Trust Controller CBA vendor demonstration

Evidence artefactdocs/evidence/content-commercial.md

TC-23 Commercial and procurement implications

ObjectiveTC-23
Evidence levelEvidence
DomainCommercial and procurement fit
OwnerID Partners, as reseller. Raidiam supplies the capability inventory only.
PhaseEnhanced Vendor Demo
Proven bycontent-commercial

On what is claimed here. Where this document describes the demonstration, it states what the Enhanced Vendor Demo of 24 August 2026 is built to prove, not what has already been built, recorded or verified. Status for every scene is tracked in objectives/tc-objectives.yaml.

1. What CBA asked for

Commercial and procurement implications of the solution and deployment model.

2. The position

Commercials route to ID Partners. ID Partners is the in region reseller and the contracting party. Licensing, pricing, contract structure and procurement route are theirs to state and CBA's to negotiate. Nothing in this document, in the demonstration, in the narration or in any diagram scopes or prices anything.

Raidiam's contribution to this objective is a single artefact: the capability inventory in section 4, which sets out what the platform can do and marks what is separately licensable, so that nothing priceable is given away by accident in a demonstration and so ID Partners knows exactly what surface they are pricing.

The line to use in the room, if asked what something costs: "Commercials route to ID Partners." Nothing further, including a range, an order of magnitude or a comparison.

3. Procurement implications worth flagging, none of which are prices

These are the structural facts that shape a procurement, and they are legitimate to state.

ImplicationWhy it matters to procurement
The contracting party is ID PartnersThe commercial relationship, the support agreement and the invoicing are with ID Partners as reseller, with Raidiam as the product vendor behind them. This affects who CBA's contract is with and how the vendor management model is set up.
The deployment option changes the contract shapeThe managed service and bring your own Postgres options place the data store on different sides of the boundary, which changes the data processing terms, the responsibility split and the operational commitments (content-deployment-model.md). The technical choice should be made before the contract is drafted, not after.
Region selection is a contractual factSydney and Melbourne for Australian customers. Which regions are used, and whether both are required, should be named in the agreement.
The Enhanced Vendor Demo carries no contract dependencyThe 24 August 2026 demonstration is vendor hosted, synthetic and requires nothing to be signed. The Formal Proof of Concept does require an agreement, at minimum covering environment access, data handling and support. That is the first commercial gate on the timeline.
Environment count is a scoping dimensionNon production environments, and whether each requires its own trust anchor, is a scoping question that should be settled early because it is easier to answer at design time than to renegotiate.
Portability is a design property, not a concessionThe declared state of the entire federation lives in a git repository CBA can own, and the platform API is documented. Exit produces a machine readable estate rather than a data extract request (content-recovery.md). This is a fact CBA's procurement team will want and it is genuinely true.
CBA is already a consumer of this stackThrough ConnectID membership. Existing familiarity with the technology and its operation is a real procurement input, and it reduces the novelty risk normally priced into a first deployment.

4. Capability inventory

Every capability below is real, and several are visible in the demonstration. The licensing column records only whether a capability is separately licensable, so it is not conceded by implication. No capability is scoped, sized or priced here, and any question about any row routes to ID Partners.

4.1 Trust Controller core

CapabilityWhat it doesWhere it appearsLicensing
Directory and organisation modelFederations, authorities, authorisation domains, organisations, authorisation servers, software statementsScenes 01, 02Core
OpenID Federation publicationEntity configurations, subordinate statements, subordinate listing, resolve endpointScenes 02, 04Core
Capability roles as metadata policyRoles carrying metadata rows, applied as federation metadata policy, unioned across roles, forming the capability envelope. Projection into the published statement is open verification item 4.1 in content-gap-register.md.Scenes 02, 10Core
Authority claims and trust marksCertification and status assertion, with a live status endpointScenes 02, 06Core
Lifecycle controlApprove, suspend, withdraw, with publication following the stateScenes 02, 06Core
Change history and versioningEvery state change versioned with actor, time and before and after state, in the interface and the APIScenes 02, 07, 10Core
Full API surfaceEverything the interface does is available through the API, which is what allows approval workflow to be externalisedScenes 01, 07Core
Arbitrary attribute recordingManifest sourced attributes recorded against a software statement or authorisation server and retrievedScene 08Core
Single sign on into the platformAdministrators authenticate with their own organisation's identity providerDescribed, TC-14Confirm with ID Partners

4.2 Separately licensable capability

Each of these is a distinct capability with its own commercial treatment. They are shown in the demonstration because they are part of the architecture. They are not included by implication.

CapabilityWhat it doesWhere it appearsNote
Federation hubPartner organisations authenticate into the platform with their own identity provider, so CBA does not run an identity estate for its partnersDescribed, TC-14. CBA already consumes this through ConnectID.Separately priceable
Public key infrastructure, standard profilesRSA and elliptic curve certificate issuance backed by a managed key management service, including the bring your own public key path where the private half never leaves the customer hardware security moduleScene 09Separately priceable
Post quantum public key infrastructureML-DSA profile for post quantum signingScene 09Separately priceable
Credential issuanceOID4VCI credential issuance, used here for verifiable mandates carried by an agentWoven through scenes 03, 05, 06Separately priceable
Credential verification and presentationOID4VP presentation with selective disclosure, so a counterparty receives only the mandate claims it needsWoven through scenes 03, 05, 06Separately priceable
Shared signals publicationSecurity event publication and delivery over HTTP (RFC 8935), so a withdrawal reaches subscribed consumers immediatelyScene 06Separately priceable
Token status listsOAuth token status list publication, so a consumer that subscribes to nothing still fails on the next presentation of an already issued tokenScene 06Separately priceable
Bring your own Postgres deploymentCustomer held data store over private connectivity, with the vendor running the processing layerDescribed, TC-13Separately priceable
Additional trust anchors or authoritiesMore than one anchor, for example a separate anchor per environment or per jurisdictionModelled in the estateSeparately priceable
Cross recognition with an external schemeMutual recognition between the CBA federation and an external scheme, so an external party's identity is trusted into CBA by federation aloneModelled: an external partner agent provider and ConnectID as a cross recognised peerSeparately priceable
Additional environmentsNon production environmentsScoping dimensionSeparately priceable

4.3 Not Raidiam capability, and therefore not Raidiam commercials

Recorded here so the inventory is complete and so nothing in these rows is assumed to be included.

ItemOwner
Agent marketplace or catalogueCBA or ID Partners. See content-gap-register.md.
Agent Identity Manifest schemaID Partners
Approval and rejection workflowCBA's existing tooling. External by design.
Ping Federate and Entra bridgeID Partners
SPIFFE and SPIRE integrationID Partners
Implementation, integration and support servicesID Partners

5. What we need from ID Partners

  1. Confirmation that the section 4 inventory matches how ID Partners intends to package and price, and a correction where it does not.
  2. The procurement route CBA prefers, and whether an existing vendor arrangement can be used.
  3. What agreement is needed to start the Formal Proof of Concept, and its lead time. This is the first commercial item on the critical path.
  4. The data processing position for each deployment option.
  5. Whether any capability in section 4.2 should be withheld from the demonstration entirely rather than shown and marked. Raidiam's recommendation is to show them, because they are the strongest part of the architecture, and to name none of their commercial treatment on screen.

6. Status

Framed, with the capability inventory supplied. All commercial content is owned by ID Partners and is deliberately absent from this document, from the demonstration and from every narration script.

Back to the coverage page