Credential security
Credentials establish that required authority was successfully presented. Existence establishes a different current condition.
Passwords, passkeys, certificates, hardware tokens, biometrics, and other credentials can be designed, issued, protected, revoked, and recovered with increasing strength. Existence does not replace them. An EAID is not an access credential, and possession of a found identification must never be sufficient to enter the organization’s application.
The credential fact
A credential answers whether required evidence of authority has been accepted.
The organization decides which credentials are allowed, how they are bound to an account, when additional factors are required, how secrets are protected, and what happens when evidence is lost or compromised.
That decision is necessary. It remains a credential decision. It does not become proof that the governed existence relationship continues to return present at a later protected action.
Possession is not permission
A found identification cannot become a substitute credential.
The EAID identifies the governed existence relationship and participates in establishing its current condition. It does not independently authorize entry, assign a role, or grant application permission.
The organization’s page must still apply its own credential, identity, role, and authorization requirements. Without that separation, possession of a lost or stolen identification could be mistaken for authority.
Private arrival
Existence establishment completes before the organization begins consuming the result.
The first successful heartbeat releases the private Rendering Agent. The organization then loads its page into that private arrival. That loading completes existence establishment.
The page does not inherit unrestricted authority from the EAID. It applies the organization’s credential and access requirements, then uses the maintained existence result only where organizational policy requires it.
After authentication
A credential event can remain historically valid while the current existence condition changes.
A password, passkey, certificate, or multifactor event may have succeeded earlier. A session may continue to carry the authority derived from that event. Existence maintains itself separately through recurring heartbeat after private arrival.
The network is where the organization observes that current result. The network does not create existence and does not turn the result into a credential.
Protected use
The organization can require both valid authority and a present existence condition.
A selected function may first evaluate the credentialed identity, role, and permission. Before consequence, it may also request the current existence result.
verify_existence(...)The function consumes the present-or-absent condition without changing the organization’s credential policy.
Credential compromise
Stolen evidence and current existence are different attack surfaces.
A stolen credential can falsely satisfy an authentication requirement. A stolen session can carry previously granted authority. A found EAID cannot be allowed to satisfy either requirement by itself.
Existence adds a separately governed current condition. It does not repair weak credential issuance, prevent credential theft, or prove that a present participant is acting safely.
What existence does not replace
Credential security remains a complete discipline in its own right.
Existence does not replace secure enrollment, phishing resistance, secret storage, cryptographic binding, multifactor authentication, revocation, rotation, device protection, recovery, fraud detection, or authorization.
The bounded contribution is to keep current existence separate from the credential fact so both can be required without either being misrepresented.
Continue the examination