EMA/ID-JAG Design & Pilot
Enterprise-managed authorization (EMA) and identity-assertion grant (ID-JAG) design for MCP — cross-app access, token exchange and identity boundaries, piloted against your identity provider.
Suitable for
- Platform and security teams rolling MCP out inside an organisation with an existing identity provider (for example Okta, Microsoft Entra ID or Ping).
- Teams that need per-user, per-agent authorization boundaries rather than shared static credentials.
- Teams evaluating enterprise-managed authorization and identity-assertion grant patterns (ID-JAG) and needing a working, reviewable pilot rather than a slide deck.
Before we start
What you provide
Fixed-scope work needs defined inputs. This is everything the engagement requires from your side.
- An architecture session with your identity and platform owners.
- A test tenant or sandbox on your identity provider (customer-controlled credentials; we request the least privilege needed).
- The pilot's target MCP server(s) and client(s), agreed at qualification.
- Your security team's constraints and review requirements up front.
Scope
What is included — and what is not
Included
- Identity-boundary architecture: where user identity, agent identity and service identity begin and end across your MCP deployment.
- Authorization design: scopes, audiences, consent boundaries and token-exchange flows appropriate to your identity provider — including ID-JAG-style identity-assertion grants where they fit.
- Written design review with your security team before implementation.
- Pilot implementation of the agreed flows against your IdP sandbox and the agreed MCP server and client pair.
- Testing of the pilot against the named clients and conditions agreed in scope.
- Handover: documentation, walkthrough and a hardening roadmap.
Excluded
- EcoCitizenz does not replace, resell or operate your identity provider.
- Third-party platform fees (IdP licences, hosting, gateway products) are excluded unless explicitly stated in the written scope.
- Organisation-wide rollout beyond the agreed pilot boundary.
- Ongoing operation of the piloted infrastructure — handover is included; operations remain yours.
“EMA” refers to enterprise-managed authorization patterns for MCP deployments; “ID-JAG” refers to identity-assertion authorization grant flows for cross-application access. Both are design patterns applied to your existing identity infrastructure — this engagement never positions EcoCitizenz as an identity provider.
What you receive
Deliverables
- Identity and authorization architecture document, reviewed with your security team.
- Working pilot implementation of the agreed flows in your sandbox environment.
- Test record for the agreed clients and conditions.
- Hardening and rollout roadmap.
- Production Evidence Pack (identity edition) — see contents below.
Production Evidence Pack — identity design & pilot edition
- Architecture document with identity-boundary diagrams.
- State and authorisation data-flow summary.
- Authorization design rationale (scopes, audiences, token-exchange flows).
- Pilot test record with conditions and results.
- Negative authorisation test record: wrong issuer, wrong audience, expiry, replay and insufficient permission.
- Requirements, findings and acceptance traceability matrix.
- Residual-risk register, including dependencies on your identity provider.
- Security-review notes and resolved actions.
- Hardening and rollout roadmap.
Timetable
Expected timetable
- Architecture sessions begin after intake and scope validation.
- Design review typically within 10 working days of start.
- Pilot implementation timetable is confirmed in the written scope, because it depends on your IdP sandbox and review gates.
Acceptance
How success is accepted
- The architecture document has been reviewed with your security team and revisions from that review incorporated.
- The pilot demonstrates the agreed flows end-to-end in your sandbox against the agreed test conditions.
- Handover documentation is delivered and walked through with your team.
After payment
What happens after you pay
- TrustOps confirms the order and opens the technical intake.
- Architecture sessions are scheduled with your identity and platform owners. Delivery start is confirmed after intake and scope validation.
- Final scope and price are confirmed in writing after the design phase — no further milestone is due before that written confirmation.
You'll review your order on TrustOps (trustops.ecocitizenz.com) before any payment step. Purchase starts your engagement and written intake; your delivery schedule is confirmed during intake.