Operational use cases

Modernize identity with the control story intact.

Atlas connects the migration, operating, and evidence workflows around the same policy and authority model—from workforce access and vendor coexistence to compartment-aware federation and disconnected operations.

Identity-platform migration

Run the incumbent and Atlas in parallel.

Large identity estates contain more than user records. Atlas inventories people, groups, nested relationships, roles, policies, applications, protocol connections, signing material, lifecycle mappings, and administrative controls.

Discover the estate

Connect read-only first; capture exact source counts, configuration versions, unresolved objects, and dependency relationships.

Map complete controls

Compare authentication, claims, group and role rules, policy conditions, session behavior, lifecycle operations, keys, and administrative boundaries.

Reconcile identities and applications

Resolve collisions and exclusions. Test source-to-Atlas-to-target behavior before treating imported records as authority.

Move by application and cohort

Observe, shadow, pilot, expand, and cut over with measurable gates and an explicit incumbent rollback route.

Atlas parallel run view showing incumbent and Atlas routing by application
Parallel runApplication-level routes · bounded cohorts · explicit rollback

Enterprise workforce ICAM

Connect proofing, authentication, access, and lifecycle.

A workforce identity becomes useful when its authoritative status, proofing, authenticators, devices, roles, application accounts, entitlements, approvals, sessions, and audit history can be operated together.

HR

Authoritative lifecycle

Ingest hire and affiliation, verify identity, issue or bind credentials, calculate access, provision accounts, and withdraw them when authority ends.

AA

Adaptive assurance

Match authenticator and session assurance to the resource, action, device, and current evidence through resource-specific assurance profiles.

GV

Governed access

Route requests to authorized approvers, enforce separation of duties, time-bound privileged access, and retain fulfillment evidence.

Mission-partner federation

Recognize the partner. Re-evaluate the request.

A partner can assert identity, authentication, mission relationship, and scoped adverse context. Atlas validates those assertions and maps them into a local decision while resource policy remains under local authority.

Partner authority

Issues a signed, audience-bound, purpose-limited assertion with minimal claims or a pseudonymous reference.

Atlas admission

Validates signature, issuer, freshness, replay, subject binding, schema, and semantic applicability.

Local enforcement

Combines admitted context with local identity, resource, mission, device, and threat policy.

Compartment principle: share only what the receiving policy needs. An adverse condition can be expressed as a minimal restriction signal. Audience and purpose controls bind its use to the approved receiving context.

Edge and DDIL operations

Continue bounded access when the enterprise is unreachable.

Atlas can pre-position a mission-scoped identity and policy package, validate local authenticators and devices, make locally authoritative decisions, and reconcile evidence after connectivity returns.

Example: forward operations

A field user authenticates with an approved credential. Atlas verifies locally available revocation and device state, evaluates the resource against the current signed mission policy, limits session duration to the offline window, and records the decision. If a required signal expires, the outcome becomes step-up, deny, or indeterminate according to that resource’s policy.

The decision receipt records which dependencies were available and which offline authority permitted the result.

Application modernization

Put modern controls in front of legacy resources.

Atlas can broker a qualified legacy protocol while presenting a modern authentication and policy path. Over time, applications can move from translated federation to native OIDC/OAuth and SCIM while preserving the enterprise identity model.

01

Catalog

Record owner, users, data classification, protocol, route, claims, lifecycle, and recovery dependencies.

02

Front

Add managed authentication, assurance, protocol validation, session policy, and centralized evidence.

03

Reduce

Remove password sprawl, excess claims, stale accounts, implicit network trust, and unmanaged keys.

04

Modernize

Move to native protocols and resource-level policy when the application release can support them.

Continuous access response

Let new evidence change the next decision.

When a subject’s session, device, privilege, threat, or mission evidence changes, Atlas can identify affected sessions and resources and apply policy-defined response.

  • InvestigateSee the observation, source, freshness, validation, confidence, affected dimensions, and projection delta.
  • RespondRequire step-up, shorten sessions, restrict actions, revoke tokens, suspend application routes, or deny under explicit policy.
  • Propagate carefullySend a signed restriction signal to eligible federated contexts while containing the incident case within its owning boundary.
  • CorrectReview false positives, retract invalid evidence, recalculate affected projections, and preserve the correction trail.

Cross-context example

A compromised device observation lowers device and session integrity for one Atlas subject. A separate application request on another network receives a scope-valid restriction signal rather than the original case file. Its policy sees a current, scope-valid restriction signal, requests a managed device and AAL3 step-up, and records the local outcome.

Trust remains contextual: the evidence stays bounded, the other application keeps local authority, and favorable access is re-established when correction or fresh evidence satisfies policy.