Proven

Demonstrated end to end with a current operational result.

Operational

Implemented and used with documented controls and constraints.

Governed

Implemented behind policy, approval, or environment enablement.

Portable pattern

Reusable architecture that still earns proof in each new environment.

Proof chain

“Proven” means the action survives contact with reality.

A route existing is not enough. The correct authority, safe execution, observable result, and recovery posture all matter.

IntentPolicyExecuteObserveProve
Detailed record

The executive atlas is backed by the full technical matrix.

Every row preserves the exact status, operating boundary, and proof requirement behind the visual summary.

DomainCurrent capabilityStatusProof and boundary
SCIM usersDiscovery, create, read, replace, patch, active-state disable, filters, paging, structured errors, and replay-safe behavior.ProvenStandard SCIM transactions backed by FreeIPA-aware mapping and correlated evidence.
Password convergenceAuthorized password delivery in memory, policy checks, guarded FreeIPA write, and downstream Linux login validation.ProvenPlaintext is never persisted, echoed, or logged.
SAML SSOAuthentication, MFA handoff, ACS validation, role mapping, sessions, logout, readiness, and diagnostics.ProvenHuman login remains distinct from machine provisioning.
OIDCRP and broker integration, discovery, JWKS, authorization-code security controls, role mapping, and session evidence.OperationalEnvironment policy decides which path is enabled.
FreeIPA controlUsers, groups, HBAC, host groups, directory health, bounded operations, and Linux enforcement evidence.ProvenFreeIPA remains the Linux authorization and Kerberos/POSIX authority.
Foreman and PuppetHost/interface inventory, MAC enrichment, Puppet facts, host groups, fleet readiness, dry-run import, and backups.OperationalReviewed enrichment never silently overwrites workstation truth.
Classroom operationsRoom and seat views, health, per-seat WoL, reboot, power-off, reasons, probes, and policy gates.ProvenPower paths are scoped per workstation and relay authority.
Remote consoleGuacamole SSH/VNC plans, tokenized launch URLs, dedicated jump relays, VNC activation, and audit trails.OperationalLaunchability is evaluated from the actual jump vantage point.
TopologyLiving graph for identity, directory, Foreman, storage, relays, rooms, workstations, protocols, health, and evidence.ProvenConfigured, inferred, cached, and live states remain labeled.
Living ERDRuntime schema inventory and relationship visualization tied to the active platform model.OperationalOperators are not dependent on a stale static diagram.
Observability and securityApplication, SSO, OIDC, login, SSH, host, remote-session, threat, system, and error evidence with remediation.ProvenSecrets, assertions, cookies, keys, and plaintext credentials are excluded or redacted.
Database controlHealth, schema audit, migration preview, approvals, backups, retention, guarded pruning, vacuum/analyze, and survivability.OperationalDestructive SQL is blocked from the safe apply path.
Move from status to experience

Choose the control plane you want to inspect.

Trace identity convergence, walk the topology, operate a workstation path, investigate security evidence, or examine governed database maintenance.