Platform capabilities

One operating surface for the identity decision lifecycle.

Atlas brings authoritative identity, modern authentication, application federation, resource policy, lifecycle governance, session control, and evidence into a single operational model.

Universal Directory

Unify identity and preserve provenance.

Atlas represents users, groups, roles, devices, applications, entitlements, authenticators, and relationships as linked objects. Every normalized property retains its source and authority context.

  • Multiple identity sourcesLDAP and Active Directory patterns, SCIM, APIs, files, and native Atlas records can coexist.
  • Relationship-aware groups and rolesStatic membership, governed assignment, rule-derived membership, owners, and linked objects remain distinguishable.
  • Reconciliation before authorityMatches, conflicts, exclusions, and transformations are reviewed before imported state becomes authoritative.
  • Stable Atlas identifiersInternal identifiers survive source renames while source-native keys remain available for traceability.
Atlas Universal Directory studio with source and object summaries
Universal Directory StudioSources · objects · relationships · provenance

Authentication and assurance

Build journeys around required assurance.

Applications request an assurance outcome. Atlas evaluates identity proofing posture, authenticator properties, session state, and policy, then selects an eligible journey or requires step-up.

PH

Phishing-resistant

WebAuthn/FIDO2, device-bound credentials, and certificate or smart-card patterns can satisfy policy-defined assurance when deployment prerequisites are met.

MF

Multi-factor journeys

TOTP, push, password, recovery, temporary access, and enrollment controls are composed with rate limits and lockout policy.

AL

Assurance lifecycle

Track proofing, enrollment, authenticator status, revocation, device binding, session assurance, and step-up fulfillment.

Assurance boundary: Atlas can enforce configured IAL, AAL, and FAL policy patterns. The resulting deployment assurance depends on proofing, authenticator, cryptographic module, operational, and relying-party configuration; deployment evidence establishes the achieved assurance posture.

Federation and application access

Modernize protocols application by application.

Atlas acts as identity provider, authorization server, broker, service provider, or relying party under explicit trust configuration. Application routes can remain incumbent-primary, run in shadow, move by cohort, and retain rollback.

OA

OIDC and OAuth

Managed clients, redirect and grant policy, PKCE, token lifecycles, signing keys, scopes, claims, introspection, revocation, and bounded advanced profiles.

SA

SAML federation

Entity metadata, certificates, attribute contracts, encrypted or signed assertions, IdP and SP routing, and source refresh governance.

MX

Migration and coexistence

Inventory applications and connections, map controls, compare expected behavior, pilot bounded cohorts, and preserve the source route.

Open the protocol compatibility matrix

Atlas Vector Language

Policy that reads like the decision it protects.

Vector rules combine subject, resource, action, relationship, assurance, device, network, time, mission, and TrustAI evidence. A decision can return obligations such as step-up, approval, session limits, masking, or enhanced audit.

permit access to mission_plan when
  subject.clearance dominates resource.classification
  and subject.mission in resource.allowed_missions
  and authentication.aal >= 2
  and device.posture == "managed"
  and trust.projection >= 72
with step_up(aal: 3) when resource.release == "final"
deny when threat.compromise == "confirmed"
  • Typed inputsPolicies address registered claims and relationship types rather than free-form hidden features.
  • Deterministic evaluationVersioned bundles and inputs produce reviewable outcomes and reason codes.
  • Explicit precedenceDeny and hard-gate behavior is visible; missing required inputs produce the configured indeterminate or restrictive result.
  • Lifecycle governanceDraft, validate, test, approve, activate, roll back, and retain the exact evaluated version.

Lifecycle and governance

Make identity change observable and reversible.

Joiner, mover, leaver events become attributable workflows. Provisioning, approvals, role assignment, application access, certifications, and deprovisioning carry their authority and evidence.

01

Detect

Ingest the authoritative change and validate source freshness, identity binding, and schema.

02

Plan

Calculate account, group, entitlement, role, approval, and policy impacts.

03

Execute

Provision through SCIM, connectors, agents, or governed human fulfillment with idempotent state.

04

Prove

Record the request, approver authority, operations, responses, conflicts, and final reconciliation.

Sessions and devices

Access continues beyond sign-in.

Atlas maintains session assurance, device binding, token and application relationships, regional posture, activity, trust changes, and revocation state.

Continuous controls

  • Session inventory and accounting
  • Assurance and step-up state
  • Device enrollment, posture, and trust binding
  • Token revocation and application logout
  • Risk and TrustAI response workflows
  • Regional and disconnected-session handling

Evidence and operations

Show what changed and why it mattered.

An Atlas receipt connects the human-readable explanation to machine-verifiable decision inputs. Operational views expose freshness, source, validation, policy version, and unresolved evidence alongside its source context.

Observation

Who or what reported the fact, for which subject and scope, at what time.

Evaluation

Which normalized inputs, rule bundle, trust profile, and applicability gates were used.

Receipt

Verdict, reasons, obligations, digests, and the enforcement target that consumed it.