North-star: docs/architecture/identity-and-access-strategy.md — the workforce-first identity & access strategy.
Build the unified model in phases: decide a principal's access once (who × what-they're-on × policy) → derive → project into every system from one git source of truth (gitops/teams + new gitops/people + Grants). Everyday access is standing; dangerous power is borrowed temporarily; auth strength scales with role; the scale-hardening (strategy §3) is owned honestly.
Phase 1 — the foundation (build now)
Build order: MFA first, then the registry → catalog → {both generators} → templates.
Later
- P2 GitHub org-team membership connector · P3 temporary-power front door + emergency revocation · P4 PagerDuty/Slack connectors + live on-call · scale-hardening tracker (drift detection · access reviews · governance observability).
Builds on / dedup (link, don't duplicate)
CIAM (customer/end-user identity) is a named, deliberately-deferred plane.
North-star:
docs/architecture/identity-and-access-strategy.md— the workforce-first identity & access strategy.Build the unified model in phases: decide a principal's access once (who × what-they're-on × policy) → derive → project into every system from one git source of truth (
gitops/teams+ newgitops/people+ Grants). Everyday access is standing; dangerous power is borrowed temporarily; auth strength scales with role; the scale-hardening (strategy §3) is owned honestly.Phase 1 — the foundation (build now)
Build order: MFA first, then the registry → catalog → {both generators} → templates.
gitops/people/schema + gateLater
Builds on / dedup (link, don't duplicate)
CIAM (customer/end-user identity) is a named, deliberately-deferred plane.