CurrentIdentity operations
SCIM lifecycle, canonical identity, SAML, FreeIPA mediation, reconciliation, drift, audit, Linux proof, replay, and operator dashboards.
Runtime truth
FreeSCIM has grown from a SCIM bridge into an identity operations control plane. This page keeps the growth honest by separating implemented behavior from enabled authority, direct proof, runtime findings, and future-provider frameworks.
CurrentSCIM lifecycle, canonical identity, SAML, FreeIPA mediation, reconciliation, drift, audit, Linux proof, replay, and operator dashboards.
GovernedOIDC enablement, password movement, profile writes, rollback execution, bulk mutations, and live ITSM actions remain deliberately constrained.
RoadmapNew provider frameworks exist, but live integrations still require configuration, adapter work, tenant proof, and operating evidence.
These functions are present in the canonical runtime and belong in the public product story.
LifecycleUser lifecycle, bounded groups, discovery, filtering, paging, structured errors, concurrency controls, mapping, and secret-safe request handling.
IdentityUpstream login, contact address, SCIM username, directory uid, and Kerberos principal are modeled as related but distinct identifiers.
ControlMutation audit, observe mode, dry-run, pre-write snapshots, approval gates, blocked-state UX, and rollback candidates make execution state visible.
ReconcilePersistent comparisons, snapshots, drift artifacts, action history, correlation IDs, and read-only replay support evidence-first remediation.
TrustSAML, governed OIDC, provider maturity, application onboarding, key intelligence, trust health, drift, stewardship, and readiness are modeled operationally.
OperateDegraded-state reporting, evidence integrity, retention, exports, database-backed history, and audited landing, FreeIPA, Okta, Sync, Mapping, and Admin surfaces support day-two operations.
The password transition is the clearest example: substantial safety machinery exists, but the final real-write chain is still blocked from being called complete.
| Milestone | State | Public interpretation |
|---|---|---|
| SCIM behavior and conformance | Proven | Safe to describe as current capability. |
| Canonical identity provenance | Operational | Current platform behavior across operator surfaces. |
| Observe and dry-run execution | Proven | Current governed behavior. |
| Linux trust and login proof | Proven | Current controlled proof for Linux enforcement. |
| External password-origin event | Not proven | Do not describe the password chain as complete. |
| Real password write | Blocked | Adapter and guard machinery exist, but production proof is incomplete. |
| Real rollback after password write | Not proven | Rollback tooling exists without the final end-to-end proof milestone. |
| Database runtime posture | Needs attention | Governance tooling is real, while current schema and maintenance findings remain visible. |
FreeSCIM already has provider registries and onboarding templates. The maturity model exists specifically to prevent a framework entry from being mistaken for production support.
CurrentOkta, FreeIPA, SCIM 2.0, SAML, and the governed OIDC relying-party path have real runtime implementation and evidence.
DeclaredMicrosoft Entra ID, Active Directory, generic LDAP, Google Workspace, GitHub Enterprise, Canvas, Shibboleth, CAS, and generic OAuth patterns remain declared or templated until live proof advances their maturity.
Next targetThe control plane already has the identity, mapping, governance, evidence, and maturity concepts needed around a connector. What is still missing is the dedicated GitHub SCIM destination adapter and its live enterprise proof.
Making GitHub Enterprise a real FreeSCIM destination means defining GitHub-specific lifecycle behavior and then proving it under the same governance model as the existing identity path.
The control plane is already much larger than its original connector role. The next step is to keep adding adapters and governed execution while preserving the same distinction between declared, configured, proven, and blocked.