Identity assurance
Resolve user, service, device and organization identity appropriate to the action.
PLATFORM
Bind who acted, under which authority and purpose, against what consent/delegation state, and what outcome was produced.
Resolve user, service, device and organization identity appropriate to the action.
Combine role, workspace, relationship, purpose and policy instead of a single coarse role check.
Evaluate current scope, purpose, subject, delegate and expiry/withdrawal state.
Retain actor, decision, policy/config version, time, source, correlation and outcome for accountable actions.
OIDC/OAuth 2.1, enterprise federation and service credentials integrate with application authorization.
Step-up, session controls and revocation can be applied to sensitive actions.
Identity proofing level and accepted external identity providers depend on deployment policy and confirmed integration.