Capability map
This capability map tracks lifecycle behavior across SAML access, SCIM users, groups, filtering, federation integrations, ITSM handoffs, and administrative controls. Each feature page explains how a protocol contract becomes an operating action across identity authorities.
Adoption sequence
- Align SAML/OIDC claims, SCIM user schema, enterprise directory patterns, and application ownership.
- Define lifecycle state ownership for create, update, disable, and reconcile actions.
- Implement filtering, grouping, and pagination with predictable client behavior.
Feature links
External integration posture
Okta is one verified provider path, not the whole platform story. The implementation also includes TeamDynamix ticket creation, webhook ingestion, ticket correlation, and dry-run execution queues. ServiceNow-class workflows fit the same ITSM handoff pattern, but should be described as integration-ready until a dedicated connector is added.
Feature verification sequence
- Users: idempotent create, update, and disable flows.
- Groups: deterministic visibility, reconciliation, and FreeIPA authority boundaries.
- Filters: bounded query cost and index-aware sort behavior.
- Admin UI: preview and audit logs before high-impact actions.