Identity & Access

Users, roles, teams and tenants. Part of the platform vertical. Legend: βœ… done Β· 🟑 in progress Β· ⬜ pending.

Checklist

βœ… Tenants

Tenant directory with create, provision and delete; provisioning is idempotent and was verified live.

βœ… Users

Principals directory plus invitations; creation is invitation-based β€” there is no direct principal write.

βœ… Organizations

Full CRUD over organizations with the org-teams UI on top.

βœ… Teams

Team CRUD and membership management; the session context carries the active team.

βœ… Roles & permissions

Seeded built-in catalog (Owner, Administrator, Manager, Member, Auditor) with assignments, grants and an active-role switch.

βœ… Sessions & devices

List, revoke, revoke-all, devices and step-up; revocation is self-service β€” an admin fleet view is a future item.

Evidence

All six features are built, registered by the authorize service and verified live against the droplet catalog: six iam_feature_definitions rows, all available.