The agent, and the federation that vouches for it Live · the same agent, two federation interactions

This is the same accounts payable agent you see in the console, shown here through the federation lens. Run the real payment run to watch the actual delegated authority flow (the one the console runs) as a chain of federation interactions: attestation, delegation, per hop token exchange that only narrows, and role enforced resource calls. Or run a cross estate exchange to watch an internal operations agent authenticate on the workforce platform and exchange that token at business banking, which resolves the workforce platform through the federation at the moment of the request. Business banking holds no record of it and shares no secret with it, and the exchanged token is narrower than the one presented, so crossing the boundary attenuates authority rather than widening it. Both authorisation servers are reference implementations standing in for Entra and Ping.

The real supplier payment run, federation interactions, live

This is the exact flow the console runs, and every step is a real federation interaction. Press Run the real payment run.
    and a cross estate federation exchange

    Who am I, and who vouches for me

    entity: https://agent-workforce-ops.demo.cba.raidiam.io
    identity plane: Workforce OP (reference implementation, stands in for Entra)
    resolving who vouches for my OP…

    The flow, live

    • attest the instance key (HAIP)
    • mint the subject token at the workforce platform
    • exchange at business banking (federation resolved)
    • read the supplier invoice register

    The trust decision, resolved live rather than hardcoded

    runs when you press play

    Tokens, subject vs exchanged

    subject (workforce platform):
    exchanged (business banking, narrowed):

    Resource result