Identity
OIDC / SAML configuration · HTTPS issuer/metadata · PKCE/signed assertions · no raw secrets
ENTERPRISE ONBOARDING
Finality stores configuration and evidence references, not raw customer private keys or raw connector secrets. High-risk external bindings require distinct approvals, and production activation stays false until the customer-owned dependencies are actually present.
Integration surfaces
The onboarding contract separates configuration readiness from externally observed operation.
OIDC / SAML configuration · HTTPS issuer/metadata · PKCE/signed assertions · no raw secrets
SCIM 2.0 Users + Groups · tenant-bound ETags · deactivation removes group membership
Customer KMS/HSM key reference · rotation policy · non-exportable private keys · dual approval for external activation
HTTPS endpoint reference · secret reference · connectivity verification hash · external evidence reference
SIEM / OpenTelemetry endpoint binding · secret reference · external connectivity evidence
Scoped · expiring · hashed at rest · secret returned once · revocable
HTTPS-only target · SSRF guard · secret reference · HMAC/replay/DLQ reference semantics
Recovery receipts · incident kill switch · hash-chained audit · redacted telemetry export
Activation APIs
All mutation endpoints require authenticated role/tenant authorization and remain fail-closed when the durable store is unavailable.
Bindable OIDC / SAML / SCIM configuration
Tenant-scoped SCIM user lifecycle
Tenant-scoped SCIM group lifecycle
Dual-approval request
Customer key-custody policy
Authoritative-source or SIEM/OpenTelemetry binding
Scoped secret-once credential
Purpose/residency/retention policy
Recovery evidence receipt
Incident state + high-risk stop
Example classification
Developer examples retain the same truth boundary as the rest of the public estate.
Read-only readiness, control, release and activation-state APIs.
Seller-controlled SCIM, DPoP, approval, webhook, data-policy, audit and recovery reference semantics.
External customer OIDC/SAML, KMS/HSM, authoritative-source, SIEM/OpenTelemetry and hidden E4 bindings after a real institution supplies them.