{"version":"0.2.0","built_at":"2026-10-10T20:58:14.188Z","license":"CC BY 4.0 © Mike Reams","canonical":"https://catalog.mikereams.com","capability":{"id":"BC-1250.40","name":"Customer Identity & Access Integration","level":2,"parent_id":"BC-1250","l1_id":"BC-1250","industry":"software","macro_id":null,"path":["Subscription & Tenant Operations","Customer Identity & Access Integration"],"description":"Let each tenant bring its own identity provider, manage its own users and roles, and get an audit trail of who did what inside its tenant.","aliases":["Customer SSO","Tenant Administration","Customer IAM"],"in_scope":["Single sign-on and directory sync per tenant","Tenant administrator roles and user management","Per-tenant audit logs of access and changes"],"out_of_scope":["Workforce identity for employees (see BC-760)","The product's authentication code itself (see BC-530)"],"csdm_note":null,"status":"active","successor_id":null,"child_ids":["BC-1250.40.10","BC-1250.40.20","BC-1250.40.30"]},"crosswalk":{"realized_by":[],"used_in":[],"patterns":[{"id":"DP-360","name":"Federated Identity","category":"Security","via":"BC-1250.40.10"}],"stacks":[{"id":"TS-080","name":"Workforce identity stack","layer":"Identity","via":"BC-1250.40.10"}],"books":[]},"ancestors":[{"id":"BC-1250","name":"Subscription & Tenant Operations","level":1}],"children":[{"id":"BC-1250.40.10","name":"Single Sign-On Integration","level":3,"child_count":0},{"id":"BC-1250.40.20","name":"Tenant Role Administration","level":3,"child_count":0},{"id":"BC-1250.40.30","name":"Tenant Audit Trail","level":3,"child_count":0}]}