Core

Part of the primary identity path and intended for routine production use.

Operational

Implemented and usable with documented authority and environmental boundaries.

Governed

Implemented but intentionally gated, disabled by default, or restricted to test and pilot scope.

Roadmap

A deliberate integration direction that is not represented here as already shipped.

Capability matrix

The identity bridge first. Everything else stays in its proper lane.

The matrix below reflects the operating contract rather than simply counting routes or modules.

CapabilityStateWhat FreeSCIM doesBoundary that matters
SCIM user lifecycleCoreList, read, create, replace, PATCH, active-state lifecycle, limited filtering, paging, structured errors, identifier mapping, and concurrency-aware behavior.FreeIPA remains the downstream directory and Linux enforcement authority.
SCIM groupsBoundedGroup list, read, filtering, and create are implemented.Full group replacement and deletion remain intentionally outside the public SCIM group contract.
SCIM conformance and secret safetyProvenDiscovery, response contracts, error shapes, password write-only semantics, redaction, and controlled probes are part of the verified service path.Conformance does not imply every optional SCIM feature or every downstream mutation is enabled.
Okta provisioningCoreBearer-authenticated SCIM provisioning, profile mapping, assignment-aware lifecycle, safe app policy, and operator diagnostics.Broad profile sourcing, force sync, and password sync remain disabled in the safe posture.
FreeIPA integrationCoreLDAP/LDAPS or agent-mediated operations, directory health, lifecycle operations, group visibility, and policy-aware workflows.Kerberos, POSIX identity, groups, HBAC, sudo policy, and host authorization remain FreeIPA responsibilities.
Canonical identity provenanceOperationalSeparates upstream login, contact address, SCIM username, canonical Linux username, FreeIPA uid, and Kerberos principal across dashboards and replay evidence.Contact identity is not silently reused as Linux identity.
Attribute authority matrixOperationalTracks authoritative, observational, derived, blocked, and deprecated fields plus transformation rules and precedence.Mapping configuration is allowed without implying an approved directory overwrite.
SAML SSOOperationalOkta SAML login, assertion handling, session creation, role mapping, logout, readiness, and correlated event evidence.SAML remains the preferred human SSO path and does not replace SCIM or Linux authorization.
OIDC relying-party pathGovernedAuthorization-code, PKCE, discovery, JWKS validation, claims, role mapping, readiness, and session services are implemented.The path is environment-gated and secondary to SAML. It is not a claim that FreeSCIM is the institutional IdP.
Federation governanceOperationalApplication registry, onboarding governance, maturity states, health, key intelligence, drift, readiness, lifecycle, replay, and stewardship services exist.Framework registration never equals live provider proof.
Password observe and dry-runProvenPassword payload detection, redaction, in-memory handling, observe mode, dry-run evidence, readiness checks, and guarded adapter paths are implemented.Real identity-provider password origin, a real password write, and rollback proof remain separate milestones.
Real password writeBlockedWrite guards and adapter machinery exist, but the canonical proof chain does not mark the real write as proven.No public copy should describe password convergence as end-to-end complete.
Rollback executionImplemented, not provenRollback candidates, dry-run execution, evidence, and operator restoration workflows exist.The real post-write rollback milestone remains incomplete until a governed write and rollback drill are performed.
Linux trust and login validationProvenLinux trust, HBAC, Kerberos, SSSD/PAM, and login evidence are represented in the controlled proof path and operator dashboards.This proves the Linux enforcement path, not the unproven password-write milestone.
Persistent sync and reconciliationOperationalPersistent comparison, change tracking, snapshots, plans, history, reconciliation, and operator-visible evidence are implemented.Broad execution, legacy queue processing, and bulk writes remain policy-blocked.
Drift and replayOperationalDrift artifacts, snapshot comparison, read-only replay candidates, correlation IDs, action history, and recovery context support investigation before mutation.Replay is not mutation and automatic drift repair remains blocked.
Runtime survivabilityOperationalDegraded-state labeling, cached truth surfaces, dependency fault boundaries, and operator-safe failure responses are implemented.A degraded dependency must remain visible rather than being converted into a false green status.
Evidence integrity and retentionOperationalEvidence-chain completeness, retention controls, secret stripping, export identifiers, and integrity checks support audit reconstruction.Evidence remains useful only when sensitive payloads are excluded or redacted.
Operator dashboardsOperationalLanding, FreeIPA, Okta, Sync, Mapping, and Admin surfaces have dedicated operational summaries, exports, blocked-state UX, and browser verification.Operator-ready does not mean institution-wide write authority is enabled.
TeamDynamix handoffGoverned dry-runTicket previews, persistence scaffolding, correlation, ownership context, and operations-center integration are implemented.Live institutional ticket creation and webhook authority are not production claims.
Database operationsNeeds attentionSchema audit, backups, retention, maintenance, migration controls, and survivability tooling exist.The latest runtime audit reports missing expected schema objects, an index finding, and maintenance pressure, so the site must not imply uniformly healthy database posture.
OIN preparationPreparation onlyReadiness and conformance preparation services exist for evaluating future catalog submission.FreeSCIM is not being represented as OIN certified or marketplace-ready.
Provider maturity

The platform already knows about more providers than it currently connects.

The provider registry and onboarding framework are real functionality. Live integrations still have to earn higher maturity through configuration, reachability, authentication, read/write capability, and production evidence.

Live paths

Current identity foundations

Okta, FreeIPA, SCIM 2.0, SAML, and the governed OIDC relying-party path have implemented runtime behavior and evidence models.

Declared frameworks

Future provider onboarding

Microsoft Entra ID, Active Directory, generic LDAP, Google Workspace, Canvas, Shibboleth, CAS, OAuth 2.0, and additional application patterns are registered or templated without being marketed as live connections.

Next adapter

GitHub Enterprise SCIM

GitHub Enterprise has federation-framework presence today. A dedicated SCIM destination adapter, organization and team mapping, deprovision semantics, reconciliation, retry controls, and live enterprise proof are still required before it becomes a current connector.

Runtime interaction

Compare, preview, and keep writes visibly gated.

The sync surface below follows the real runtime pattern: capture state, compute drift, generate a plan, and keep apply separate from observation.

Proof chain

A successful HTTP response is only the beginning.

A production claim should survive the full path from identity intent to downstream state and recovery.

01IntentWhat change did the source system request?
02PolicyWas the request in scope and allowed?
03DirectoryDid FreeIPA receive the intended bounded change?
04EnforcementDid Linux behavior reflect the directory state?
05EvidenceCan an operator explain, verify, and recover?
Strong claims need visible limits

FreeSCIM is more credible when “not enabled yet” is allowed to be an answer.

Governance state is part of the product. Pilot scopes, intentionally unsupported group mutations, password redaction, OIDC enablement, and future connectors are surfaced instead of hidden behind broad marketing language.