Skip to main content

Platform

One product. Two responsibilities across the identity estate.

The Application Identity Runtime gives governed applications a stable identity boundary. The Enterprise Identity Control Plane gives teams a shared view of the estate and a controlled way to change it.

One product, two responsibilities

Applications get one identity boundary. The enterprise gets one view of the estate.

01 / Application Identity Runtime

The identity boundary your applications use.

Applications connect to Authonomy using OpenID Connect or SAML. Older web applications use a protected path that supplies identity in the form the application expects.

The application points to Authonomy. Authonomy connects that application contract to an approved identity provider, and the provider continues to run its own authentication journey.

When the provider behind an application changes, the application contract remains stable.

02 / Enterprise Identity Control Plane

The model, intent, and evidence for the whole estate.

Authonomy records the applications, identity systems, and relationships that make up the estate. It also records where authority sits for each part.

Teams decide the outcome they want and approve the change. Within the agreed scope, Authonomy carries it out through each connected system’s own administrative interface, then checks the resulting state against the approved intent.

For example, when an identity policy changes, Authonomy shows which applications and providers are affected, applies the approved updates through their existing interfaces, and checks that the resulting configuration matches the decision.

This creates a common operational view across providers while respecting the systems that already hold identity, access decisions, and application permissions.

Authority boundaries

Each system keeps the decisions it is responsible for.

Identity providers and directories
Hold identity records and run authentication journeys.
IGA systems
Make access governance and entitlement decisions.
Applications and authorization services
Control application sessions, roles, and business permissions.
Authonomy
Holds the application identity contract and the cross-provider model, intent, and evidence for the estate.

Start with one part of the estate.

We can begin with a specific application, a provider change, or a governance problem that already has an owner.

Talk to us