Proven now

Still behind a gate

Needs runtime attention

Database governance and maintenance tooling are implemented, but the latest runtime audit reports missing expected schema objects, an index finding, and storage pressure in large event/log tables. Those findings remain visible until corrected and re-audited.

Provider expansion

The federation and onboarding framework already recognizes additional providers and application patterns. Microsoft Entra ID, Active Directory, generic LDAP, Google Workspace, GitHub Enterprise, Canvas, Shibboleth, CAS, and generic OAuth patterns remain declared or templated until live configuration and proof advance their maturity.

Next high-value milestones

  1. Complete the real password-origin, real write, and rollback proof sequence without broadening blast radius.
  2. Resolve and re-audit current database schema and maintenance findings.
  3. Build a dedicated GitHub Enterprise SCIM destination adapter with organization/team mapping, lifecycle semantics, retries, reconciliation, and enterprise proof.
  4. Advance future providers through declared, configured, reachable, authenticated, read-capable, write-capable, and production-proven maturity only as evidence supports each step.
  5. Keep OIN work labeled as preparation until an external certification or marketplace milestone actually exists.

Use the live truth ledger

Runtime Truth is the public reference for the current boundary between implemented, governed, needs-attention, and roadmap functionality.