Confidential, This document is provided for evaluation purposes only and remains the property of AffirmedID.
Executive Brief

Pulse Continuous Authentication & Identity Assurance

Securing Every Moment of Every Session, For Users and AI Agents Alike


The Problem with Today's Security

Every organization that provides access to digital services faces the same hidden vulnerability: authentication happens once, at the point of login, and then stops. From that moment on, whether the session lasts 10 minutes or 10 hours, the system has no reliable way of knowing whether the person who logged in is still the person in control.

This gap is where modern attacks occur. Authorization token handed off to bad actor following successful MFA. Stolen credentials used mid-session. Devices handed to an unauthorized person. Employees moving to unexpected locations. Compromised phones continue to hold active access tokens. Traditional security tools have no answer to any of these scenarios once the login ceremony is complete.

As AI-powered automation becomes central to enterprise operations, the stakes increase further. AI agents frequently run for hours without direct human interaction, making decisions and accessing sensitive data on the user's behalf. Worse yet, the agentic AI tasks it spins off with equal access to perform tasks absent accountability or awareness. A compromised session that feeds an autonomous agent can cause far greater harm than a compromised human session alone.

These aren't hypothetical risks. The 2024 discovery of 17 billion stolen session cookies exposed session hijacking as an attack class in its own right, by 2025 it was behind 87% of successful attacks that followed a valid MFA login. And in November 2025, exploitation of Gainsight's OAuth integrations compromised 200+ Salesforce customer environments, not because anyone's login was compromised, but because nothing was watching what happened after it.

The Pulse Proposition

Pulse is a Continuous Authentication & Identity Assurance (CA) framework developed by AffirmedID. Unlike conventional security products assembled from separate tools bolted together, Pulse was designed from the ground up as a single, integrated system. It closes the post-login security gap entirely, providing real-time, ongoing verification that the right person stays in control, from login to logout.

The framework comprises four tightly integrated components, each serving a distinct role:

Pulse API
Orchestration Hub
Anchors and orchestrates every component across the full session lifecycle
Auth App
Authentication & Continuous Monitoring
Streams live trust signals from the user's phone to Pulse API throughout every session
Connect
Session & Policy Enforcement
Enforces policy via OIDC and optional SAML protocols, no custom development required
Sentinel
Access Device Orchestration
Extends session security to access devices and AI agents acting on users' behalf
Commander
Tenant Admin Dashboard
For tenant admins to configuration, monitoring, and maintenance.

Two Ways to Deploy

Both configurations share the same core, Auth, Pulse API, and, optionally, Sentinel. The Complete Solution adds Connect, Pulse CA's own OIDC/SAML provider, so enforcement happens natively rather than as a signal to someone else's system.

  • As an Add-on, deployed alongside your existing IdP/IAM (Okta, Entra, Ping, or similar), Pulse CA fills the gaps that investment leaves open, without disrupting it. This is the lower-friction path for organizations with an identity platform already in place.
  • As a Complete Solution, with Connect included, Pulse CA becomes your identity provider outright, orchestrating the entire session lifecycle natively, from login to logout, with no third-party handoff required for enforcement.

How the Components Work Together

01, Pulse API: The Orchestration Engine

Pulse API is the central orchestrator that manages the full session lifecycle. From the moment of user login, Pulse API anchors and orchestrates the session between Auth App, Connect, and Sentinel, providing a persistent point of reference that links every later event, from trust score changes and policy decisions to enforcement actions and audit log entries. This detect-and-prevent approach, with automated step-up response where possible, means security teams have a complete, unbroken record of what happened, when, and why.

02, Auth App: The Continuous Monitoring Layer

The Auth App transforms the user's mobile phone into an identity recognition and verification, phishing-resistant responder, and continuous security sensor. Once installed and bonded to the user through behavioral patterns and a PIN, and to the device through FIDO2 authentication, the Auth App streams live trust signals to the Policy Decision Point (PDP) throughout the entire session:

  • Identity Trust Score, behavioral biometrics confirm the same person remains in control, based on interaction patterns learned during initial bonding.
  • Proximity Trust Score, Bluetooth verification confirms the authenticated phone remains physically near the device being used. If the user steps away, proximity degrades.
  • 3D Location Trust Score, GPS and barometric altitude monitoring provides floor-level precision, detecting movement that standard 2D tools miss entirely.
  • Device Health Trust Score, real-time integrity monitoring catches jailbreaks, malware indicators, hijack attempts, and other device compromise events as they happen.
  • Session Health Trust Score, real-time integrity monitoring of the phone, its Pulse API connections, and Sentinel's active proximity responder over BLE, fulfilling the Triangular Network 3-point (Tri-Net) patent.

03, Connect: Session Management and Policy Enforcement

Connect is the policy enforcement point, embedded within the OIDC and optionally SAML identity providers most enterprise environments already use. When trust is sufficient, sessions continue normally. At medium trust, a step-up authentication challenge is issued automatically. At low trust, the session is terminated, push notifications propagate enforcement decisions to all registered systems within milliseconds.

Connect also exposes AuthZEN endpoint with MCP implementing the OpenID Foundation's emerging standard for authorization queries, allowing existing applications to query current trust state inline without architectural redesign.

04, Sentinel: Access Device Orchestration for Autonomous Workflows

As organizations deploy AI agents, Pulse CA addresses the emerging risk of AI agency acting on users' behalf through Sentinel's Agentic AI extensions and a chain of custody principle: every AI agent, however autonomous, was initiated by a human, and that human origin is the immutable anchor of the agent's authority.

  • Through Tri-Net, orchestrated by and between Sentinel, Pulse API, and Auth App, user identity, presence, and participation are established and continuously assured from login to logout.
  • Every agent session carries a unique identifier associated with the originating human session, providing complete traceability from agent action back to human identity.
  • If the human's trust score degrades, that signal propagates immediately through the entire Tri-Net chain of custody, reported and acted upon within seconds, if not milliseconds.
  • Sub-agents inherit scoped authorization linked to the same human origin, are uniquely known to Sentinel, and are subject to the same trust evaluations.
  • High-privilege agent actions can require real-time re-evaluation or explicit human confirmation before proceeding.
  • Evaluation of agent actions, along with PDP inputs, is instantly available via Sentinel's integrated MCP and AuthZEN providers, with millisecond, and in some cases sub-millisecond, response times.

Tri-Net, the patent behind Session Health. Auth, Pulse API, and Sentinel form a patent-protected, three-point trust network where each leg continuously verifies the other two are live and uncompromised. Other approaches, a passkey confirmed by Bluetooth proximity at login, for instance, can verify proximity once, at the door. Tri-Net verifies it for the life of the session, and verifies the verification channel itself hasn't been tampered with, which is what makes Active Proximity and Session Health trustworthy signals rather than single points that could be spoofed. This may be Pulse CA's single hardest-to-replicate piece of technology.

Phishing Resistance Beyond Login: A Unique Pulse Capability

FIDO2 phishing resistance has traditionally applied only to the login moment, once a session is underway, that protection ends. Pulse implements FIDO2 technology at every component intersection where human involvement is required; the Auth App's FIDO2, or Passkey, provides it for the authentication ceremony. At every other intersection, Pulse API to OIDC or Sentinel, and Sentinel to OIDC, Pulse uses FIDO2-DA (Device Assertion, no user) to extend phishing resistance across the entire session lifecycle.

The result is that phishing resistance is no longer a property of the login event alone, it extends across the entire session, from authentication to logout. This is, to our knowledge, a unique capability in the market, and a material step forward for organisations seeking assurance that goes beyond securing the front door.

Real-World Threat Scenarios

Threat Scenario Without Pulse With Pulse
Mid-session credential theft Attackers reuse stolen login, system unaware until next login check Behavioral anomaly detected immediately; session terminated before damage occurs
Unexpected location change User in London at 9am, accessed from abroad 20 mins later, traditional auth sees no issue 3D location monitoring flags impossible travel; step-up or termination triggered instantly
Device compromise mid-session Phone jailbroken while session active, access continues unchecked Device health score detects compromise in real time; access revoked automatically
AI agent over-running authority Credentials stolen 20 mins into a 2-hour autonomous agent workflow Continuous trust monitoring detects anomaly; MCP or AuthZEN blocks further agent actions; full audit trail preserved
User leaves workstation with phone behind Unauthorized person takes the helm, access occurs unchecked Behavioral anomaly detected immediately; session terminated before damage occurs

Compliance and Standards Alignment

  • Zero Trust Architecture (NIST SP 800-207)
  • CMMC Level 2 & 3
  • FIDO2 / Passkey
  • AuthZEN (OpenID Foundation)

Pulse embodies the 'never trust, always verify' mandate throughout the full session, not merely at the perimeter, satisfying continuous diagnostics and audit requirements across all four frameworks.

A note on MCP: as AI agents increasingly reach tools and data through the Model Context Protocol, Sentinel supports it today through a proprietary implementation built on generally accepted methodologies. The OpenID Foundation's AuthZEN working group is developing an official MCP binding (COAZ-MCP), currently a Working Group Draft; Pulse CA intends to adopt that binding as Sentinel's standard once it's finalized, keeping MCP on the same standards trajectory as the rest of the AuthZEN evaluation layer.

Deployment Options

Pulse CA provides Continuous Authentication & Identity Assurance for AI in two configurations

As an Addon

As an addon to existing an IdP/IAM installation bringing continuous authentication and identity assurance where none previously existed. Core components include Auth as a source of identity truth, Pulse API providing the PDP, headless OIDC orchestrating the CA session and the PEP, and Sentinel's AuthZEN with MCP for AI agent integration.

As an IdP

As a primary IdP provider, supplies same continuous monitoring for AI assurance as outlined for Addon and includes SSO support with a choice of either OIDC or SAML 2 provider service. Headless OIDC for Sentinel use and Auth app source of truth are retained while user authentication responsibility remains unchanged.

Typically, integration and configuration are completed within minutes. Deployment of Sentinel to Windows, MacOS, or Linux devices may require reloading of the system. Staff familiar with the IdP/IAM and AI agent setup are best suited for performing setup and configuration.

Pulse CA represents a fundamental shift in how digital security is delivered, from a checkpoint at login to a continuous, intelligent assurance that persists for the duration of every session, whether driven by a human or an autonomous AI agent. It addresses the security gaps that conventional tools leave open, satisfies the compliance requirements of regulated enterprise customers, and provides the audit-ready architecture that AI-enabled services increasingly demand.

For the full architectural detail behind these claims, Tri-Net, AuthZEN and MCP, the OPA policy engine, and deployment mode specifics, see the Pulse CA Technical Brief.

NOTICE: As of the date of this page, support for AI agents, agentic or otherwise, is delivered via Sentinel's integrated AuthZEN and MCP evaluator endpoints. Via this facility, AuthZEN- and MCP-based evaluation and response can be applied to any of Pulse CA's core and extended metric sets. Additional Sentinel Agentic AI capabilities continue to roll out through the remainder of 2026; contact AffirmedID for the current feature-availability schedule.