Identity & Access
Users, roles, teams and tenants. Part of the platform vertical. Legend: β done Β· π‘ in progress Β· β¬ pending.
Checklist
β Tenants
Tenant directory with create, provision and delete; provisioning is idempotent and was verified live.
β Users
Principals directory plus invitations; creation is invitation-based β there is no direct principal write.
β Organizations
Full CRUD over organizations with the org-teams UI on top.
β Teams
Team CRUD and membership management; the session context carries the active team.
β Roles & permissions
Seeded built-in catalog (Owner, Administrator, Manager, Member, Auditor) with assignments, grants and an active-role switch.
β Sessions & devices
List, revoke, revoke-all, devices and step-up; revocation is self-service β an admin fleet view is a future item.
Evidence
All six features are built, registered by the authorize service and verified live against the droplet catalog: six iam_feature_definitions rows, all available.