GATEWAY
Identity & Compliance · Design record

Governed identity and access

Treat people, applications, organisations, and agents as governed principals with explicit, revocable permissions.

Representative workflowGoverned identity and access
01Identity provider
02Institution
03User or operator
04Application or agent
Target business outcome

A shared identity and policy layer that translates enterprise roles into transaction and data access decisions.

Gateway implementation layer

Translate the workflow into a deployable operating boundary.

The record defines the financial problem. Gateway then maps the relevant Platform capabilities, privacy fit, deployment, specialist dependencies, and validation path.

01 · Platform

Gateway capabilities

  • Permissioning
  • Policy decisions
  • Access evidence
02 · Privacy

Open Privacy Suite applicability

Core fit: permissions, selective disclosure, and audit are native Open Privacy Suite concerns.

03 · Boundary

Deployment

Integrated with institutional IAM and approved identity sources.

04 · Ecosystem

Partner dependencies

  • Identity provider
  • Policy owner
  • Assurance
Implementation path01 · Map the flow02 · Validate the hardest assumption03 · Define the production boundary

Actors

  • Identity provider
  • Institution
  • User or operator
  • Application or agent
  • Compliance function
  • Auditor

Confidential data

  • Personally identifiable information
  • Credentials and risk attributes
  • Role and entitlement data
  • Access history
  • Agent instructions

Public or shared evidence

  • Credential validity or attribute proof
  • Policy version
  • Allow or deny receipt
  • Tamper-evident access log

Regulator and auditor access

Compliance and audit roles can inspect identity, policy, and decision evidence according to purpose; applications receive the minimum attributes needed.

Institutional constraints

  • Identity provider availability and revocation matter
  • Role mapping differs across systems
  • Break-glass access must be controlled
  • Raw infrastructure paths must not bypass policy

Viable approaches

01

Enterprise identity federation

Map existing SSO, tenant, and role controls onto platform permissions.

02

Verifiable credentials

Use signed attributes for portable eligibility and selective disclosure.

03

Agent principal model

Give automated agents separate identity, scope, spend, and approval limits.

Questions to resolve during discovery

  • Which identity source is authoritative?
  • What happens when credentials are revoked or unavailable?
  • Which permissions require four-eyes approval?
  • How are agents separated from sponsoring users?

Relevant standards and frameworks

  • OIDC and SAML
  • DID and Verifiable Credentials
  • NIST Zero Trust Architecture
  • Enterprise IAM policy
Start with the architecture

Turn governed identity and access into an institution-specific architecture.

A workshop maps the actors, authoritative records, disclosure requirements, operating boundary, and highest-risk assumptions into a proposed architecture.