GoreeCloud IdentityIdentity Center

GoreeCloud Integral Platform System

One identity.
Clear authority everywhere.

GoreeCloud Identity is the platform authority for identities, authentication, authorization, accounts, devices, credentials, sessions, application and service identity, and delegated authority across participating GoreeCloud systems.

Identity Center is under native development. The repository still contains a substantial authentik-derived transitional runtime, and production GoreeCloud Identity is not yet accepted.

GLAZE UI V1.3 source target. This Identity Center revision targets GLAZE UI `1.3.0` at canonical Glaze revision 8354308445da9ac35ced2b37a7f503a08a0aaf72. Stable upstream eligibility does not establish Identity Center rendered, accessibility, performance, rollback, or production acceptance.

Identity Center scope

A coherent identity layer for people, devices, apps, and services.

The Identity Center is the intended user-facing and administrative surface. Capabilities remain evidence-scoped: a capability listed here is part of the approved Identity domain, not a claim that every workflow is already production-deployed.

01

Accounts

Human identity, profiles, account state, administrative identities, groups, and platform-level authority.

02

Authentication

Approved authentication methods including passwords where required, MFA, WebAuthn/passkeys, and interoperable identity protocols.

03

Authorization

Platform authority and permissions while preserving application-specific ownership and domain authorization boundaries.

04

Devices + sessions

Trusted-device relationships, active-session visibility, expiration, revocation, and account-security context.

05

Apps + services

Application registrations, service and machine identities, standards-based integration, and carefully scoped delegation.

06

Recovery + audit

Identity recovery, break-glass planning, credential lifecycle, and privacy-conscious authentication and authorization auditability.

Platform principles

Single sign-on must not collapse security boundaries.

Identity is not Network

Private-network connectivity does not replace application authentication or authorization.

Identity is not GoreeVault

GoreeVault remains the general credential, secure-note, recovery-information, and sensitive-secret management product.

Apps retain domain ownership

Applications continue to decide record ownership, workspace access, domain roles, and data operations unless explicitly delegated.

Privacy by default

Only necessary identity claims should cross application boundaries; unnecessary attributes, telemetry, retention, and public exposure are minimized.

Recovery is independent

Break-glass administration and restore procedures must not depend exclusively on the failed identity service authenticating itself.

Integral systems stay independent

Wardveil Security, Privacy Shield, Everkeep, Glaze UI, and GoreeCloud Mesh retain their own substantive authorities.

Current implementation boundary

Native Identity work is real. Production identity remains a separate acceptance gate.

Current GoreeCloud-owned work

  • Native Identity authority and platform-integration contracts
  • GoreeCloud-owned Mesh evidence schema/profile and delivery client
  • Strict producer binding and cross-domain evidence restrictions
  • HTTPS-only non-loopback delivery policy and redirect refusal
  • Credential non-disclosure and receipt-binding regression tests
  • Native-build guardrails around the transitional inherited tree

Still required before production acceptance

  • Complete native Identity Center and approved production runtime boundaries
  • Protected signing/JWKS/key custody and production service-token issuance
  • Validated authentication, authorization, session, MFA, passkey, and recovery workflows for the approved scope
  • Break-glass, backup, restore, monitoring, and rollback evidence
  • Controlled application integration and failure-mode acceptance
  • GLAZE UI V1.3 consumer acceptance plus current Wardveil, Privacy Shield, and Everkeep acceptance and explicit production approval

Website truth baseline: GoreeCloud Identity main through ddd86f636b6fb7b2036186021289c4129e02f3a5. The inherited authentik-derived runtime is transitional and is not presented as the permanent GoreeCloud Identity architecture.