# Identity Assurance **Entity class:** Concept or analytic term Identity assurance is the evidence-backed confidence that an actor, account, device, or message source is the entity it claims to be and is authorized for the action performed. It combines enrollment, authentication, authorization, provenance, monitoring, and recovery. In communication systems, identity assurance protects against impersonation, unauthorized publication, false sponsorship, and corrupted recovery. Authentication alone is insufficient when authority, account custody, or source provenance remains unclear. Related: [[wiki/Channel Custody|Channel Custody]], [[wiki/Channel Integrity|Channel Integrity]], [[wiki/Authority–Identity Separation|Authority–Identity Separation]], [[wiki/Provenance|Provenance]]. In federal interoperability, identity assurance is carried through [[wiki/PIV and CAC|PIV/CAC]], [[wiki/Federal Public Key Infrastructure|Federal PKI]], certificate validation, role and attribute assignment, monitoring, and revocation. It is one component of [[wiki/Machine-Readable Assurance|machine-readable assurance]]; authentication does not itself establish clearance, need-to-know, mission purpose, or authority. ## Relationships <!-- BEGIN HUMANIZED RELATIONSHIPS 2026-09-11 --> This entry's documented connections are expressed in its definition and related-work routes, with provenance retained in the source-linked material. <!-- END HUMANIZED RELATIONSHIPS 2026-09-11 --> - **federal credential layer:** [[wiki/PIV and CAC|PIV and CAC]] and [[wiki/Federal Public Key Infrastructure|Federal PKI]]. - **executable trust layer:** [[wiki/Machine-Readable Assurance|Machine-Readable Assurance]].