The evidence reaches a usable identity, verified host action, observable remote path, or recoverable maintenance outcome.
Twelve domains become six clear operator experiences.
Instead of an endless feature list, the platform is organized around the outcomes an identity, security, infrastructure, or operations team needs to understand.
Identity convergence
Lifecycle begins in SCIM and remains traceable through policy, FreeIPA, and Linux enforcement.
- Users, groups, filters, patch and disable
- Transaction-scoped password delivery
- FreeIPA write and Linux login proof
SAML and OIDC
Human authentication and machine provisioning remain separate, explicit trust paths.
- MFA handoff and assertion validation
- Discovery, JWKS, PKCE, state and nonce
- Role mapping, sessions and readiness
FreeIPA control
Kerberos, POSIX identity, HBAC, host groups, directory health, and bounded writes stay visible.
- Users, groups and authorization
- Host and service identity
- Downstream enforcement evidence
Foreman and classrooms
Inventory and Puppet facts become room-aware operational context for physical workstations.
- Interfaces, MACs, facts and host groups
- Room, seat and floor-plan views
- Per-seat WoL and bounded power actions
SSH, VNC and Guacamole
Remote support uses the relay path that can actually reach the workstation.
- Dedicated jump-vantage probes
- Tokenized Guacamole launches
- On-demand VNC activation and evidence
Topology, logs and data control
The estate, evidence stream, living ERD, migrations, retention, and recovery become one operational language.
- Configured, inferred and observed topology
- Explainable security and system events
- Backup-first database maintenance
“Proven” means the action survives contact with reality.
A route existing is not enough. The platform has to show the correct authority, safe execution, observable result, and a path to recovery or remediation.
The complete capability record remains available for technical review.
The visual layer gives the story energy; the matrix preserves the exact status and operating boundary behind each claim.
| Domain | Current capability | Status | Proof and boundary |
|---|---|---|---|
| SCIM users | Discovery, create, read, replace, patch, active-state disable, filters, paging, structured errors, and replay-safe behavior. | Proven | Standard SCIM transactions backed by FreeIPA-aware mapping and correlated evidence. |
| Password convergence | Authorized password delivery in memory, policy checks, guarded FreeIPA write, and downstream Linux login validation. | Proven | Plaintext is never persisted, echoed, or logged. |
| SAML SSO | Okta authentication, MFA handoff, ACS validation, role mapping, sessions, logout, readiness, and diagnostics. | Proven | Human login remains distinct from machine provisioning. |
| OIDC | RP and broker integration, discovery, JWKS, authorization-code security controls, role mapping, and session evidence. | Operational | Environment policy decides which path is enabled. |
| FreeIPA control | Users, groups, HBAC, host groups, directory health, bounded agent operations, and Linux enforcement evidence. | Proven | FreeIPA remains the Linux authorization and Kerberos/POSIX authority. |
| Foreman and Puppet | Host/interface inventory, MAC enrichment, Puppet facts, host groups, fleet readiness, dry-run import, and backups. | Operational | Reviewed enrichment never silently overwrites workstation truth. |
| Classroom operations | Room and seat views, health, per-seat WoL, reboot, power-off, reasons, probes, and policy gates. | Proven | Power paths are scoped per workstation and relay authority. |
| Remote console | Guacamole SSH/VNC plans, tokenized launch URLs, dedicated jump relays, VNC activation, and audit trails. | Operational | Launchability is evaluated from the actual jump vantage point. |
| Topology | Living graph for identity, directory, Foreman, storage, relays, rooms, workstations, protocols, health, and evidence. | Proven | Configured, inferred, cached, and live states remain labeled. |
| Living ERD | Runtime schema inventory and relationship visualization tied to the active platform model. | Operational | Operators are not dependent on a stale static diagram. |
| Observability and security | Application, SSO, OIDC, login, SSH, host, remote-session, threat, system, and error evidence with remediation. | Proven | Secrets, assertions, cookies, keys, and plaintext credentials are excluded or redacted. |
| Database control | Health, schema audit, migration preview, approvals, backups, retention, guarded pruning, vacuum/analyze, and survivability. | Operational | Destructive SQL is blocked from the safe apply path. |
Go from the matrix to the operating experience.
Trace identity convergence, inspect federation, enter the infrastructure command surface, walk the topology, review security intelligence, or examine governed database operations.