On this page
WP-07 Identity and Access Management (IAM)
Summary
Deliver centralized identity and authorization for users and services across the platform.
Scope
- Deliver centralized identity provider and single sign-on integration for platform entry points.
- Standardize RBAC role templates and tenant authorization boundaries.
- Define lifecycle workflows for onboarding, privilege elevation, and deprovisioning.
Architecture Context
- Domain architecture index: Security Architecture
- OpenShift runtime context where relevant: Platform Architecture
Decision Context
Dependencies
Acceptance Criteria
- Federated Authentication is enabled for primary portal and CLI entry points in scope, with documented exceptions.
- RBAC matrices per tenant are automated and enforced.