IDENTITY

Access follows organizational identity

SSO and SCIM are enterprise capabilities enabled only after the specific provider and contract are verified.

Evidence snapshot: 2026-09-06 · review by 2026-09-20 · partial_read_only

Controls

Role-based accessEarly Access

Owner, Admin, Member, and Viewer roles bound administrative and workspace actions.

Production multi-tenant pilot pending.
Scope
business_enterprise
Evidence
docs/business/rbac-matrix.md
SSOBeta

Enterprise identity federation is configured for a specific provider.

Production IdP registration and acceptance are deployment-specific.
Scope
enterprise_deployment_specific
Evidence
docs/enterprise/sso-scim.md
SCIMEarly Access

The provisioning interface requires validation against the customer directory.

Customer conformance and directory validation pending.
Scope
enterprise_deployment_specific
Evidence
docs/enterprise/sso-scim.md

Deployment profiles

SaaSBeta

A Wicsora-managed deployment with no published HA or SLA guarantee.

Current single-site runtime is not HA/SLA evidence.
Region
deployment_specific
Evidence
docs/enterprise/deployment-profiles.md
On-PremBeta

Customer-environment packaging with outbound access denied by default.

Signed artifacts and a customer restore drill are still required.
Region
customer_environment
Evidence
docs/enterprise/deployment-profiles.md;deploy/onprem

Evidence snapshot: 2026-09-06 · review by 2026-09-20 · partial_read_only