Integrations
Microsoft and AWS reference profiles, open standards, and the adapter contract every connector has to satisfy.
Cloud services implement the boundary. They do not define the semantics.
No product is mandatory. Deployment profiles select the services a customer boundary permits, and compatibility tests verify that each implementation preserves passport status, revocation, policy and evidence semantics.
Compute Passport owns CPID semantics, passport schemas, status, policy obligations, verification profiles and evidence references. Everything else is an implementation primitive.
| Component | Microsoft reference | AWS reference | Open / portable |
|---|---|---|---|
| Identity fabric | Entra Agent ID; Entra Workload ID; Managed Identities; Microsoft Graph | Bedrock AgentCore Identity; IAM; IAM Identity Center; IAM Roles Anywhere | SPIFFE/SPIRE; OIDC; OAuth 2.0; SCIM |
| Credential exchange | Entra tokens; workload identity federation; Azure Identity SDK | AWS STS; X.509 with IAM Roles Anywhere; EKS Pod Identity | JWT SVID; X.509 SVID; token exchange |
| Policy engine | Azure RBAC; Conditional Access; API Management policy; Azure Policy | IAM policies; Verified Permissions/Cedar; AgentCore Gateway policy | OPA/Rego; Cedar; ABAC/ReBAC profiles |
| Trust and keys | Key Vault; Managed HSM; key attestation; Azure Attestation | AWS KMS; CloudHSM; Nitro Enclaves attestation | JWS/JWE; COSE; W3C VC 2.0; X.509 |
| Runtime guardrails | API Management; Foundry Agent Service; AKS admission and sidecar | AgentCore Gateway/Runtime; API Gateway; EKS admission and sidecar | MCP/A2A gateways; Envoy; service mesh |
| Evidence | Azure Monitor; Log Analytics; Sentinel; Event Hubs; Purview | CloudTrail; CloudWatch; EventBridge; Security Lake; Audit Manager | OpenTelemetry; CloudEvents; signed evidence bundles |
Inbound
Assertions and events carry source, tenant, subject, time, confidence, sensitivity and integrity metadata.
Decision
Compute Passport returns permit, restrict or deny with approval, logging, isolation, expiry and status obligations.
Evidence
Every adapter records source references, transformation version, delivery status and reconciliation results.
Each connector must also define its authoritative source, object mapping, event semantics, latency, error handling, replay behaviour, tenant isolation and evidence retention before it is approved for a deployment profile.
One control model across cloud, sovereign and controlled environments.
Enterprise SaaS
Regional multi-tenant control plane, customer connectors, encrypted evidence, customer-managed key option.
Sovereign cloud
Approved region, customer evidence store, restricted administration and supplier boundaries.
Hybrid secure edge
Central registry with customer-hosted policy decision, enforcement, revocation cache and evidence broker.
Controlled on-premises
Customer-hosted registry, policy, evidence and keys for segmented or restricted environments.