02 — Capability · BC-1250.40
Customer Identity & Access Integration
Let each tenant bring its own identity provider, manage its own users and roles, and get an audit trail of who did what inside its tenant.
- Customer SSO
- Tenant Administration
- Customer IAM
In scope
- Single sign-on and directory sync per tenant
- Tenant administrator roles and user management
- Per-tenant audit logs of access and changes
Out of scope
- Workforce identity for employees (see BC-760)
- The product's authentication code itself (see BC-530)
Realized by · 0
- No product in the catalog yet.
Used in · 0
- Not yet placed on a value stream.
Build it · 2
- pattern Federated Identity via BC-1250.40.10
- stack Workforce identity stack via BC-1250.40.10
Decomposes into · 3
- BC-1250.40.10Single Sign-On IntegrationConnect each tenant to its identity provider and keep users in sync as the customer's directory changes.
- BC-1250.40.20Tenant Role AdministrationGive tenant administrators the tools to define roles, invite users and remove them without a support ticket.
- BC-1250.40.30Tenant Audit TrailRecord access and administrative changes per tenant in a form the customer can export for its own auditors.