Admin

Admin · Identity · Configuration

How access is decided.

Federated trust, session and MFA policy, and the platform configuration that bounds autonomy. Changes here are gated by a policy change and land on the audit ledger. This page is a preview: controls are presentational.

Federated identity providers

identity trust · distinct from network federation
ProviderProtocolTrustDirectionCert fingerprintCert expiry
NaaS Labs IdPacct-naasoidctrustedbidirectionalsha256:412d91ef…expired
Northwind IdPacct-northwindsamltrustedinboundsha256:3c552dd3…expired
Beacon Digital IdPacct-beaconoidctrustedinboundsha256:1332229a…expired
Meridian IdPacct-meridianoidctrustedbidirectionalsha256:1e473fc5…expired
Harbor Grain Networkssamlprobationaryinboundsha256:aa63da13…expired
Aurora Transit IdPacct-auroraoidctrustedbidirectionalsha256:e608c4d6…29d left
Cert rotation CHG-5102

Session, password & MFA policy

simulated

Password complexity is enforced at the federated IdP layer (see roster above). The knobs below bound sessions, MFA grace, and break-glass. Controls are disabled: changes require a policy change ticket.

Re-auth required after this window.
Idle lockout for privileged sessions.
Grace before MFA blocks privileged actions.
Upper bound on an emergency grant.
Simulated write

System configuration

5 keys
KeyValueScopeDescription
breakGlass.maxDurationMinutes240platformMaximum break-glass grant duration.
breakGlass.requireApprovertrueplatformSecond approver required to open a grant.
change.requirePolicyGatetrueplatformNo change goes live without a named gate.
notifications.floorEnforcedtrueplatformSecurity + incident alerts cannot be muted.
agentic.autonomyEnabledfalseplatformMaster switch for agentic execution (advisory policy).