty can read without any access to your accounts.
  • Google Cloud IAM and workload identity federation

    What it does
    Govern access to your Google Cloud projects.
    What an ECZ-ID adds
    A public identity readable outside your projects, naming the organisation that operates the subject.

Adjacent identities

The Passports that surround this one

Each is a separate subject with its own operator and its own identity. None is issued for you, and none is implied by holding this one.
  • ECZ-ID API Passport™

    Services expose APIs. Each API is identified separately from the workload that serves it.

  • ECZ-ID SDK Passport™

    Services are built from SDKs and libraries, each of which can carry its own publisher identity.

  • ECZ-ID Agent Passport™

    Agents increasingly run as workloads. The agent and the workload hosting it are two subjects, not one.