Three operating lanes

Follow one action across identity, infrastructure, and the physical edge.

The graph is useful because it shortens diagnosis: it shows which layer owns the next decision and which boundary should be inspected.

IDENTITY / TRUST

Intent begins with people and protocols.

Okta, SAML, OIDC, SCIM, password convergence, role decisions, and session ownership establish who is asking for what.

INFRASTRUCTURE / AUTHORITY

Systems decide what the estate believes.

FreeIPA, DNS, Kerberos, Foreman, Puppet, storage, host identity, and relay relationships define the operational substrate.

EDGE / ACTION

The result lands on a real workstation.

Rooms, seats, WoL, SSH, VNC, Guacamole, power state, and endpoint evidence prove whether the requested outcome reached reality.

Truth model

The map labels what it knows and how it knows it.

Configured relationships, inferred expectations, current observations, and evidence-backed state are different things. FreeSCIM preserves that distinction.

Configured

Declared services, protocols, rooms, relays, and ports.

Inferred

Expected directory, Kerberos, DNS, Puppet, storage, and estate relationships.

Observed

Current probes, console readiness, blockers, health, and runtime state.

Evidence linked

Rooms, workstation actions, logs, sessions, and remediation context.

From map to action

Diagnosis becomes direction.

Choose a system, relay, room, workstation, or protocol edge; inspect the linked evidence; identify the real boundary; then move into the correct control surface.