Works alongside
What an ECZ-ID Service & Workload Passport sits beside
A Service & Workload Passport complements cloud and workload identity. SPIFFE, IAM and service accounts govern access inside your infrastructure; the Passport is readable outside it.
Adjacent systems
What each already does, and what the Passport adds
ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path.
SPIFFE and SPIRE
- What it does
- Issue short-lived workload identities inside your infrastructure.
- What an ECZ-ID adds
- A stable public identifier for the enduring service, rather than a rotating internal one for a running process.
Kubernetes service accounts
- What it does
- Identify pods to the cluster and to other workloads in it.
- What an ECZ-ID adds
- One identity for the logical workload that stays the same while pods, replicas and clusters change.
Microsoft Entra Agent ID and workload identities
- What it does
- Govern what an agent or workload may do inside your Microsoft tenant.
- What an ECZ-ID adds
- An identity that resolves outside the tenant, for parties with no access to it.
AWS IAM
- What it does
- Governs what a role or workload may call inside your AWS accounts.
- What an ECZ-ID adds
- A public identity a counterparty can read without any access to your accounts.
Google Cloud IAM and workload identity federation
- What it does
- Govern access to your Google Cloud projects.
- What an ECZ-ID adds
- A public identity readable outside your projects, naming the organisation that operates the subject.
Adjacent identities
The Passports that surround this one
Each is a separate subject with its own operator and its own identity. None is issued for you, and none is implied by holding this one.
ECZ-ID API Passport™
Services expose APIs. Each API is identified separately from the workload that serves it.
ECZ-ID SDK Passport™
Services are built from SDKs and libraries, each of which can carry its own publisher identity.
ECZ-ID Agent Passport™
Agents increasingly run as workloads. The agent and the workload hosting it are two subjects, not one.
