Skip to main content

EMA/ID-JAG Design & Pilot

Enterprise-managed authorization (EMA) and identity-assertion grant (ID-JAG) design for MCP — cross-app access, token exchange and identity boundaries, piloted against your identity provider.

Suitable for

  • Platform and security teams rolling MCP out inside an organisation with an existing identity provider (for example Okta, Microsoft Entra ID or Ping).
  • Teams that need per-user, per-agent authorization boundaries rather than shared static credentials.
  • Teams evaluating enterprise-managed authorization and identity-assertion grant patterns (ID-JAG) and needing a working, reviewable pilot rather than a slide deck.

Before we start

What you provide

Fixed-scope work needs defined inputs. This is everything the engagement requires from your side.

  • An architecture session with your identity and platform owners.
  • A test tenant or sandbox on your identity provider (customer-controlled credentials; we request the least privilege needed).
  • The pilot's target MCP server(s) and client(s), agreed at qualification.
  • Your security team's constraints and review requirements up front.

Scope

What is included — and what is not

Included

  • Identity-boundary architecture: where user identity, agent identity and service identity begin and end across your MCP deployment.
  • Authorization design: scopes, audiences, consent boundaries and token-exchange flows appropriate to your identity provider — including ID-JAG-style identity-assertion grants where they fit.
  • Written design review with your security team before implementation.
  • Pilot implementation of the agreed flows against your IdP sandbox and the agreed MCP server and client pair.
  • Testing of the pilot against the named clients and conditions agreed in scope.
  • Handover: documentation, walkthrough and a hardening roadmap.

Excluded

  • EcoCitizenz does not replace, resell or operate your identity provider.
  • Third-party platform fees (IdP licences, hosting, gateway products) are excluded unless explicitly stated in the written scope.
  • Organisation-wide rollout beyond the agreed pilot boundary.
  • Ongoing operation of the piloted infrastructure — handover is included; operations remain yours.

“EMA” refers to enterprise-managed authorization patterns for MCP deployments; “ID-JAG” refers to identity-assertion authorization grant flows for cross-application access. Both are design patterns applied to your existing identity infrastructure — this engagement never positions EcoCitizenz as an identity provider.

What you receive

Deliverables

  • Identity and authorization architecture document, reviewed with your security team.
  • Working pilot implementation of the agreed flows in your sandbox environment.
  • Test record for the agreed clients and conditions.
  • Hardening and rollout roadmap.
  • Production Evidence Pack (identity edition) — see contents below.

Production Evidence Pack — identity design & pilot edition

  • Architecture document with identity-boundary diagrams.
  • State and authorisation data-flow summary.
  • Authorization design rationale (scopes, audiences, token-exchange flows).
  • Pilot test record with conditions and results.
  • Negative authorisation test record: wrong issuer, wrong audience, expiry, replay and insufficient permission.
  • Requirements, findings and acceptance traceability matrix.
  • Residual-risk register, including dependencies on your identity provider.
  • Security-review notes and resolved actions.
  • Hardening and rollout roadmap.

Timetable

Expected timetable

  1. Architecture sessions begin after intake and scope validation.
  2. Design review typically within 10 working days of start.
  3. Pilot implementation timetable is confirmed in the written scope, because it depends on your IdP sandbox and review gates.

Acceptance

How success is accepted

  • The architecture document has been reviewed with your security team and revisions from that review incorporated.
  • The pilot demonstrates the agreed flows end-to-end in your sandbox against the agreed test conditions.
  • Handover documentation is delivered and walked through with your team.

After payment

What happens after you pay

  1. TrustOps confirms the order and opens the technical intake.
  2. Architecture sessions are scheduled with your identity and platform owners. Delivery start is confirmed after intake and scope validation.
  3. Final scope and price are confirmed in writing after the design phase — no further milestone is due before that written confirmation.
Start the identity pilot — £1,750

You'll review your order on TrustOps (trustops.ecocitizenz.com) before any payment step. Purchase starts your engagement and written intake; your delivery schedule is confirmed during intake.