Identity convergenceSCIM + Password

User lifecycle and password delivery are proven through FreeIPA write and downstream Linux login evidence.

FederationSAML + OIDC

Parallel trust paths, role mapping, readiness, protocol evidence, and governed broker capabilities.

Fleet operationsForeman + Classrooms

Puppet facts enrich inventory while operators manage rooms, seats, WoL, SSH, VNC, and Guacamole paths.

Security intelligenceExplainable Logs

SSO, login, SSH, remote-session, threat, system, and application evidence becomes operator-readable guidance.

Data controlLiving ERD + Maintenance

Inspect schema, preview migrations, preserve backups, prune by policy, and maintain the database from the control plane.

True platform scope

FreeSCIM governs the entire path from identity intent to a working Linux session.

The strongest proof is not that an API returned success. It is that the platform can trace an identity operation through policy gates, a FreeIPA write, Linux enforcement, host state, and an operator-verifiable outcome while preserving correlation and recovery evidence.

Read the complete engineering case study

Control-plane domains

One system, multiple accountable operating planes.

01

Identity lifecycle

SCIM discovery, users, groups, filters, patch, active state, password delivery, attribute mapping, reconciliation, and rollback evidence.

02

Federation and access

SAML and OIDC trust, MFA handoff, claim and role mapping, sessions, failed-attempt evidence, readiness, and protocol security controls.

03

Linux authority

FreeIPA users, groups, HBAC, host groups, Kerberos/POSIX identity, directory health, bounded agents, and Linux login validation.

04

Infrastructure enrichment

Foreman host inventory and Puppet facts enrich workstation identity, interfaces, MAC addresses, operating state, and fleet context.

05

Classroom and remote support

Room and seat views, per-seat WoL, power controls, SSH paths, VNC vortex activation, tokenized Guacamole launches, and dedicated jump relays.

06

Operational intelligence

Living topology, living ERD, database controls, detailed logs, security intelligence, health/readiness, drift, retention, migration, and survivability.

Visual operations

The topology page makes the platform legible.

FreeSCIM maps the application, identity providers, FreeIPA, Foreman, storage, jump relays, WoL relays, rooms, workstations, protocols, remote-console routes, and current health into a relationship graph. It distinguishes configured and inferred paths from live evidence instead of manufacturing traffic data.

See why topology is a first-class product surface
Living infrastructure graphAuthority · Path · Health · Evidence

Operators can move from the estate-wide map to a room, workstation, trust path, or recovery action without losing context.

Verified lifecycle contract

SCIM is the ingress; proof continues after the request.