Identity and provisioning
SAML, OIDC, SCIM, service identities, revocable sessions, invitations, groups, and lifecycle controls.
Trust architecture
Identity, authorization, residency, audit, and AI approval are platform planes with enforceable contracts—not optional UI settings.
SAML, OIDC, SCIM, service identities, revocable sessions, invitations, groups, and lifecycle controls.
Tenant, workspace, application, model, and document relations combine with specialized cell-access evaluation.
Tenant encryption contexts, customer-managed key references, vault-backed secrets, and explicit rotations.
Planning data and AI context stay in assigned regions with tiered cell, namespace, cluster, or sovereign isolation.
Governed intelligence
Agents receive typed tools and governed context. Any production mutation becomes a reviewable proposal with actor, inputs, outputs, approvals, and rollback.