Phishing-resistant
WebAuthn/FIDO2, device-bound credentials, and certificate or smart-card patterns can satisfy policy-defined assurance when deployment prerequisites are met.
Platform capabilities
Atlas brings authoritative identity, modern authentication, application federation, resource policy, lifecycle governance, session control, and evidence into a single operational model.
Universal Directory
Atlas represents users, groups, roles, devices, applications, entitlements, authenticators, and relationships as linked objects. Every normalized property retains its source and authority context.

Authentication and assurance
Applications request an assurance outcome. Atlas evaluates identity proofing posture, authenticator properties, session state, and policy, then selects an eligible journey or requires step-up.
WebAuthn/FIDO2, device-bound credentials, and certificate or smart-card patterns can satisfy policy-defined assurance when deployment prerequisites are met.
TOTP, push, password, recovery, temporary access, and enrollment controls are composed with rate limits and lockout policy.
Track proofing, enrollment, authenticator status, revocation, device binding, session assurance, and step-up fulfillment.
Federation and application access
Atlas acts as identity provider, authorization server, broker, service provider, or relying party under explicit trust configuration. Application routes can remain incumbent-primary, run in shadow, move by cohort, and retain rollback.
Managed clients, redirect and grant policy, PKCE, token lifecycles, signing keys, scopes, claims, introspection, revocation, and bounded advanced profiles.
Entity metadata, certificates, attribute contracts, encrypted or signed assertions, IdP and SP routing, and source refresh governance.
Inventory applications and connections, map controls, compare expected behavior, pilot bounded cohorts, and preserve the source route.
Atlas Vector Language
Vector rules combine subject, resource, action, relationship, assurance, device, network, time, mission, and TrustAI evidence. A decision can return obligations such as step-up, approval, session limits, masking, or enhanced audit.
permit access to mission_plan when
subject.clearance dominates resource.classification
and subject.mission in resource.allowed_missions
and authentication.aal >= 2
and device.posture == "managed"
and trust.projection >= 72
with step_up(aal: 3) when resource.release == "final"
deny when threat.compromise == "confirmed"Lifecycle and governance
Joiner, mover, leaver events become attributable workflows. Provisioning, approvals, role assignment, application access, certifications, and deprovisioning carry their authority and evidence.
Ingest the authoritative change and validate source freshness, identity binding, and schema.
Calculate account, group, entitlement, role, approval, and policy impacts.
Provision through SCIM, connectors, agents, or governed human fulfillment with idempotent state.
Record the request, approver authority, operations, responses, conflicts, and final reconciliation.
Sessions and devices
Atlas maintains session assurance, device binding, token and application relationships, regional posture, activity, trust changes, and revocation state.
Evidence and operations
An Atlas receipt connects the human-readable explanation to machine-verifiable decision inputs. Operational views expose freshness, source, validation, policy version, and unresolved evidence alongside its source context.
Who or what reported the fact, for which subject and scope, at what time.
Which normalized inputs, rule bundle, trust profile, and applicability gates were used.
Verdict, reasons, obligations, digests, and the enforcement target that consumed it.