{
  "schema": "ecz.website_family_site.v2",
  "site": {
    "name": "ECZ-ID Service & Workload",
    "url": "https://workloads.ecocitizenz.com",
    "brand_contract": "ecz.website_brand_contract.v1",
    "operator": {
      "legal_name": "EcoCitizenz Ltd",
      "ecz_id": "ECZ-GB-RBS1NW",
      "resolver": "https://resolver.ecocitizenz.org/p/ECZ-GB-RBS1NW",
      "resolver_machine": "https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json",
      "statement": "The operator's own record is proof about the company that runs this site, not about any visitor or any Passport they hold."
    }
  },
  "family": {
    "slug": "service-workload",
    "type_code": "SERVICE_WORKLOAD_PASSPORT",
    "family_code": "SVC",
    "product_name": "ECZ-ID Service & Workload Passport™",
    "subject": "service or workload",
    "identifier_pattern": "ECZ-XX-XXXXXX::SERVICE_WORKLOAD_PASSPORT-XXXXXX",
    "subject_law": "One Service & Workload Passport is one logical service or workload your organisation operates.",
    "not_separate_passports": "Pods, replicas, regions, environments and deployments of that workload are not separate Passports."
  },
  "free_passport": {
    "price_gbp": 0,
    "price_label": "FREE",
    "includes": [
      "A persistent ECZ-ID for the service or workload.",
      "Your organisation on the record as its operator — a free DECLARED Parent is created if you do not already have one.",
      "A public Resolver record anyone can open, and the same record as machine-readable JSON.",
      "A badge, a QR code and a share link.",
      "Basic bindings to the public places your service or workload already appears.",
      "Lifecycle and current public state, evaluated on demand.",
      "Claim and recovery.",
      "Basic participation in the Digital Entity Graph.",
      "Essential lifecycle evidence, kept in LedgerCore."
    ],
    "distinctions": [
      {
        "title": "DECLARED ≠ VERIFIED",
        "body": "A DECLARED record states what your organisation says about itself, with the date it said it. It is not the outcome of an independent check."
      },
      {
        "title": "Identity ≠ Binding",
        "body": "The Passport identifies the service or workload. A binding records a public place it already appears. Adding a binding never creates a second identity."
      },
      {
        "title": "Binding ≠ Authority",
        "body": "A binding shows that a relationship has been declared. It does not grant, prove or imply authority to act."
      },
      {
        "title": "Parent verification ≠ Service & Workload verification",
        "body": "A VERIFIED or ASSURED Parent verifies your organisation. It does not verify the service or workload."
      }
    ],
    "publication_consent_required": true
  },
  "acquisition": {
    "state": "NOT_YET_LIVE",
    "states": [
      "AVAILABLE",
      "TEMPORARILY_PAUSED",
      "NOT_YET_LIVE"
    ],
    "start_url": null,
    "authority": "https://trustops.ecocitizenz.com",
    "configuration": "Set by Operating Command through ECZ_FAMILY_ACQUISITION_STATE. FREE is the price; the state is whether new activations are open."
  },
  "aec": {
    "name": "AEC — Active Entity Capacity",
    "definition": "One AEC is one actively managed production entity with live bindings and current state.",
    "exists_without_aec": "A free Passport exists and resolves whether or not you use any AEC.",
    "counts_for_this_family": "A logical service or workload you actively manage in production, with live bindings and current state.",
    "pooled_across": "AEC is one pool shared across your Agent, MCP, Plugin, API, SDK and logical Service & Workload identities, and your IoT product, model and fleet identities.",
    "device_instances": "Individual IoT device instances are counted separately, in IoT Fleet Capacity, and never consume AEC.",
    "never": [
      "AEC never makes an identity more verified.",
      "AEC never replaces a Passport.",
      "AEC never changes an ECZ-ID. Your ECZ-ID does not change.",
      "Running out of AEC never deletes, revokes or unpublishes an identity."
    ]
  },
  "commercial": {
    "authority": "TrustOps",
    "trustops_origin": "https://trustops.ecocitizenz.com",
    "configure_url": "https://trustops.ecocitizenz.com/start",
    "prices_published_here": false,
    "statement": "Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal."
  },
  "interoperability": {
    "families": [
      "API_PASSPORT",
      "SDK_PASSPORT",
      "AGENT_PASSPORT"
    ],
    "systems": [
      {
        "name": "SPIFFE and SPIRE",
        "what_it_does": "Issue short-lived workload identities inside your infrastructure.",
        "what_ecz_id_adds": "A stable public identifier for the enduring service, rather than a rotating internal one for a running process.",
        "replaces": false
      },
      {
        "name": "Kubernetes service accounts",
        "what_it_does": "Identify pods to the cluster and to other workloads in it.",
        "what_ecz_id_adds": "One identity for the logical workload that stays the same while pods, replicas and clusters change.",
        "replaces": false
      },
      {
        "name": "Microsoft Entra Agent ID and workload identities",
        "what_it_does": "Govern what an agent or workload may do inside your Microsoft tenant.",
        "what_ecz_id_adds": "An identity that resolves outside the tenant, for parties with no access to it.",
        "replaces": false
      },
      {
        "name": "AWS IAM",
        "what_it_does": "Governs what a role or workload may call inside your AWS accounts.",
        "what_ecz_id_adds": "A public identity a counterparty can read without any access to your accounts.",
        "replaces": false
      },
      {
        "name": "Google Cloud IAM and workload identity federation",
        "what_it_does": "Govern access to your Google Cloud projects.",
        "what_ecz_id_adds": "A public identity readable outside your projects, naming the organisation that operates the subject.",
        "replaces": false
      }
    ],
    "boundary": "ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path."
  },
  "strengthen": [
    {
      "key": "parent-assurance",
      "name": "Parent VERIFIED and ASSURED",
      "prominence": "PRIMARY",
      "phase": "CATALOGUE",
      "adds": "Independent verification of the organisation behind your Passports. VERIFIED suits production use; ASSURED is the higher-assurance posture for larger or more sensitive estates.",
      "boundary": "It verifies your organisation. It never verifies an agent, a server or any other child identity, and it never changes an ECZ-ID.",
      "included_free": "Every Passport starts with a free DECLARED Parent — created for you if your organisation has none.",
      "next_steps": [
        {
          "kind": "EXPLORE",
          "label": "Explore Parent VERIFIED and ASSURED",
          "url": "https://workloads.ecocitizenz.com/parent"
        },
        {
          "kind": "TRUSTOPS",
          "label": "Configure in TrustOps",
          "url": "https://trustops.ecocitizenz.com/start#parent-passports"
        }
      ]
    },
    {
      "key": "workload-federation",
      "name": "Workload Identity Federation",
      "prominence": "PRIMARY",
      "phase": "CATALOGUE",
      "adds": "Links the ECZ-IDs of your logical services to the workload identities they already run under.",
      "boundary": "It never replaces or controls your cloud IAM, SPIFFE identities or service accounts.",
      "included_free": null,
      "next_steps": [
        {
          "kind": "CONTACT",
          "label": "Talk to us",
          "url": "mailto:hello@ecocitizenz.com?subject=Workload%20Identity%20Federation%20%E2%80%94%20ECZ-ID%20Service%20%26%20Workload%20Passport%E2%84%A2"
        }
      ]
    },
    {
      "key": "pulseguard",
      "name": "PulseGuard",
      "prominence": "SECONDARY",
      "phase": "CATALOGUE",
      "adds": "Current-state evaluation for the entities you operate. Paid tiers extend evaluation across more entities and more evaluations each month.",
      "boundary": "It reports state. It is not a safety verdict, and it never changes an identity or its tier.",
      "included_free": "On-demand and event-driven evaluation of your own entities.",
      "next_steps": [
        {
          "kind": "CONTACT",
          "label": "Talk to us",
          "url": "mailto:hello@ecocitizenz.com?subject=PulseGuard%20%E2%80%94%20ECZ-ID%20Service%20%26%20Workload%20Passport%E2%84%A2"
        }
      ]
    },
    {
      "key": "evidencecore",
      "name": "EvidenceCore",
      "prominence": "SECONDARY",
      "phase": "IN_V2_BUILD",
      "adds": "The evidence behind each claim on a record: what supports it, where it came from, when it was checked and who may see it.",
      "boundary": "Evidence supports a claim. It does not make the claim true, and it never turns a declaration into a verification.",
      "included_free": "Essential evidence references are part of every free Passport.",
      "next_steps": []
    },
    {
      "key": "ledgercore",
      "name": "LedgerCore",
      "prominence": "SECONDARY",
      "phase": "CATALOGUE",
      "adds": "Tamper-evident retention of decisive lifecycle evidence — issuance, activation, material bindings, authority changes, suspension and revocation — with eligible evidence anchored to a permissioned, append-only ledger.",
      "boundary": "An anchor shows an entry has not been altered since it was written. It does not make the statement inside it true.",
      "included_free": "Essential LedgerCore evidence is kept for every identity, free ones included.",
      "next_steps": [
        {
          "kind": "CONTACT",
          "label": "Talk to us",
          "url": "mailto:hello@ecocitizenz.com?subject=LedgerCore%20%E2%80%94%20ECZ-ID%20Service%20%26%20Workload%20Passport%E2%84%A2"
        }
      ]
    },
    {
      "key": "graph",
      "name": "Digital Entity Graph and Graph Intelligence",
      "prominence": "SECONDARY",
      "phase": "CATALOGUE",
      "adds": "The public-safe relationships between your organisation, its Passports and their bindings. Graph Pro, Graph Business and Enterprise Graph Intelligence add scale, history and custom analysis above the free view.",
      "boundary": "A relationship in the graph is a published link, not an endorsement of either end.",
      "included_free": "Basic Graph participation and a current one-hop view.",
      "next_steps": [
        {
          "kind": "PRIVATE_OFFER",
          "label": "Discuss a private offer",
          "url": "mailto:hello@ecocitizenz.com?subject=Digital%20Entity%20Graph%20and%20Graph%20Intelligence%20%E2%80%94%20ECZ-ID%20Service%20%26%20Workload%20Passport%E2%84%A2"
        }
      ]
    }
  ],
  "operate": [
    {
      "key": "developer-gateway",
      "name": "Developer Gateway",
      "summary": "Integration reference, schemas and machine-readable documentation for ECZ-ID.",
      "url": "https://developers.ecocitizenz.com"
    },
    {
      "key": "resolver",
      "name": "Resolver",
      "summary": "Resolve any ECZ-ID to its public record — free, with no account and no API key.",
      "url": "https://workloads.ecocitizenz.com/verify"
    },
    {
      "key": "machine-json",
      "name": "Machine-readable record",
      "summary": "Every record as JSON at /api/p/{ecz_id}.json, for policy engines, gateways and agents. Shown here on EcoCitizenz's own record.",
      "url": "https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json"
    },
    {
      "key": "console",
      "name": "ECZ-ID console",
      "summary": "Sign in to TrustOps to reach the Passports your organisation holds. It is where current commercial configuration lives, too.",
      "url": "https://trustops.ecocitizenz.com/console"
    }
  ],
  "related": [
    {
      "type_code": "API_PASSPORT",
      "product_name": "ECZ-ID API Passport™",
      "relationship": "Services expose APIs. Each API is identified separately from the workload that serves it.",
      "acquisition_state": "NOT_YET_LIVE",
      "start_url": null,
      "site": null
    },
    {
      "type_code": "SDK_PASSPORT",
      "product_name": "ECZ-ID SDK Passport™",
      "relationship": "Services are built from SDKs and libraries, each of which can carry its own publisher identity.",
      "acquisition_state": "NOT_YET_LIVE",
      "start_url": null,
      "site": null
    },
    {
      "type_code": "AGENT_PASSPORT",
      "product_name": "ECZ-ID Agent Passport™",
      "relationship": "Agents increasingly run as workloads. The agent and the workload hosting it are two subjects, not one.",
      "acquisition_state": "AVAILABLE",
      "start_url": "https://trustops.ecocitizenz.com/start/agent?source_surface=workloads-machine-related-agent",
      "site": "https://agents.ecocitizenz.com"
    }
  ],
  "resolver": {
    "human": "https://resolver.ecocitizenz.org/p/{ecz_id}",
    "machine": "https://api.ecocitizenz.com/api/p/{ecz_id}.json",
    "is_proof": false,
    "recheck_before_reliance": true,
    "statement": "A Resolver record is not proof. It publishes what is currently declared and what evidence exists, with the time it was read — is_proof is false and recheck_before_reliance is true. Re-check before you rely on it.",
    "absence": "No public ECZ-ID found is not a finding. It means the identifier resolves to no published record — nothing more."
  },
  "boundaries": [
    "An ECZ-ID does not make anything safe, certified, approved or compliant, and holding one does not make you compliant with anything.",
    "ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path."
  ],
  "not_published_here": [
    "No A2A Agent Card and no agent manifest: this host is a website, not an agent endpoint.",
    "No prices, allowances, SKUs or purchase states: TrustOps is the commercial authority."
  ]
}
