Federation and sessions
SAML and OIDC starts, callbacks, validation, role mapping, session establishment, logout, failures, and readiness.
Observability and security intelligence
FreeSCIM turns application, identity, network, host, remote-support, threat, and database signals into correlated operational evidence instead of leaving operators with isolated raw lines.
Method, path, status, duration, request ID, correlation ID, actor, session, source, lifecycle phase, impact, outcome, retry state, degraded state, trust score, related identity or host, and recommended action can travel together.
Operators can move across the stack without losing correlation or translating six unrelated logging formats in the middle of an incident.
SAML and OIDC starts, callbacks, validation, role mapping, session establishment, logout, failures, and readiness.
Success, failure, policy denial, fallback, account state, downstream Linux proof, and post-login validation.
Jump-path checks, workstation reachability, Guacamole mints and launches, VNC activation, blockers, and ownership.
Repeated failures, malformed requests, suspicious sources, host findings, confidence, and containment guidance.
Request lifecycle, mappings, provisioning outcomes, password-presence flags, retries, drift, errors, and remediation.
Service state, readiness, migrations, retention, pruning, maintenance, schema drift, and operational errors.
A useful operational event should tell the operator what failed, where the boundary sits, what was affected, whether retry is safe, and what evidence or action comes next.
SSO validation failureFailed trust path, likely configuration class, correlated attempt, impact, and next inspection point.
Remote console failureApplication-to-jump and jump-to-seat evidence, selected relay, blocker, and correct owner.
SCIM write errorLifecycle phase, mapping or directory boundary, retry safety, degraded state, and remediation direction.
The event stream can remain concise for scanning while preserving the IDs and evidence needed for investigation.
FreeSCIM is intentionally rich in operational evidence and intentionally sparse in sensitive material.
The evidence model answers what happened, who or what initiated it, which trust or network path was involved, what was affected, whether retry is safe, and what the operator should do next.