Skip to main content
Identity Platform Control Plane
P
Astitva Governance Plane

Admin Governance

Readonly operational posture for tenant, domain, protocol, session, token, federation, audit, and observability governance.

Readonly Surfaces
Readonly
18

Governance API surfaces visible without mutation authority

Tenants
Tenant-aware
3

Bootstrap tenant governance records

Domains
Domain-safe
4

Shared and white-label identity domains

Mutation Authority
Guarded
Blocked

/api/v1/governance/mutations

Governance Confidence Posture

The console leads with what remains controlled: readonly visibility, explicit mutation blocking, tenant-aware scope, and runtime/governance plane separation.

Readonly governance visibility
Runtime-plane authority blocked
Tenant scope preserved
Diagnostics rendered public-safe

Governance Navigation

Deterministic visibility sections for posture inspection. No production mutation workflow is rendered.

Overview
Runtime Readiness
Tenants
Domains
Branding
Redirect Policies
Runtime Policies
OIDC
Sessions
Tokens
Federation
Audit & Observability
Authorization
Roles
Permissions
Policies
Policy Evaluation
Diagnostics

Tenant Governance

Tenant posture remains readonly and diagnostics-safe.

TenantLifecycleGovernanceRuntimeIdentityVisibility
Navasoft (navasoft)active_placeholderreadonlyYesYessafe
Example Tenant Alpha (example-alpha)active_placeholderreadonlyYesYessafe
Example Tenant Beta (example-beta)active_placeholderreadonlyYesYessafe

Domain Governance

Domain ownership, routing, certificate posture, and normalized host visibility are shown without DNS or certificate workflows.

DomainTenantTypeRoutingValidationCertificate
identity.navasoft.innavasoftshared_identity_domainready_placeholdervalidatedissued_placeholder
login.navasoft.innavasoftshared_identity_domainready_placeholdervalidatedissued_placeholder
identity-alpha.example.localexample-alphawhite_label_identity_domainready_placeholdervalidatedissued_placeholder
identity-beta.example.localexample-betawhite_label_identity_domainready_placeholdervalidatedissued_placeholder

Branding Governance

Branding metadata is visible without upload or live theming controls.

ProfileTenantThemeEnabled
NavasoftnavasoftsystemYes
Example Tenant Alphaexample-alphasystemYes
Example Tenant Betaexample-betasystemYes

Redirect Policy Governance

Unsafe redirect shapes remain visibly rejected; OAuth client registration is not present.

RedirectTenantStateReason
https://identity.navasoft.in/callbacknavasoftvalidation_readybootstrap_redirect_policy_visibility_only
https://identity-alpha.example.local/callbackexample-alphavalidation_readybootstrap_redirect_policy_visibility_only
https://identity-beta.example.local/callbackexample-betavalidation_readybootstrap_redirect_policy_visibility_only

Runtime Policy Governance

PKCE-first posture and implicit-flow prohibition are rendered as readonly runtime policy evidence.

TenantPKCEImplicit FlowSessionToken LifetimeFederation
navasoftYesNoYesshort-lived-placeholderYes
example-alphaYesNoYesshort-lived-placeholderYes
example-betaYesNoYesshort-lived-placeholderYes

OIDC, Session, Token, and Federation Posture

Protocol and identity-engine posture is visible without login, signing-key, token, session, or federation execution controls.

SectionReadinessSafetyBlocked Behavior
OIDCskeleton-readonly-no-authenticationPKCE: Yesimplicit, resource_owner_password_credentials, tokens_in_query_parameters
Sessionsskeleton-readonly-no-session-mutationRevocation: Yesadmin-session-mutation-workflows, user-session-termination-workflows, browser-session-persistence, real-session-issuance, token-issuance
Tokensskeleton-readonly-no-production-token-issuanceAlgorithms: RS256, ES256production-token-issuance, refresh-token-issuance, refresh-token-rotation, production-signing-infrastructure, signing-key-crud, token-introspection-workflows, client-secret-management
Federationskeleton-readonly-no-live-federation-executionoidc-authorization-code-pkceprovider-crud-workflows, secret-management-workflows, metadata-ingestion-workflows, live-federation-administration, production-trust-exchange, social-login-execution, saml-runtime-processing

Audit & Observability Governance

Readonly propagation posture, sink warnings, and future Pramaana/Avalokana readiness.

AreaPostureDetail
AuditYesnon-production-in-memory-bootstrap
TelemetryYesreadonly-diagnostics-no-audit-mutation
PramaanaYesFuture integration readiness only
AvalokanaYesFuture integration readiness only

Authorization & Tenant Governance Contract

Readonly authorization contract posture for tenant-scoped roles, permissions, policies, Niyama readiness, and evaluation skeletons.

AreaPostureDetail
Authorization Contractreadonly-contract-ready-no-enforcementYes
Tenant ScopeYesNo
EvaluationYesSkeleton only; no request-blocking middleware
NiyamaYesFuture policy integration readiness

Role Posture

Role records are visible without assignment workflows.

RoleTenantScopeRuntime
identity_observernavasofttenantNo
identity_observerexample-alphatenantNo
identity_observerexample-betatenantNo

Permission Posture

Permission records expose scope and plane posture without entitlement execution.

PermissionScopeRuntimeGovernance
authorization.posture.readgovernanceNoYes
runtime.policy.readruntimeYesYes

Policy Posture

Policy contracts are readonly and evaluation-ready without policy editors or enforcement toggles.

PolicyTenantScopeMode
tenant_authorization_contractnavasofttenantskeleton_only_no_enforcement
tenant_authorization_contractexample-alphatenantskeleton_only_no_enforcement
tenant_authorization_contractexample-betatenantskeleton_only_no_enforcement

Policy Evaluation Contract

Deterministic tenant-scoped evaluation posture for future Niyama integration without production policy execution.

AreaPostureDetail
Evaluation ContractYesskeleton_only_no_production_execution
DeterminismYesNo
Tenant ScopeYesBlocked and unresolved outcomes are explicit
ExecutionNoNo
NiyamaYesFuture integration readiness only

Cloud Deployment Posture

Cloudflare, Route53, ALB, container, rollback, and runtime/governance separation posture rendered without infrastructure controls.

AreaPostureDetail
Ingresscloudflare-ready -> route53-ready -> aws-alb-readyCloud ingress posture ready
Deploymentlocallocal
RollbackYesContainer image rollback posture only
Runtime Separationgovernance-plane-readonly-no-runtime-authorityNo

Diagnostics Safety

Rendered diagnostics avoid secrets, tokens, session identifiers, private keys, raw cookies, and runtime-plane authority.

GuardrailState
Runtime-plane admin authorityNo
Sensitive event data exposedNo
Tokens in query parametersredacted
URL session identifiersredacted