Workforce identity wiring
Configure Better Auth OIDC/SAML providers; live enterprise provider and group/claim mapping tests remain outstanding.
Identity plane
Issue scoped gateway sessions today and evaluate Better Auth federation wiring, while connected accounts and production claim mapping remain planned.
Product boundary
Capabilities
Status labels distinguish tested behavior from useful previews and the open roadmap.
Configure Better Auth OIDC/SAML providers; live enterprise provider and group/claim mapping tests remain outstanding.
Target open SCIM user and group lifecycle management with comprehensive credential invalidation.
Broker approved OAuth, API-key, and service-account connections per identity and environment.
Issue short-lived gateway sessions for a precise composition, principal, and policy context.
Operating flow
Resolve the workforce user, workload, or service principal at the control plane.
Attach organization roles, groups, claims, and approved connected accounts.
Mint a short-lived data-plane session with explicit audience and scope.
Target control surface
These controls define the intended product boundary; the capability labels above are the current implementation record.
The managed cloud and Kubernetes paths are previews of one open codebase, with no intended capability gate or mandatory call-home path.