Skip to content

Feature: Add fine-grained permissions and SCIM provisioning #309

Description

@JustNZ

Release

Release 3 — Regulated and air-gapped operations

Goal

Extend the existing organization roles and OIDC mappings for least-privilege enterprise administration and timely deprovisioning.

Scope

  • Add permissions for policy, intelligence feeds, accepted-risk approval, VEX publication, evidence export, audit access, retention, and identity administration.
  • Allow organization roles to be composed from supported permissions while keeping current roles as migration-safe presets.
  • Add SCIM 2.0 user and group provisioning/deprovisioning.
  • Preserve OIDC claim/group mapping and a tested emergency local administrator path.
  • Audit all role, permission, SCIM, and break-glass changes.

Acceptance criteria

  • Existing owner/admin/editor/viewer assignments preserve their effective access after migration.
  • Deprovisioned users lose active organization access promptly.
  • No user can approve their own risk-reduction decision.
  • Break-glass authentication can be restricted, tested, and audited.
  • SCIM retries and duplicate requests are idempotent.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions