Five channel types

An integration is a bounded operating path, not a logo.

Each connection keeps its own trust, credentials, authority, operation, downstream result, and failure mode. Evidence can converge without secrets converging.

TRUST

Federation

SAML and OIDC validate browser authentication, claims, sessions, roles, and protocol readiness.

PROVISIONING

SCIM

User and group lifecycle, password delivery, mappings, paging, errors, and correlated evidence.

AUTHORITY

FreeIPA

Directory, Kerberos, POSIX identity, HBAC, host context, and downstream Linux enforcement.

OPERATIONS

Fleet + remote

Foreman, Puppet, jump relays, SSH, VNC, Guacamole, rooms, seats, and power readiness.

DATA

PostgreSQL

Evidence persistence, living ERD, schema audit, migrations, retention, pruning, and recovery.

Proof rule

Every external system earns its place in the platform.

FreeSCIM calls an integration proven when the trust path works, the operation is bounded, downstream state can be observed, and the evidence remains followable.

Trust valid

The correct protocol, token, key, or directory credential is configured and validated.

Scope bounded

The adapter can perform only the operation its authority and policy allow.

State observed

The downstream system exposes the result rather than requiring blind success assumptions.

Evidence linked

Request, action, outcome, blocker, and remediation context remain correlated.

No credential shortcuts

Shared visibility without shared secrets.

Okta SAML, OIDC, SCIM provisioning, FreeIPA writes, Foreman facts, Guacamole sessions, and database maintenance remain separate channels inside one accountable control plane.