Accounts
Human identity, profiles, account state, administrative identities, groups, and platform-level authority.
GoreeCloud Integral Platform System
GoreeCloud Identity is the platform authority for identities, authentication, authorization, accounts, devices, credentials, sessions, application and service identity, and delegated authority across participating GoreeCloud systems.
Identity Center is under native development. The repository still contains a substantial authentik-derived transitional runtime, and production GoreeCloud Identity is not yet accepted.
GLAZE UI V1.3 source target. This Identity Center revision targets GLAZE UI `1.3.0` at canonical Glaze revision 8354308445da9ac35ced2b37a7f503a08a0aaf72. Stable upstream eligibility does not establish Identity Center rendered, accessibility, performance, rollback, or production acceptance.
Identity Center scope
The Identity Center is the intended user-facing and administrative surface. Capabilities remain evidence-scoped: a capability listed here is part of the approved Identity domain, not a claim that every workflow is already production-deployed.
Human identity, profiles, account state, administrative identities, groups, and platform-level authority.
Approved authentication methods including passwords where required, MFA, WebAuthn/passkeys, and interoperable identity protocols.
Platform authority and permissions while preserving application-specific ownership and domain authorization boundaries.
Trusted-device relationships, active-session visibility, expiration, revocation, and account-security context.
Application registrations, service and machine identities, standards-based integration, and carefully scoped delegation.
Identity recovery, break-glass planning, credential lifecycle, and privacy-conscious authentication and authorization auditability.
Platform principles
Private-network connectivity does not replace application authentication or authorization.
GoreeVault remains the general credential, secure-note, recovery-information, and sensitive-secret management product.
Applications continue to decide record ownership, workspace access, domain roles, and data operations unless explicitly delegated.
Only necessary identity claims should cross application boundaries; unnecessary attributes, telemetry, retention, and public exposure are minimized.
Break-glass administration and restore procedures must not depend exclusively on the failed identity service authenticating itself.
Wardveil Security, Privacy Shield, Everkeep, Glaze UI, and GoreeCloud Mesh retain their own substantive authorities.
Current implementation boundary
Website truth baseline: GoreeCloud Identity main through ddd86f636b6fb7b2036186021289c4129e02f3a5. The inherited authentik-derived runtime is transitional and is not presented as the permanent GoreeCloud Identity architecture.