Close the loop — from signal to enforcement
A CAEP signal isn’t just logged — the receiver re-decides your access, live, mid-session.
- 1
On the CAEP lab, delete a passkey from the Account page.
Continuous Access Evaluation means a token isn’t valid forever: the receiver doesn’t just file the resulting session-revoked / credential-change signal away — it revokes every one of your OTHER live sessions on the spot, the same instant it verifies the SET.
- 2
Then step up with TOTP right here on the CAEP lab.
assurance-level-change maps to a DIFFERENT enforcement action: require a fresh step-up rather than a full revoke — posture shifted, so anything sensitive should re-prove itself, without logging anyone out.
- 3
Watch the Continuous enforcement panel show exactly what happened.
Signal → policy decision → enforcement action, live — “session-revoked → 2 sessions revoked”, “assurance-level-change → step-up required” — the whole point of CAEP over a receiver that only logs what it’s told.
Learn the theory
🩻 X-ray — what actually happened
Your own insert-only audit trail — the real server events, sanitized (never a secret), each linked to the lesson that explains it.