The product follows the identity transaction from request to enforcement.
Each plane has a narrow job. Together they produce a lifecycle path that is observable enough to operate and constrained enough to trust.
Lifecycle mediation
Receive SCIM users, normalize identifiers and attributes, enforce request rules, apply bounded writes, and return standards-aware results.
Authority mediation
Keep Okta, FreeSCIM, and FreeIPA responsibilities explicit so provisioning never quietly becomes authentication or access policy.
Federation and sessions
SAML is the preferred production SSO path. OIDC remains a parallel governed capability with readiness, key, role, and session evidence.
Evidence and reconciliation
Mappings, persistent sync, snapshots, drift, audit, health, and logs show whether intent and downstream state still agree.
Password convergence is a staged migration, not a checkbox.
FreeSCIM has the plumbing to receive transaction-scoped password material safely, but production authority moves only through explicit readiness, pilot, and rollback gates.
The identity product can see farther without claiming every system as its own.
Operational integrations add context around the identity path. They are useful, but they do not redefine the core authority model.
Clear non-goals keep automation from becoming accidental authority.
The platform is designed to bridge responsibilities, not erase them.
Scale the operating model, not the ambiguity.
The strongest path forward is to keep one common policy and evidence plane while adding provider-specific adapters only where their authority contracts are explicit.