Four product planes

The product follows the identity transaction from request to enforcement.

Each plane has a narrow job. Together they produce a lifecycle path that is observable enough to operate and constrained enough to trust.

Governed authority transition

Password convergence is a staged migration, not a checkbox.

FreeSCIM has the plumbing to receive transaction-scoped password material safely, but production authority moves only through explicit readiness, pilot, and rollback gates.

01DisabledReject password push and record the blocked attempt safely.
02ObserveDetect and redact without applying a directory change.
03TestExercise approved test identities without committing the write.
04PilotApply only for the approved pilot cohort with rollback ready.
05EnableCut over only after the operating proof supports production scale.
Supporting extensions

The identity product can see farther without claiming every system as its own.

Operational integrations add context around the identity path. They are useful, but they do not redefine the core authority model.

Fleet contextForeman and Puppet can enrich host and environment understanding around directory identities.
Remote supportSSH, VNC, jump paths, and Guacamole can carry bounded support actions with evidence.
Data operationsPostgreSQL health, schema, backups, retention, and recovery protect the platform’s own operating memory.
TopologyRelationships can be visualized while configured, inferred, cached, and live state remain distinguishable.
Federation runtimeApplication readiness, trust health, key freshness, and drift can be tracked without replacing the upstream IdP.
Future SCIM adaptersNew destinations can reuse the mediation pattern only after target-specific authority and proof are defined.
What it deliberately is not

Clear non-goals keep automation from becoming accidental authority.

The platform is designed to bridge responsibilities, not erase them.

Not a password vaultStanding cleartext passwords are not pulled from Okta or retained for later replay.
Not an HBAC bypassA successful provisioning event does not grant Linux access outside FreeIPA policy.
Not a replacement IdPOkta remains the human authentication and MFA authority in the current model.
Not proof by existenceA route or module is not called production-proven until the full environment-specific path has been validated.
A bridge that can become a platform

Scale the operating model, not the ambiguity.

The strongest path forward is to keep one common policy and evidence plane while adding provider-specific adapters only where their authority contracts are explicit.