Proven now
- SCIM lifecycle and conformance behavior.
- Canonical identity provenance and attribute authority modeling.
- Observe and dry-run controlled execution.
- Linux trust, Kerberos, SSSD/PAM, HBAC, and controlled login validation.
- Sync comparison, drift, audit, read-only replay, and operator evidence.
- Landing, FreeIPA, Okta, Sync, Mapping, and Admin operational dashboards.
Still behind a gate
- Real identity-provider password-origin proof.
- Real FreeIPA password write through the governed password path.
- Post-write rollback proof.
- Broad password sync, profile attribute writes, profile sourcing, bulk execution, and automatic drift remediation.
- OIDC promotion beyond its environment-gated role.
- Live TeamDynamix ticket creation and other dedicated ITSM connectors.
Needs runtime attention
Database governance and maintenance tooling are implemented, but the latest runtime audit reports missing expected schema objects, an index finding, and storage pressure in large event/log tables. Those findings remain visible until corrected and re-audited.
Provider expansion
The federation and onboarding framework already recognizes additional providers and application patterns. Microsoft Entra ID, Active Directory, generic LDAP, Google Workspace, GitHub Enterprise, Canvas, Shibboleth, CAS, and generic OAuth patterns remain declared or templated until live configuration and proof advance their maturity.
Next high-value milestones
- Complete the real password-origin, real write, and rollback proof sequence without broadening blast radius.
- Resolve and re-audit current database schema and maintenance findings.
- Build a dedicated GitHub Enterprise SCIM destination adapter with organization/team mapping, lifecycle semantics, retries, reconciliation, and enterprise proof.
- Advance future providers through declared, configured, reachable, authenticated, read-capable, write-capable, and production-proven maturity only as evidence supports each step.
- Keep OIN work labeled as preparation until an external certification or marketplace milestone actually exists.
Use the live truth ledger
Runtime Truth is the public reference for the current boundary between implemented, governed, needs-attention, and roadmap functionality.