Skip to content
The integration means your existing identity stack can act the instant a user's trust level changes, not just at the next login.

Twosense Introduces CAEP Integration for Real-Time IAM Trust Signals

NEW YORK CITY, August 18, 2026. Twosense, which provides Continuous Authentication and Continuous Access Evaluation (CAE) for workforce identity and access management, today announced an integration with CAEP (Continuous Access Evaluation Profile) that lets any application in a customer's identity stack react instantly to changes in user trust. Organizations get real-time, automated response to identity risk using the tools they already have, without waiting for a security team to build a custom integration first.

The integration works by connecting Twosense's continuous, biometric trust signal to the Continuous Access Evaluation Profile (CAEP), an open standard within the Shared Signals Framework (SSF). CAEP and the broader SSF let identity and security platforms share real-time signals about changes in session risk and user trust, so any CAEP-compliant platform a customer already runs can consume Twosense's signal and act on it immediately.

Most IAM infrastructure today is built on a point-in-time, human-driven model of authentication: verify once at login, then trust for the rest of the session. That model has no native pathway for dynamic de-authentication and doesn't account for mid-session changes, whether up or down, in a user's trust level. As a result, organizations that deploy Continuous Authentication haven't been able to automatically realize its full security benefit; doing so has required custom, per-application integration work that only the most sophisticated engineering teams could take on.

"Continuous Authentication delivers its full value when the rest of the identity stack can actually act on it in real time," said Dawud Gordon, Ph.D., CEO of Twosense. "CAEP removes the integration burden that's kept organizations from operationalizing continuous trust signals. This is what makes continuous identity practical at enterprise scale, not just a checkbox feature."

Five ways our customers are using this

For customers, this means the gap between "something looks wrong" and "something gets fixed" closes from an entire session down to the moment it happens. Twosense's beta customers are already using this integration in production to catch:

  • Unauthorized use, with automatic session revocation. If that behavior stops matching the authenticated user mid-session, whether from stolen credentials used elsewhere or deliberate impersonation, the session is automatically revoked, regardless of whether a workstation was ever left unlocked.
  • Credential sharing. A login or access badge lent out for convenience is one of the most common ways credentials get misused. The integration flags the mismatch the moment it happens.
  • Session hijacking. A stolen session token doesn't help an attacker if the behavior behind it doesn't match. The mismatch gets caught and the session can be ended before it's misused.
  • MFA compromise. MFA can be phished, socially engineered, or worn down through repeated push prompts. This integration keeps watching after MFA clears, catching an imposter who's already gotten past that step.
  • Accidental open session takeover. Someone steps away from a workstation without logging out, and the next person to sit down inherits full access without ever entering their own credentials. The integration detects the identity switch immediately.

The underlying technical details, including how trust signals map to the CAEP risk model, are available in Twosense's documentation.

Twosense's integrations, including SGNL (CrowdStrike), Okta, Ping, and Imprivata, are already positioned to ingest these signals to drive policy enforcement and orchestration on their own platforms, from step-up authentication challenges to session termination and access revocation. Imprivata and Ping are Twosense's initial integration partners for this release. The Imprivata integration is documented and live on Imprivata's platform as Advanced Passwordless Access, with CAEP signals flowing between platforms automatically. Ping integration is available today through the Ping DaVinci SKU, with the same automatic signal flow.

"CAEP gives us a standard, out of the box way to plug Twosense's trust signal directly into a customer's existing policy engine," said John Tanios, CTO of Twosense. "Organizations get real-time, automated responses to changes in user trust without writing custom integration code for every application in their stack."

Customer benefits

  • Immediate time-to-value: consume standardized, real-time trust signals out of the box, without bespoke engineering or custom integration work
  • Faster response to risk: integrated platforms can act on a trust signal the moment it changes, closing the gap between authentication events and enforcement
  • Frictionless user experience: continuous, invisible authentication that keeps valid users productive without repeated login interruptions
  • Ecosystem interoperability: built on an open standard already supported by leading identity and security platforms, so customers aren't locked into a single vendor's integration path

Availability

This CAEP integration is available now to Twosense customers. Organizations already using Okta, Ping, SGNL, or Imprivata can begin consuming real-time trust signals without additional development work. To see it in action, get a demo or visit www.twosense.ai to learn more.


About Twosense Twosense provides Continuous Authentication and Continuous Access Evaluation (CAE) for workforce identity and access management. Using passive biometrics such as typing patterns and mouse movements, Twosense delivers invisible, always-on authentication that runs in the background, with no phones, tokens, or user training required. It stops threats that occur after login, including session hijacking, credential misuse, and unauthorized access, and can be deployed in a single day, entirely through software. Twosense is trusted by leading BPOs, healthcare systems, and enterprises operating in high compliance, high friction environments. For more information, visit www.twosense.ai.

Media Contact Isabeau Boody Marketing Manager, Twosense E: isabeau@twosense.ai



More from the Blog

October 30, 2025

Part 3: From Passwords to Passwordless

In Part 1, we uncovered why most passwordless strategies fail the moment they hit the clinical floor. Shared...
May 20, 2025

The Future of Authentication Is Automated—And It’s Already Here

Manual Authentication Can’t Keep Up Most contact centers still rely on traditional authentication systems to verify...
August 24, 2020

Okta and Twosense Join Forces on the Future of Identity Security: Continuous Authentication

Twosense provides software-based continuous authentication in the workplace, for better security with better...

Subscribe Here

We will never share your email address with third parties.