The full control plane

Twelve domains become six clear operator experiences.

Instead of an endless feature list, the platform is organized around the outcomes an identity, security, infrastructure, or operations team needs to understand.

01 · IDENTITY

Identity convergence

Lifecycle begins in SCIM and remains traceable through policy, FreeIPA, and Linux enforcement.

  • Users, groups, filters, patch and disable
  • Transaction-scoped password delivery
  • FreeIPA write and Linux login proof
02 · FEDERATION

SAML and OIDC

Human authentication and machine provisioning remain separate, explicit trust paths.

  • MFA handoff and assertion validation
  • Discovery, JWKS, PKCE, state and nonce
  • Role mapping, sessions and readiness
03 · LINUX AUTHORITY

FreeIPA control

Kerberos, POSIX identity, HBAC, host groups, directory health, and bounded writes stay visible.

  • Users, groups and authorization
  • Host and service identity
  • Downstream enforcement evidence
04 · INFRASTRUCTURE

Foreman and classrooms

Inventory and Puppet facts become room-aware operational context for physical workstations.

  • Interfaces, MACs, facts and host groups
  • Room, seat and floor-plan views
  • Per-seat WoL and bounded power actions
05 · REMOTE OPERATIONS

SSH, VNC and Guacamole

Remote support uses the relay path that can actually reach the workstation.

  • Dedicated jump-vantage probes
  • Tokenized Guacamole launches
  • On-demand VNC activation and evidence
06 · INTELLIGENCE

Topology, logs and data control

The estate, evidence stream, living ERD, migrations, retention, and recovery become one operational language.

  • Configured, inferred and observed topology
  • Explainable security and system events
  • Backup-first database maintenance
Proof chain

“Proven” means the action survives contact with reality.

A route existing is not enough. The platform has to show the correct authority, safe execution, observable result, and a path to recovery or remediation.

IntentAuthorized request
PolicyGuard and boundary
ExecuteDirectory or system action
ObserveHost or service result
ProveEvidence and recovery
Detailed matrix

The complete capability record remains available for technical review.

The visual layer gives the story energy; the matrix preserves the exact status and operating boundary behind each claim.

DomainCurrent capabilityStatusProof and boundary
SCIM usersDiscovery, create, read, replace, patch, active-state disable, filters, paging, structured errors, and replay-safe behavior.ProvenStandard SCIM transactions backed by FreeIPA-aware mapping and correlated evidence.
Password convergenceAuthorized password delivery in memory, policy checks, guarded FreeIPA write, and downstream Linux login validation.ProvenPlaintext is never persisted, echoed, or logged.
SAML SSOOkta authentication, MFA handoff, ACS validation, role mapping, sessions, logout, readiness, and diagnostics.ProvenHuman login remains distinct from machine provisioning.
OIDCRP and broker integration, discovery, JWKS, authorization-code security controls, role mapping, and session evidence.OperationalEnvironment policy decides which path is enabled.
FreeIPA controlUsers, groups, HBAC, host groups, directory health, bounded agent operations, and Linux enforcement evidence.ProvenFreeIPA remains the Linux authorization and Kerberos/POSIX authority.
Foreman and PuppetHost/interface inventory, MAC enrichment, Puppet facts, host groups, fleet readiness, dry-run import, and backups.OperationalReviewed enrichment never silently overwrites workstation truth.
Classroom operationsRoom and seat views, health, per-seat WoL, reboot, power-off, reasons, probes, and policy gates.ProvenPower paths are scoped per workstation and relay authority.
Remote consoleGuacamole SSH/VNC plans, tokenized launch URLs, dedicated jump relays, VNC activation, and audit trails.OperationalLaunchability is evaluated from the actual jump vantage point.
TopologyLiving graph for identity, directory, Foreman, storage, relays, rooms, workstations, protocols, health, and evidence.ProvenConfigured, inferred, cached, and live states remain labeled.
Living ERDRuntime schema inventory and relationship visualization tied to the active platform model.OperationalOperators are not dependent on a stale static diagram.
Observability and securityApplication, SSO, OIDC, login, SSH, host, remote-session, threat, system, and error evidence with remediation.ProvenSecrets, assertions, cookies, keys, and plaintext credentials are excluded or redacted.
Database controlHealth, schema audit, migration preview, approvals, backups, retention, guarded pruning, vacuum/analyze, and survivability.OperationalDestructive SQL is blocked from the safe apply path.
Choose a control plane

Go from the matrix to the operating experience.

Trace identity convergence, inspect federation, enter the infrastructure command surface, walk the topology, review security intelligence, or examine governed database operations.