Who this comparison is for
AccessGuard highlights
- Hosted registration/login/recovery, JWT/refresh/session lifecycle, email/phone verification, account approval, and MFA policy state
- Customer profiles, communication preferences/consent, KYC/risk, notification inbox/delivery state, and reusable audiences
- Workspace app operation grants, delegation policies, Bridge v2, Handler/RCP, ContextResolver, secure media, provider delivery, and case/problem orchestration
AWS Cognito highlights
- AWS Cognito capabilities and operating model vary by product configuration, edition, deployment model, and connected ecosystem
Capability matrix
| Capability | AccessGuard | AWS Cognito | Notes |
|---|---|---|---|
| Hosted registration, login, recovery & verification | Native | varies by product/edition | AccessGuard exposes canonical website/customer operations through signed Bridge v2 plus internal APIs/capabilities. |
| JWT, refresh tokens, sessions, introspection & revocation | Native | varies by product/edition | AccessGuard keeps durable session/refresh/revocation state and administrative force-logout controls. |
| Customer profile & customer-identity bundles | Native | varies by product/edition | Profiles include contacts, addresses, media, external-account/payment references, communication state, KYC, risk, and audit. |
| Communication preferences & consent evidence | Native | varies by product/edition | Channel/purpose preferences and consent evidence participate in AccessGuard notification authorization. |
| Notification center, inbox & provider orchestration | native + capability providers | varies by product/edition | AccessGuard owns notification/recipient/inbox/events and delegates external email or messaging delivery. |
| Audience definitions & member resolution | Native | varies by product/edition | Schema-aware audience definitions support validation, preview, versions, activation state and canonical member capabilities. |
| Application operation grants & downstream delegation | Native | varies by product/edition | Inbound application authority and outbound delegation authority are explicit, separate policy records. |
| ContextResolver entities, timeline, permissions & actions | Native | varies by product/edition | Trusted apps can consume live AccessGuard source state and execute authorized state-sensitive actions. |
| KYC, risk, approval & verification human work | native + case/problem provider | varies by product/edition | AccessGuard owns the identity state and can synchronize review work to a configured service-operations provider. |
| Secure profile media & protected app secrets | native platform services | varies by product/edition | Profile media uses Core secure file services and integration/JWT secrets use Core AppSecretService-backed storage. |
Total cost of ownership
AccessGuard concentrates identity, customer-security, notification policy, application authorization, and context operations inside the Velaxe workspace while using capability providers for downstream delivery and human work.
Assumptions
- The organization runs one or more Velaxe workspace applications and/or external websites that need a shared identity/customer-security authority.
Migration plan
From AWS Cognito · Inventory identity flows → map users/sessions/profile/security policy → connect applications/sites → controlled cutover
-
1
Inventory the authentication, account lifecycle, session/token, profile, consent, notification, and application-integration data required for the target workspace.
-
2
Configure AccessGuard authentication/session policy, customer profile model, communication catalogue/policy, app grants, Bridge clients, and provider bindings.
-
3
Connect representative websites and workspace applications through Bridge v2 and trusted Handler/RCP capabilities; validate identity, profile, notification, and context operations.
-
4
Cut over identity traffic to AccessGuard and monitor sessions, verification, notifications, provider connections, authorization events, and human-review synchronization.
Security
- Trusted AppExecutionContext, operation/resource/delegation authorization, HMAC v2 Bridge credentials, Core-backed secrets, secure file ingress/download, production error boundaries, and audit/event state.
Evidence & sources
About AccessGuard
AccessGuard centralizes workspace authentication and customer identity. External websites can use the signed Bridge v2 proxy and JavaScript SDK for registration, login, verification, recovery, token refresh, profile management, protected media, and notification inbox operations.
Inside the workspace, AccessGuard owns users, sessions, verified identities, customer profiles, communication preferences and consent, approval state, KYC documents, risk flags, notification state, audience segments, application operation grants, delegation policies, and trusted context actions. Canonical capabilities are available through Handler and RCP, with selected operations available through Bridge v2.
Configured providers handle downstream delivery and human work: email, SMS, WhatsApp, voice, push, and case/problem operations can be delegated while AccessGuard preserves the identity, authorization, provenance, and customer-policy record.