Flow baseline

Incoming identity events progress through decode, validation, mapping, policy checks, connector execution, and final audit emission. SCIM provisioning events and SAML access events follow separate ingress paths but converge in operator-visible evidence.

Flow phases

Inbound plane

Okta SAML -> ACS -> Signature/Claim Checks -> Session + Role Mapping
Operator access depends on SAML metadata, ACS routing, signatures, claims, and mapped roles.

Transformation plane

SCIM Bearer Token -> Schema/Filter Validation -> Attribute Mapper -> FreeIPA Connector
Provisioning requests are validated before FreeIPA/LDAP-backed state changes.

Operational invariants

Failure branching

Retries follow explicit classification: transport failures can retry after health recovers, validation failures should not replay without operator correction, and mapping failures should create a remediation task with input diff and no secret material.

Flow visibility

SAML / SCIM -> Validator -> Attribute Mapper -> Connector Adapter -> Lifecycle Telemetry -> Audit Sink
Add correlation IDs at ingress so downstream SSO, SCIM, FreeIPA, and database events are searchable and explainable.

Filtering and pagination edge behavior

Replay-safe flow pattern

Request -> Supported filter check -> startIndex/count bounds -> Deterministic list response
The public contract should stay inside implemented filters and bounded paging behavior.