SAML + OIDC
Starts, callbacks, validation, claims, role mapping, sessions, logout, and failures.
FreeSCIM correlates identity, application, host, network, remote-support, threat, and database signals into evidence an operator can act on immediately.
An incident can move across authentication, provisioning, directory, host, relay, and database boundaries without losing its request, session, actor, or evidence context.
Starts, callbacks, validation, claims, role mapping, sessions, logout, and failures.
Success, failure, HBAC, Kerberos, account state, and downstream Linux proof.
Jump path, Guacamole launches, readiness, blockers, and ownership.
Repeated failures, malformed requests, source patterns, confidence, and containment context.
Mappings, provisioning outcomes, password-presence flags, retries, drift, and errors.
Service readiness, migrations, retention, pruning, schema state, and recovery.
FreeSCIM can retain technical depth while excluding plaintext passwords, tokens, assertions, cookies, private keys, and deployment secrets.
Every meaningful event can answer what happened, who or what initiated it, which boundary was involved, what was affected, and what the operator should do next.