Capability status language

Proven

Demonstrated end to end with current operational evidence.

Operational

Implemented and used with documented controls and constraints.

Governed

Implemented behind approval, policy, or environment-specific enablement.

Portable pattern

Architecture is reusable, but a new external tenant or environment still requires its own proof.

Verified capability matrix

DomainCurrent capabilityStatusProof and boundary
SCIM usersDiscovery, create, read, replace, patch, active-state disable, filters, paging, structured errors, and replay-safe behavior.ProvenStandard SCIM transactions backed by FreeIPA-aware mapping and correlated evidence.
Password convergencePassword values delivered in an authorized SCIM transaction can be accepted in memory, policy-checked, pushed into FreeIPA, and proven through a downstream Linux login.ProvenPlaintext is never persisted, echoed, or logged; gates control eligible flows and evidence records only the transaction outcome.
SAML SSOOkta authentication, MFA handoff, ACS validation, role mapping, session establishment, logout, readiness, and diagnostics.ProvenHuman login remains distinct from machine provisioning.
OIDCRP and broker control-plane integration, discovery and JWKS readiness, authorization-code security controls, role mapping, session evidence, protocol parity, and governed enablement.OperationalRuns in parallel with SAML; deployment policy decides which path is enabled for a given environment.
FreeIPA controlUsers, groups, HBAC, host groups, identity probes, bounded agent operations, directory health, and Linux enforcement evidence.ProvenFreeIPA remains the Linux authorization and Kerberos/POSIX authority.
Foreman and PuppetHost and interface inventory, MAC enrichment, Puppet facts, host-group context, fleet readiness, and controlled import with dry-run and backups.OperationalEnrichment augments workstation truth without silently overwriting reviewed inventory.
Classroom operationsRoom and seat views, multi-signal health, per-seat WoL, reboot and power-off paths, reason capture, status probes, and policy gates.ProvenPower paths are scoped per workstation and separated by relay/SSH authority.
Remote consoleInventory-driven Guacamole SSH and VNC session planning, tokenized launch URLs, dedicated jump relays, VNC vortex activation, and audit trails.OperationalLaunchability depends on the workstation and jump-vantage path; secrets are outside the repository.
TopologyLiving estate graph for application, identity, directory, Foreman, storage, relays, rooms, workstations, protocols, health, and evidence links.ProvenConfigured, inferred, cached, and live states are labeled rather than blended.
Living ERDDatabase schema inventory and relationship visualization tied to the running platform model.OperationalOperators can inspect schema evolution and relationships without relying on a stale static diagram.
Observability and securityDetailed application, SSO, OIDC, login, failed-attempt, SSH, host, remote-session, threat, system, and error evidence with human descriptions and remediation guidance.ProvenTokens, assertions, cookies, private keys, and plaintext secrets are excluded or redacted.
Database controlHealth, schema audit, migration preview and approval, backups, retention planning, guarded pruning, size caps, vacuum/analyze, and survivability views.OperationalDestructive SQL is blocked from the safe apply path; maintenance begins with preview and backup.

What “proven” means here

A feature is not marked proven because a route exists. The evidence path must reach an operational result: the identity is usable, the workstation action is observable, the remote path can be explained, the migration is accounted for, or the security event can be followed by an operator from cause to remediation.

Explore by control plane