Authentication, Authorization, and Tenant Context
Verified identity registration, endpoint policy boundaries, tenant resolution, and monolith authorization checks.
Verified identity registration, endpoint policy boundaries, tenant resolution, and monolith authorization checks.
Access classifications for public, customer, partner, internal, and restricted documentation.
Public-safe authentication, authorization, tenant isolation, identity context, and responsibility boundaries for Employee Service.
Verified identity-context extraction, UI access presentation and service authorization gaps.
Public-safe practices for operating and integrating with HR Suit identity, tokens, sessions, and tenant-aware access.
Source-backed authentication posture of the Notification API, covering the anonymous native surface and the authorized compatibility controllers.
Source-backed authorization posture of the Notification API, including ownership checks on the compatibility surface and their absence on the native surface.
Verified authentication and authorization posture of the Notification Service, including the absence of in-service enforcement.
Verified UI visibility, protected-route checks and backend authorization boundaries.
Public-safe security and governance expectations for platform and tenant administration.
Public-safe overview of authentication, authorization, tenant-aware access, sessions, auditing, and secret handling.
Verified control evidence and unimplemented legal scheduling controls.