If you can’t prove it, you can’t sell it: making trust a competitive advantage
As regulation tightens and AI enters live networks, trust is becoming a commercial differentiator. This Catalyst turns access control into a real-time, provable capability operators can sell, not just manage.

If you can’t prove it, you can’t sell it: making trust a competitive advantage
Why trusted access control is becoming a commercial priority
As telecom networks become more distributed and complex, maintaining secure, consistent access control is becoming harder. Services often span multiple vendors, clouds and management layers, while permissions remain fragmented across systems.
Manual configuration processes and disconnected tools add further risk. Misconfigurations can lead to outages and security breaches, while audit processes are often slow, resource-intensive and incomplete.
Three pressures are now converging. Regulatory requirements are increasing, enterprise customers are demanding enforceable guarantees around data sovereignty and access control, and AI agents are beginning to operate within live network environments.
Together, these forces expose a single gap. There is no unified, standards-aligned enforcement layer that can evaluate every access decision, whether human or machine, against current policy, contract and regulation in real time.
Turning compliance requirements into real-time access decisions
The Catalyst, Trusted agentic AI for access management, introduces an AI-enabled compliance agent and a standards-aligned Digital Identity Management layer that acts as a single enforcement point across multi-vendor, multi-domain networks. Rather than treating compliance as a downstream audit task, the solution brings regulatory, contractual and internal policy requirements directly into the access-control path.
Every access request, whether from a human user or an AI agent, is checked against one continuously updated identity and access management rule base before it reaches OSS, BSS, service order, resource order, inventory, assurance or performance systems. This replacesfragmented, per-system access logic with a consistent way to govern permissions across complex infrastructure.
The AI compliance agent interprets legal, contractual and policy text, such as GDPR obligations, customer contract terms or internal security rules, and translates them into candidate access-policy updates. The agent does not directly apply policy changes to production systems. Instead, proposed updates are submitted to the Digital Identity Management layer, where they are first tested through policy dry-runs and validation processes. High-risk changes are then reviewed and approved by a human before enforcement, ensuring that AI serves as a decision-support capability rather than an autonomous policy authority.
The team demonstrated the approach through progressive use cases: a baseline role-based access control model, a GDPR-driven scenario in which only EU-based users can access sensitive German KPIs, and a critical-infrastructure scenario where configuration and provisioning actions are restricted to approved closed-user-group members. Each decision is logged with the identity, role, permission, target resource, outcome and policy basis, creating an audit-ready record that can be queried directly.
The solution is built on TM Forum assets including TMFC020 Digital Identity Management, TMFC007 Service Order Management, TMFC011 Resource Order Management, TMFC037 Service Performance Management and TMFC038 Resource Performance Management. It also uses TM Forum Open APIs including TMF720 Digital Identity Management, TMF632 Party Management, TMF676 Party Role Management, TMF768 Resource Role Management and TMF672 Permission API, with alignment to GB1087, IG1445 and IG1463 guidance.
Building auditable trust for operators, customers and critical infrastructure
For operators, the immediate impact is faster, more reliable compliance enforcement. The team aims to move policy rollout from weeks to hours by turning new legal or contractual obligations into reviewed, enforceable access rules, reducing the gap where outdated policy can create operational, security or regulatory risk.
The model also reduces operational complexity. Instead of stitching together logs and permissions from separate systems, operators can produce evidence of who accessed what, when, under which authority and why a decision was allowed or denied.
The approach enables safer adoption of agentic AI in network operations. AI agents can be authenticated, scoped, monitored and revoked through the same Digital Identity Management layer as human users. Crucially, the AI compliance agent cannot directly implement policy changes in production environments. Proposed updates are tested and validated first, while high-risk modifications require explicit human review and approval. Together with zero-trust safeguards such as controlled rollout and negative test data, this human-in-the-loop model helps prevent automated policy changes from creating new risk.
Commercially, this creates an advantage for operators serving government, defense, public-sector and regulated enterprise customers, where sovereignty, auditability and enforceable access guarantees are increasingly part of the buying decision. As Steffen Krippner, Senior Manager Fulfilment at Vodafone, explains, the Catalyst “transforms compliance from a reactive, paper-based burden into a live, automated, auditable property of the network itself.”
For the wider industry, the Catalyst provides a reusable, standards-aligned model for governing human and machine access in telecom environments. It shows how TM Forum assets can be combined into a practical enforcement framework for trusted agentic AI, helping to accelerate adoption of Digital Identity Management and reduce reliance on proprietary governance models.
More broadly, it strengthens confidence in how critical infrastructure is managed. By making compliance and data protection enforceable at the point of access, the approach supports more secure networks, more transparent operations and more responsible use of AI.