Investigation surface

Six signal domains, one correlation model.

An incident can move across authentication, provisioning, directory, host, relay, and database boundaries without losing its request, session, actor, or evidence context.

Federation

SAML + OIDC

Starts, callbacks, validation, claims, role mapping, sessions, logout, and failures.

Login

Assurance

Success, failure, HBAC, Kerberos, account state, and downstream Linux proof.

Remote support

SSH + VNC

Jump path, Guacamole launches, readiness, blockers, and ownership.

Threat

Suspicious activity

Repeated failures, malformed requests, source patterns, confidence, and containment context.

SCIM

Lifecycle

Mappings, provisioning outcomes, password-presence flags, retries, drift, and errors.

Systems

Health + data

Service readiness, migrations, retention, pruning, schema state, and recovery.

Rich context, secret-safe

More explanation does not mean exposing more sensitive material.

FreeSCIM can retain technical depth while excluding plaintext passwords, tokens, assertions, cookies, private keys, and deployment secrets.

Actor + session

Who initiated the operation and which authenticated session carried it.

Path + asset

Which route, relay, identity, host, room, or service was involved.

Outcome + trust

Success, denial, degraded state, confidence, policy result, and downstream evidence.

Remediation + recovery

Likely owner, next inspection point, safe retry posture, and recovery direction.

Designed for remediation

Observability becomes an operating advantage.

Every meaningful event can answer what happened, who or what initiated it, which boundary was involved, what was affected, and what the operator should do next.