Admin · Identity · Configuration
How access is decided.
Federated trust, session and MFA policy, and the platform configuration that bounds autonomy. Changes here are gated by a policy change and land on the audit ledger. This page is a preview: controls are presentational.
Federated identity providers
identity trust · distinct from network federation| Provider | Protocol | Trust | Direction | Cert fingerprint | Cert expiry |
|---|---|---|---|---|---|
| NaaS Labs IdPacct-naas | oidc | trusted | bidirectional | sha256:412d91ef… | expired |
| Northwind IdPacct-northwind | saml | trusted | inbound | sha256:3c552dd3… | expired |
| Beacon Digital IdPacct-beacon | oidc | trusted | inbound | sha256:1332229a… | expired |
| Meridian IdPacct-meridian | oidc | trusted | bidirectional | sha256:1e473fc5… | expired |
| Harbor Grain Networks | saml | probationary | inbound | sha256:aa63da13… | expired |
| Aurora Transit IdPacct-aurora | oidc | trusted | bidirectional | sha256:e608c4d6… | 29d left |
Cert rotation CHG-5102
Session, password & MFA policy
simulatedSystem configuration
5 keys| Key | Value | Scope | Description |
|---|---|---|---|
| breakGlass.maxDurationMinutes | 240 | platform | Maximum break-glass grant duration. |
| breakGlass.requireApprover | true | platform | Second approver required to open a grant. |
| change.requirePolicyGate | true | platform | No change goes live without a named gate. |
| notifications.floorEnforced | true | platform | Security + incident alerts cannot be muted. |
| agentic.autonomyEnabled | false | platform | Master switch for agentic execution (advisory policy). |