Platform

One decision, before the action executes.

GrayPass forms current assurance from the evidence your stack already has, applies your policy for one registered action, and returns a decision with proof bound to that action.

Five layers, one decision.

  1. What enters. Identity, session, and transaction context enter as separate sources. Brainprint continuity is one of them.
  2. What GrayPass can say. Each claim gets its own status. Coverage, freshness, and limitations travel with it instead of a single score.
  3. Your rule for this action. A versioned policy states what this registered action requires and how missing evidence is handled.
  4. What your application enforces. GrayPass returns allow, verify again, hold, or deny, with reason codes your team can read.
  5. Bound to the action. An allowed action in enforce mode receives a short-lived signed proof bound to the action and its audience.

Five layers, one decision.

Evidence

  • Identity provider
  • Passkey or MFA
  • Device and session context
  • Transaction context
  • Brainprint continuity

What enters

Identity, session, and transaction context enter as separate sources. Brainprint continuity is one of them.

Turn a source off. Watch the decision change.

Assurance is only as strong as the evidence present. This runs the documented default policy for a high-risk action in your browser.

A challenge can repair missing evidence. It never overrides evidence that contradicts the expected person.

payout.destination.change

risk: high

Coverage
sufficient
Operator continuity
likely
Human presence
likely
Allow

The evidence meets policy. The action may execute.

  • decision.policy_satisfied

Where Brainprint sits.

Brainprint contributes one claim, operator continuity, alongside the evidence your stack already produces. It is derived from timing, never from content.

Watch your own trace form
  • Identity provider
  • Passkey or MFA
  • Device and session context
  • Transaction context
  • Brainprint continuity

GrayPass

Typed assurance. Your policy. One exact action.

The same primitive can govern agents.

Actor and mandate fields are reserved in the contract so an agent's proposed action can be checked against a bounded human mandate. Agent authorization is not available yet.