CCPE — Combined Credential- and Platform-bound Enforcement
A family of integration profiles that specify how Gimel Auth combines credential-bound delegation with the platform-bound enforcement engines you already run — backed by Gimel Technologies' proprietary services.
Why two layers of enforcement
Modern AI governance has converged on a powerful pattern: pre-execution hooks that intercept agent actions and check them against platform-configured policies. Microsoft AGT, OWASP-listed governance vendors, Policy-as-Code engines (OPA, Cedar, SpiceDB), inter-agent protocols (MCP, A2A), and identity-bound IAM platforms (Entra Agent ID, Okta, Ping) all implement variants of this pattern.
These tools enforce platform rules: "Is this action permitted by the policies configured for this platform?" Gimel Auth enforces a structurally different question — delegated authority: "Is this action within the specific authority granted to this specific agent by its principal, through this delegation chain, with these constraints?"
Neither layer alone is sufficient for AI systems that must satisfy both cybersecurity controls and the authority-and-accountability requirements of the EU AI Act, NIS2, and DORA. Gimel Technologies delivers both layers under a single managed control plane, with Gimel Auth's Power-PEP as the authoritative authority layer.
How Gimel Auth integrates
Gimel Auth — Gimel Technologies' commercial implementation — preserves the 16-check Power-PEP pipeline as Phase 1 (credential-bound enforcement) and chains a Phase 2 evaluator from your existing platform stack. Gimel Technologies' proprietary value-add — managed control plane, AI-enabled governance, post-quantum cryptography, and DNA-based identity — integrates into every profile.
Phase 1 — Power-PEP
Gimel Auth's credential-bound 16-check pipeline operates on a Power-of-Attorney credential: scope, constraints, delegation depth, budget, revocation.
Phase 2 — Platform Layer
Your governance toolkit, policy store, message bus, or IAM platform evaluates platform-configured policy. The CCPE profile specifies the chain contract.
Unified Audit
A single per-action audit record carries Phase 1 mandate evidence and Phase 2 platform decision — the evidentiary record EU AI Act Art. 12–15 requires.
The CCPE Profiles
Each profile is an open integration specification. Pick the one that matches the platform layer you already operate; Gimel Technologies provides the connectors, managed deployment, and proprietary value-add.
Enterprise Agent Governance Toolkits
Integrates with: Microsoft AGT and OWASP-listed governance vendors
Combines Gimel Auth's credential-bound enforcement with operational governance toolkits that intercept agent actions through pre-execution hooks. Gimel Auth remains the authoritative governance control plane; the toolkit acts either as an access-control vehicle inside the Power-PEP or runs standalone and calls into Gimel Auth for credential-bound delegation decisions.
Policy-as-Code Engines
Integrates with: OPA / Rego, Cedar (AWS), SpiceDB / Zanzibar
Specifies the Power-PEP → Policy-PDP chain: Gimel Auth's credential-bound Phase 1 enforcement invokes a downstream Policy-as-Code engine as the platform-bound Phase 2 evaluator. Covers PEP placement, decision-shape normalization, and trust-state contracts for engines without native trust scoring.
Inter-Agent Communication Substrates
Integrates with: MCP, A2A, ACP, AGNTCY / DefenseClaw
Defines the runtime enforcement layer for multi-agent systems: every message crossing an agent-to-agent edge carries, proves, scopes, and audits the authority envelope under which the sender operates. Specifies authority composition across delegation chains and unified provenance for post-hoc reconstruction.
Coding-Agent Hooks
Integrates with: Claude Code, Cursor, GitHub Copilot, Windsurf, Cline
Integrates Gimel Auth with autonomous coding-agent stacks. Every tool call — file write, shell command, git operation, network request — initiated by a coding agent passes through Gimel Auth's credential-bound 16-check pipeline before execution.
AI-Embedded IoT Substrates
Integrates with: OPC UA, MQTT v5, CoAP / OSCORE, LwM2M; Siemens, Bosch, Rockwell, Honeywell, PTC
Integrates Gimel Auth with AI-embedded IoT (AIoT) devices, edge nodes, and device fleets that run local inference or join federated-learning cycles. Every device action — sensor publish, actuator command, on-device inference, model-version activation, OTA firmware acceptance — is enforced under a signed Power-of-Attorney mandate, with a constrained-audit profile that survives offline windows and reconciles on reconnection.
Agent Commerce Platforms
Integrates with: Universal Commerce Protocol (UCP), Stripe, Shopify, Amazon Pay, Open Banking / PSD2, W3C Payment Request API
Lets an autonomous agent transact with a vendor on a principal's behalf under a signed delegation credential while the vendor's own platform checks still apply. Defines a three-phase mandate → cart → payment decision surface, chains the credential-bound Power-PEP with a platform-bound Commerce-PDP under more-restrictive-wins, and cascades revocation to cancel in-flight payment artifacts.
Identity-Bound IAM Platforms
Integrates with: Microsoft Entra Agent ID, Okta, Auth0, Ping, ForgeRock, SPIFFE / SPIRE, CyberArk
Integrates Gimel Auth with IAM platforms that issue agents as first-class identity objects ("identity = mandate"). Defines the bridge contract by which identity attributes plus a recorded principal-delegation event are translated into a synthetic mandate envelope that satisfies the 16-check Power-PEP — closing the gap between identity-based authentication and the per-action evidence the EU AI Act requires.
Data-Governance Platforms
Integrates with: Collibra, Atlan, Informatica, Microsoft Purview, Immuta, Databricks Unity Catalog, Snowflake Horizon, AWS Lake Formation
Lets an agent read, derive from, transform, and emit data assets on a principal's behalf under a signed data-mandate, while the data platform's own access governance still applies. Adds a purpose-bound decision surface — purpose → dataset-scope → operation — chains the Power-PEP with a platform-bound Data-PDP under more-restrictive-wins, and attests lineage on every permitted action.
Supporting Evaluation Framework
A neutral nine-criterion framework for evaluating AI governance tooling — covering enforcement binding, policy location, granularity, multi-tenant model, multi-hop delegation, human oversight, interoperability, threat detection, and regulatory alignment. Gimel Technologies uses this framework to position Gimel Auth's credential-bound enforcement alongside platform-bound runtime governance.