Skip to main content

13 docs tagged with "entra"

View all tags

ADR-023: Authentication Target Architecture

Target authentication architecture for SecurityV0 — portal UI, API, and infrastructure access. Three IdPs (GitHub at L1 perimeter, WorkOS at L2 application, Entra at L3 Azure RBAC), four SSH tiers including a narrow Tier-1.5 emergency key, an Active subscription-Owner Entra account (no PIM, no backup SP — 2nd-human-Owner is the rollback) with Security Defaults MFA-on-sign-in.

Azure Integration — W1

Azure identity-plane integration specification supporting W1 (Agentic AI Exposure Discovery & Assessment)

Execution Evidence Fidelity

Honest per-connector accounting of how SecurityV0 derives execution counts, where those numbers match ground truth, and where they don't.

Execution Evidence Linkage Plan

Plan to wire execution evidence end-to-end: surface stored execution_evidence nodes via API + UI drilldown, and convert dangling ServiceNow execution refs into first-class evidence entities.

Jira Integration

Jira integration reference for SecurityV0 — Microsoft + Jira NHI access chain discovery

Recovery-credential patterns

Design patterns for recovery service principals — lessons from the 2026-05-13 cancelled sv0-azure-backup-owner SP. Reference for the NEXT time a recovery SP is genuinely warranted.