SECURITY & IDENTITY

Your infrastructure. Your users. Your keys.

Connect identity, control access and inspect operational evidence on infrastructure you own.

WHAT IT SOLVES

Identity belongs to your organization.

Connect OIDC authentication and provision users and groups with SCIM. Enforce MFA at your identity provider; OpsKnight does not provide a native server-verified second factor.

Understand the capability
01OIDC and SCIM 2.0
02Role and resource authorization
03Session registry and audit events
OPSKNIGHT / PRODUCT VIEW Northstar Systems · v2.0.0
OpsKnight security & identity product view
OpsKnight security & identity product view

HOW IT WORKS

A concrete operational path, not a feature list.

CONTROL ARCHITECTUREAuthentication, provisioning, authorization, sessions, and evidence remain separate controls.
01OIDC / PKCE
02SCIM 2.0
03RBAC / Auditor
04Session registry
05Audit events
Identity providerLeast privilegeRevocation + evidence

EXPLORE A WORKFLOW

  1. 01OIDC provider
  2. 02PKCE / sign-in
  3. 03JIT or SCIM
  4. 04Effective role

Authentication, provisioning and authorization are separate controls. Validate the effective role after identity mapping.

OPERATIONAL DEPTH

Security & identity, beyond the happy path.

The details below are the parts teams need when evaluating how the capability behaves during real response, failure, and handoff.

01

Access is an operational control.

Review roles, scoped authorization and session behavior. Provisioning and deprovisioning should be verified against the effective product permissions.

Read the operational guide
02

Keys and infrastructure have an owner.

Configure secrets, network access, HTTPS and recovery for your deployment. Preserve required encryption keys separately from database backups and follow the key-rotation guide.

Read the operational guide
03

Prepare evidence for your evaluation.

Use the security and procurement entry point for release policies, vulnerability handling, SBOM scope, supported versions and shared responsibility. These materials do not confer external certification.

Read the operational guide

KNOW BEFORE PRODUCTION

Validate the boundary, not just the happy path.

Use a test service and representative provider configuration before treating security & identity as production incident infrastructure.

  1. 01Pilot allowed, denied, deactivated, and existing-account identity cases.
  2. 02Verify effective RBAC, session revocation, and audit evidence after provisioning.
  3. 03Preserve required encryption keys outside database backups and test recovery.
DOCUMENTATIONSetup, authorization, limits, and troubleshooting.
Explore security & identity documentation

Your incidents should belong to you.

Run OpsKnight on infrastructure you control.

v2.0.0 · AGPL-3.0-only · Self-hosted · 28 inbound integrations