Tenant-scoped identities
User names and external identifiers remain unique inside the owning tenant.
Create tenant-bound users and groups, enforce versioned lifecycle changes, remove inactive identities from group authority, and preserve audit evidence.
User names and external identifiers remain unique inside the owning tenant.
Stale lifecycle updates are rejected instead of overwriting newer state.
A deprovisioned identity cannot silently return to active status.
Suspension and deprovisioning automatically remove group membership.
Each consequential action moves through the same six control points. See where 2AYE evaluates authority, requests human review, and preserves the outcome.
Document the environment, threat model, and integration boundary.
Select protocols, signals, policies, and failure behavior.
Test vendor-specific APIs, tenant isolation, and abuse paths.
Mark available only after deployed end-to-end verification.