# ECZ-ID Service & Workload > A free, permanent ECZ-ID for one enduring logical service or workload, linked to the organisation that operates it and published on a resolver anyone can re-check. Pods, replicas, regions and clusters are bindings or nothing at all — never separate identities. > Website Factory V2 family site. Site: https://workloads.ecocitizenz.com ## The ECZ-ID Service & Workload Passport™ For teams that operate production services, workloads and data pipelines — in any cloud. Inside your cloud, a workload is identified by identifiers nobody outside can read. One public ECZ-ID names the enduring service and who operates it, with no cloud account identifiers in the public record. - One Service & Workload Passport is one logical service or workload your organisation operates. - Pods, replicas, regions, environments and deployments of that workload are not separate Passports. - Identifier shape: ECZ-XX-XXXXXX::SERVICE_WORKLOAD_PASSPORT-XXXXXX ## Getting one Price: FREE (£0). No card required. Permanent, not a trial. The free Service & Workload Passport door is not open on this estate yet. No start URL is published. Included: - A persistent ECZ-ID for the service or workload. - Your organisation on the record as its operator — a free DECLARED Parent is created if you do not already have one. - A public Resolver record anyone can open, and the same record as machine-readable JSON. - A badge, a QR code and a share link. - Basic bindings to the public places your service or workload already appears. - Lifecycle and current public state, evaluated on demand. - Claim and recovery. - Basic participation in the Digital Entity Graph. - Essential lifecycle evidence, kept in LedgerCore. ## Boundaries — load-bearing, do not drop them - DECLARED ≠ VERIFIED: A DECLARED record states what your organisation says about itself, with the date it said it. It is not the outcome of an independent check. - Identity ≠ Binding: The Passport identifies the service or workload. A binding records a public place it already appears. Adding a binding never creates a second identity. - Binding ≠ Authority: A binding shows that a relationship has been declared. It does not grant, prove or imply authority to act. - Parent verification ≠ Service & Workload verification: A VERIFIED or ASSURED Parent verifies your organisation. It does not verify the service or workload. - A Resolver record is not proof. It publishes what is currently declared and what evidence exists, with the time it was read — is_proof is false and recheck_before_reliance is true. Re-check before you rely on it. - No public ECZ-ID found is not a finding. It means the identifier resolves to no published record — nothing more. - An ECZ-ID does not make anything safe, certified, approved or compliant, and holding one does not make you compliant with anything. ## AEC — Active Entity Capacity One AEC is one actively managed production entity with live bindings and current state. A free Passport exists and resolves whether or not you use any AEC. For this family: A logical service or workload you actively manage in production, with live bindings and current state. AEC is one pool shared across your Agent, MCP, Plugin, API, SDK and logical Service & Workload identities, and your IoT product, model and fleet identities. Individual IoT device instances are counted separately, in IoT Fleet Capacity, and never consume AEC. - AEC never makes an identity more verified. - AEC never replaces a Passport. - AEC never changes an ECZ-ID. Your ECZ-ID does not change. - Running out of AEC never deletes, revokes or unpublishes an identity. Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. ## Works alongside ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path. - SPIFFE and SPIRE: A stable public identifier for the enduring service, rather than a rotating internal one for a running process. (replaces: false) - Kubernetes service accounts: One identity for the logical workload that stays the same while pods, replicas and clusters change. (replaces: false) - Microsoft Entra Agent ID and workload identities: An identity that resolves outside the tenant, for parties with no access to it. (replaces: false) - AWS IAM: A public identity a counterparty can read without any access to your accounts. (replaces: false) - Google Cloud IAM and workload identity federation: A public identity readable outside your projects, naming the organisation that operates the subject. (replaces: false) ## Optional capabilities (none is required to hold a Passport) - Parent VERIFIED and ASSURED: Independent verification of the organisation behind your Passports. VERIFIED suits production use; ASSURED is the higher-assurance posture for larger or more sensitive estates. Boundary: It verifies your organisation. It never verifies an agent, a server or any other child identity, and it never changes an ECZ-ID. Included free: Every Passport starts with a free DECLARED Parent — created for you if your organisation has none. - Workload Identity Federation: Links the ECZ-IDs of your logical services to the workload identities they already run under. Boundary: It never replaces or controls your cloud IAM, SPIFFE identities or service accounts. - PulseGuard: Current-state evaluation for the entities you operate. Paid tiers extend evaluation across more entities and more evaluations each month. Boundary: It reports state. It is not a safety verdict, and it never changes an identity or its tier. Included free: On-demand and event-driven evaluation of your own entities. - EvidenceCore (part of the ECZ-ID V2 build): The evidence behind each claim on a record: what supports it, where it came from, when it was checked and who may see it. Boundary: Evidence supports a claim. It does not make the claim true, and it never turns a declaration into a verification. Included free: Essential evidence references are part of every free Passport. - LedgerCore: Tamper-evident retention of decisive lifecycle evidence — issuance, activation, material bindings, authority changes, suspension and revocation — with eligible evidence anchored to a permissioned, append-only ledger. Boundary: An anchor shows an entry has not been altered since it was written. It does not make the statement inside it true. Included free: Essential LedgerCore evidence is kept for every identity, free ones included. - Digital Entity Graph and Graph Intelligence: The public-safe relationships between your organisation, its Passports and their bindings. Graph Pro, Graph Business and Enterprise Graph Intelligence add scale, history and custom analysis above the free view. Boundary: A relationship in the graph is a published link, not an endorsement of either end. Included free: Basic Graph participation and a current one-hop view. ## Related identities - ECZ-ID API Passport™: Services expose APIs. Each API is identified separately from the workload that serves it. - ECZ-ID SDK Passport™: Services are built from SDKs and libraries, each of which can carry its own publisher identity. - ECZ-ID Agent Passport™: Agents increasingly run as workloads. The agent and the workload hosting it are two subjects, not one. Free door (open): https://trustops.ecocitizenz.com/start/agent?source_surface=workloads-llms-related-agent ## Resolving a record Human record: https://resolver.ecocitizenz.org/p/{ecz_id} Machine record: https://api.ecocitizenz.com/api/p/{ecz_id}.json Public reads are free and need no account. ## This site's operator EcoCitizenz Ltd, company number 17348848, England and Wales ECZ-ID: ECZ-GB-RBS1NW Human: https://resolver.ecocitizenz.org/p/ECZ-GB-RBS1NW Machine: https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json The operator's record is proof about the company that runs this site, not about any visitor or any Passport they hold. ## Machine-readable surfaces on this host Family site description: https://workloads.ecocitizenz.com/products.json schema ecz.website_family_site.v2 — what the family is, the free Passport, acquisition state, AEC, optional capabilities and where to act on each. It carries no paid prices and establishes nothing about any ECZ-ID. Routes: https://workloads.ecocitizenz.com/sitemap.xml This file: https://workloads.ecocitizenz.com/llms.txt ## Pages - https://workloads.ecocitizenz.com: What an ECZ-ID Service & Workload Passport is, what the free identity includes, and the current availability of its door. - https://workloads.ecocitizenz.com/free-service-workload-passport: The free Service & Workload Passport in full: what it establishes, the operator relationship, the five-step flow, and the boundaries. - https://workloads.ecocitizenz.com/products: Every product a Service & Workload Passport holder can add, grouped by what it does, with each item's real purchase state read from the TrustOps commercial registry. - https://workloads.ecocitizenz.com/pricing: What everything costs in GBP excluding VAT, and the four rules that make the numbers mean what they say. The Passport itself is free. - https://workloads.ecocitizenz.com/passport-everywhere: Where an ECZ-ID travels: the share page and machine record we serve, the badge and QR, and the places you publish it yourself. Each marked as something we serve or a pattern you implement. - https://workloads.ecocitizenz.com/identity-over-time: What was true when you checked, what changed, and whether it is still the same logical entity — and what a free Passport does not include. - https://workloads.ecocitizenz.com/after-your-passport: The journey after issuance: publish the proof, bind native identities, inspect relationships, and open the console. - https://workloads.ecocitizenz.com/verify: Resolve an ECZ-ID, and how to read a public record without over-reading it. - https://workloads.ecocitizenz.com/aec: AEC — Active Entity Capacity: what counts as an actively managed entity, the one pool across families, and what AEC never changes. - https://workloads.ecocitizenz.com/interoperability: The protocols and identity systems an ECZ-ID sits beside, and what it explicitly does not replace. - https://workloads.ecocitizenz.com/parent: Parent DECLARED, VERIFIED and ASSURED — and why none of them verifies the subject of a child Passport. - https://workloads.ecocitizenz.com/workload-identity: How an ECZ-ID sits beside Entra, AWS IAM, Google Cloud IAM, SPIFFE, SPIRE, Kubernetes service accounts and OAuth. - https://workloads.ecocitizenz.com/federation: Linking the ECZ-ID of a logical service to the workload identities it already runs under, and what that never does. - https://workloads.ecocitizenz.com/enterprise: Estate, partner and procurement arrangements, agreed directly rather than bought online. - https://workloads.ecocitizenz.com/privacy: Exactly what this site collects and what it structurally cannot collect. - https://workloads.ecocitizenz.com/security: The response headers this origin sets, the build-time preflight, and where identity truth actually lives. ## Elsewhere in the estate Developer Gateway (technical integration reference): https://developers.ecocitizenz.com Resolver (public, read-only proof): https://resolver.ecocitizenz.org TrustOps (acquisition, payment, entitlement): https://trustops.ecocitizenz.com ## Not published here This host serves a website. It does not serve an agent endpoint, so it publishes no A2A Agent Card and no agent manifest describing itself as an agent. It publishes no family-specific protocol manifest either: none exists for the Service & Workload family in the ECZ-ID architecture, and inventing one for symmetry with another family would be a machine-readable claim that is simply untrue. There is no start URL for the Service & Workload Passport on this host, because the Service & Workload door is not open on this estate. A machine reading this file should record the family's acquisition state from /products.json and re-read it rather than assuming this file is current.