Rich event context

Every signal keeps the operational story attached.

Method, path, status, duration, request ID, correlation ID, actor, session, source, lifecycle phase, impact, outcome, retry state, degraded state, trust score, related identity or host, and recommended action can travel together.

WhoActor and session
WhatAction and outcome
WherePath and affected asset
WhyPolicy and trust context
NextRemediation and retry
Signal domains

One console spans identity, systems, remote support, and data.

Operators can move across the stack without losing correlation or translating six unrelated logging formats in the middle of an incident.

SSO

Federation and sessions

SAML and OIDC starts, callbacks, validation, role mapping, session establishment, logout, failures, and readiness.

SAMLOIDCMFAclaims
AUTH

Login assurance

Success, failure, policy denial, fallback, account state, downstream Linux proof, and post-login validation.

KerberosHBACproof
RMT

SSH and remote support

Jump-path checks, workstation reachability, Guacamole mints and launches, VNC activation, blockers, and ownership.

SSHVNCGuacamole
THRT

Threat and host intelligence

Repeated failures, malformed requests, suspicious sources, host findings, confidence, and containment guidance.

confidenceseveritycontainment
SCIM

Lifecycle and application

Request lifecycle, mappings, provisioning outcomes, password-presence flags, retries, drift, errors, and remediation.

requestmappingretry
SYS

System and database

Service state, readiness, migrations, retention, pruning, maintenance, schema drift, and operational errors.

healthmigrationrecovery
FreeSCIM correlated signal console
From raw signal to explanation

The console answers the question behind the log line.

A useful operational event should tell the operator what failed, where the boundary sits, what was affected, whether retry is safe, and what evidence or action comes next.

01

SSO validation failureFailed trust path, likely configuration class, correlated attempt, impact, and next inspection point.

02

Remote console failureApplication-to-jump and jump-to-seat evidence, selected relay, blocker, and correct owner.

03

SCIM write errorLifecycle phase, mapping or directory boundary, retry safety, degraded state, and remediation direction.

Live evidence example

Human-readable without sacrificing technical depth.

The event stream can remain concise for scanning while preserving the IDs and evidence needed for investigation.

freescim://security/correlated
06:14:22PROVENDownstream Linux login validated after password convergencecorr 8f2c
06:13:18SESSIONOIDC role mapping completed; privileged scope withheld by policysess b910
06:12:40DEGRADEDGuacamole VNC plan blocked by inactive workstation serviceseat 17
06:11:03SECURITYRepeated failed login pattern exceeds confidence thresholdtrust 62
06:09:27READYDatabase migration preview and backup gates completeddb op 41
Security boundary

More context never means exposing more secrets.

FreeSCIM is intentionally rich in operational evidence and intentionally sparse in sensitive material.

No plaintext passwordsPassword values are never stored, displayed, echoed, or written into evidence.
Token and assertion redactionSCIM bearer tokens, OIDC tokens, SAML assertions, cookies, and client secrets are excluded.
Keys remain privatePrivate keys, deploy keys, database credentials, and remote credentials stay outside public content.
Evidence before accusationSuspicious activity is described with confidence, source, pattern, and observable facts.
Cross-layer correlationOne event can be followed across authentication, provisioning, directory, host, relay, and database layers.
Remediation by designThe operator sees the likely owner, next check, safe retry posture, and recovery direction.
Designed for remediation

Observability becomes an operating advantage.

The evidence model answers what happened, who or what initiated it, which trust or network path was involved, what was affected, whether retry is safe, and what the operator should do next.