Implemented now

The platform is substantially broader than a protocol connector.

These functions are present in the canonical runtime and belong in the public product story.

Lifecycle

SCIM service depth

User lifecycle, bounded groups, discovery, filtering, paging, structured errors, concurrency controls, mapping, and secret-safe request handling.

Identity

Canonical provenance

Upstream login, contact address, SCIM username, directory uid, and Kerberos principal are modeled as related but distinct identifiers.

Control

Controlled execution

Mutation audit, observe mode, dry-run, pre-write snapshots, approval gates, blocked-state UX, and rollback candidates make execution state visible.

Reconcile

Sync, drift and replay

Persistent comparisons, snapshots, drift artifacts, action history, correlation IDs, and read-only replay support evidence-first remediation.

Trust

Federation operations

SAML, governed OIDC, provider maturity, application onboarding, key intelligence, trust health, drift, stewardship, and readiness are modeled operationally.

Operate

Survivability and evidence

Degraded-state reporting, evidence integrity, retention, exports, database-backed history, and audited landing, FreeIPA, Okta, Sync, Mapping, and Admin surfaces support day-two operations.

Current proof state

Implementation and end-to-end proof are intentionally different.

The password transition is the clearest example: substantial safety machinery exists, but the final real-write chain is still blocked from being called complete.

MilestoneStatePublic interpretation
SCIM behavior and conformanceProvenSafe to describe as current capability.
Canonical identity provenanceOperationalCurrent platform behavior across operator surfaces.
Observe and dry-run executionProvenCurrent governed behavior.
Linux trust and login proofProvenCurrent controlled proof for Linux enforcement.
External password-origin eventNot provenDo not describe the password chain as complete.
Real password writeBlockedAdapter and guard machinery exist, but production proof is incomplete.
Real rollback after password writeNot provenRollback tooling exists without the final end-to-end proof milestone.
Database runtime postureNeeds attentionGovernance tooling is real, while current schema and maintenance findings remain visible.
Provider maturity

A registered provider is not automatically a connected provider.

FreeSCIM already has provider registries and onboarding templates. The maturity model exists specifically to prevent a framework entry from being mistaken for production support.

Current

Live identity foundations

Okta, FreeIPA, SCIM 2.0, SAML, and the governed OIDC relying-party path have real runtime implementation and evidence.

Declared

Provider frameworks

Microsoft Entra ID, Active Directory, generic LDAP, Google Workspace, GitHub Enterprise, Canvas, Shibboleth, CAS, and generic OAuth patterns remain declared or templated until live proof advances their maturity.

Next target

GitHub Enterprise SCIM

The control plane already has the identity, mapping, governance, evidence, and maturity concepts needed around a connector. What is still missing is the dedicated GitHub SCIM destination adapter and its live enterprise proof.

GitHub Enterprise SCIM gap

The next connector needs more than a new endpoint.

Making GitHub Enterprise a real FreeSCIM destination means defining GitHub-specific lifecycle behavior and then proving it under the same governance model as the existing identity path.

01AdapterImplement the GitHub Enterprise SCIM destination client and target configuration.
02MappingDefine enterprise, organization, department, school, user, group, and team relationships.
03LifecycleModel suspension, deprovisioning, external IDs, retries, limits, and conflict behavior.
04ReconcileCompare source intent with GitHub state before enabling repair or broad assignment.
05ProveCapture live enterprise evidence, failure handling, audit correlation, and rollback before production claims.
Truth is part of the product

FreeSCIM can be ambitious without blurring its maturity states.

The control plane is already much larger than its original connector role. The next step is to keep adding adapters and governed execution while preserving the same distinction between declared, configured, proven, and blocked.