The Continuous Access Evaluation Profile, or CAEP, has started showing up in identity and security conversations, usually described in ways that make it sound like either a new authentication method or another acronym competing for space in an already crowded identity stack. It's neither. CAEP is a specification from the OpenID Foundation, published as part of its Shared Signals Framework, and its job is narrower and more useful than a new way to log in: it standardizes how systems communicate changes in access-related conditions so the systems receiving that information can adjust security posture without waiting for a human to notice.
Here's the problem it's solving. In a typical federated environment, a user authenticates once and an identity provider issues access to a range of connected applications. If something about that user's risk profile changes after that, a device becomes non-compliant, a credential is suspected of being compromised, a session should probably be revoked, there has historically been no fast, consistent way for the systems that need to know that to actually find out. Each vendor built its own alerting, if it built any at all, and none of it spoke the same language.
CAEP gives that communication a shared format. A system that detects a change, an identity provider, a device management platform, a behavioral identity signal like the one Twosense generates, can transmit that change as a standardized event, and any CAEP-compliant receiver can act on it: trigger a step-up authentication challenge, restrict access, or terminate the session outright. The point isn't that CAEP decides what should happen. It's that CAEP makes sure the systems capable of deciding actually get the information they need to decide.
For health systems, where a single health system might run multiple identity providers, an EHR, dozens of clinical and administrative applications, and a patchwork of endpoint and security tooling, that real-time broadcast is the difference between a useful signal and an isolated one. A continuous identity signal that stays trapped inside one vendor's dashboard doesn't change anything about a session that should be reevaluated elsewhere. The same signal, delivered through CAEP, can reach the identity provider, the EHR's access controls, and the security team's monitoring platform at the same time.
CAEP doesn't generate the signal, it moves it. What generates the signal, in the case of the human identity behind a session, is where Continuous Authentication comes in, and that's the distinction the next piece in this series untangles. A continuous identity architecture needs both halves working together, a signal worth transmitting and a standard way to transmit it, and most vendors in this space have built one half well without the other.