Evidence ceiling E3Proof boundary

ENTERPRISE ONBOARDING

Bind the institution without surrendering institutional control.

Finality stores configuration and evidence references, not raw customer private keys or raw connector secrets. High-risk external bindings require distinct approvals, and production activation stays false until the customer-owned dependencies are actually present.

Integration surfaces

Customer-owned dependencies stay customer-owned

The onboarding contract separates configuration readiness from externally observed operation.

01

Identity

OIDC / SAML configuration · HTTPS issuer/metadata · PKCE/signed assertions · no raw secrets

02

Lifecycle

SCIM 2.0 Users + Groups · tenant-bound ETags · deactivation removes group membership

03

Key custody

Customer KMS/HSM key reference · rotation policy · non-exportable private keys · dual approval for external activation

04

Authoritative sources

HTTPS endpoint reference · secret reference · connectivity verification hash · external evidence reference

05

Telemetry

SIEM / OpenTelemetry endpoint binding · secret reference · external connectivity evidence

06

Service credentials

Scoped · expiring · hashed at rest · secret returned once · revocable

07

Webhooks

HTTPS-only target · SSRF guard · secret reference · HMAC/replay/DLQ reference semantics

08

Operations

Recovery receipts · incident kill switch · hash-chained audit · redacted telemetry export

Activation APIs

Protected institutional mutations

All mutation endpoints require authenticated role/tenant authorization and remain fail-closed when the durable store is unavailable.

01

POST /api/v1/institutional/identity-connections

Bindable OIDC / SAML / SCIM configuration

02

POST /api/v1/institutional/scim/users

Tenant-scoped SCIM user lifecycle

03

POST /api/v1/institutional/scim/groups

Tenant-scoped SCIM group lifecycle

04

POST /api/v1/institutional/approvals

Dual-approval request

05

POST /api/v1/institutional/key-policies

Customer key-custody policy

06

POST /api/v1/institutional/bindings

Authoritative-source or SIEM/OpenTelemetry binding

07

POST /api/v1/institutional/service-credentials

Scoped secret-once credential

08

POST /api/v1/institutional/data-policies

Purpose/residency/retention policy

09

POST /api/v1/institutional/recovery-drills

Recovery evidence receipt

10

POST /api/v1/institutional/incidents

Incident state + high-risk stop

Example classification

Integration examples are explicitly classified

Developer examples retain the same truth boundary as the rest of the public estate.

01

Implemented read-only interface

Read-only readiness, control, release and activation-state APIs.

02

Implemented local demonstration

Seller-controlled SCIM, DPoP, approval, webhook, data-policy, audit and recovery reference semantics.

03

Future institution interface

External customer OIDC/SAML, KMS/HSM, authoritative-source, SIEM/OpenTelemetry and hidden E4 bindings after a real institution supplies them.

Public knowledge index

Search Finality Group

Protected, owner-only and legacy content is excluded.