Release
Release 3 — Regulated and air-gapped operations
Goal
Extend the existing organization roles and OIDC mappings for least-privilege enterprise administration and timely deprovisioning.
Scope
- Add permissions for policy, intelligence feeds, accepted-risk approval, VEX publication, evidence export, audit access, retention, and identity administration.
- Allow organization roles to be composed from supported permissions while keeping current roles as migration-safe presets.
- Add SCIM 2.0 user and group provisioning/deprovisioning.
- Preserve OIDC claim/group mapping and a tested emergency local administrator path.
- Audit all role, permission, SCIM, and break-glass changes.
Acceptance criteria
- Existing owner/admin/editor/viewer assignments preserve their effective access after migration.
- Deprovisioned users lose active organization access promptly.
- No user can approve their own risk-reduction decision.
- Break-glass authentication can be restricted, tested, and audited.
- SCIM retries and duplicate requests are idempotent.
Release
Release 3 — Regulated and air-gapped operations
Goal
Extend the existing organization roles and OIDC mappings for least-privilege enterprise administration and timely deprovisioning.
Scope
Acceptance criteria