IDENTITY & ACCESS

Accounts become infrastructure when institutions depend on them.

V11 defines the target identity lifecycle for individual users and enterprise organisations: invitation, verification, MFA, SSO, provisioning, session control, recovery and offboarding.

Individual access

Verified email, secure authentication, MFA and recovery without weak shared credentials.

Enterprise SSO

SAML/OIDC support for institutional identity providers with organisation-enforced policies.

Provisioning

Invite users individually or later support SCIM/bulk provisioning for large customers.

Session policy

Shorter privileged sessions, re-authentication for sensitive actions and device/session visibility.

Offboarding

Disable access immediately while preserving legally required audit history.

Break-glass

Emergency privileged access should be exceptional, time-limited, justified and audited.

Service accounts

Machine credentials separated from human users, scoped and rotated.

Privileged access

Platform-admin permissions should require stronger controls and enhanced monitoring.