Continuous Authentication evaluates whether the person using a session still matches the person who logged in. CAEP, the Continuous Access Evaluation Profile, carries a detected change in trust to the rest of a hospital's identity stack so those systems can act on it. One detects, the other distributes.
Two Related but Different Functions
Continuous Authentication evaluates whether the person using the session continues to match the authenticated identity. The Continuous Access Evaluation Profile (CAEP), an open standard from the OpenID Foundation's Shared Signals Framework (SSF), can communicate changes in authentication or trust state to connected systems so those systems can enforce access policies.
For example, a Continuous Authentication system may detect a behavioral mismatch and reduce the user's trust state. A connected identity or access system can then respond according to organizational policy. Depending on the environment, the response could include re-authentication, step-up authentication, session termination, access restriction, or another remediation action.
A Three-Part Architecture
This creates a broader architecture, not a single control:
- Continuous Authentication identifies changes in user identity.
- CAEP communicates changes in trust to the systems that need to act on them.
- Policy-driven orchestration determines what happens next.
For hospitals, that distinction matters because securing a shared workstation isn't simply about detecting a problem. The organization also needs a defined response when the trust state changes, and CAEP is what lets that response reach the rest of the identity ecosystem, the EHR, virtual desktops, and the broader IAM stack, rather than staying isolated inside one tool.

Frequently Asked Questions
How is Continuous Authentication different from CAEP?
Continuous Authentication determines whether the person using a session still matches the person who authenticated. CAEP is the standard that carries a change in that trust status to the rest of a hospital's identity and access systems so they can act on it.
Does a hospital need both?
For the signal to be useful beyond a single tool, yes. Continuous Authentication without a way to communicate what it detects stays siloed. CAEP is what lets a detected mismatch actually trigger a policy response elsewhere in the identity stack.