Enterprise Identity & Access Management Platform
A multi-tenant, zero-trust identity and access platform on Azure covering human, external and workload identity, authentication, layered authorization, privileged access, governance, secrets and auditability. Five decisions carry the design: a second tenant for customer identity so the boundary is structural rather than procedural; managed identity and workload identity federation so long-lived credentials are eliminated instead of rotated; three separate authorization layers, because an app role can never answer whose data a caller may touch; zero standing privileged access, with PIM as the only path rather than the preferred one; and every role, policy and Conditional Access rule deployed as code with drift reconciled daily.
27 views, each in three formats.
Open a view to read it in full. Every SVG carries its diagram source inside it, so it opens in diagrams.net fully editable with no import step; the draw.io files are the same diagrams as plain source.
-
01
System Context
Who this platform issues identity to, what it governs access to, and what it deliberately never holds.
-
02
High-Level Architecture
The path from an identity source to an authorized action, in one picture.
-
03
Identity Estate & Tenancy Model
Which classes of identity exist, and which directory each one lives in.
-
04
Layered Architecture
What depends on what, and the one dependency that points the wrong way.
-
05
Platform Component Architecture
What is actually deployed, and the small part of it that we operate.
-
06
Integration Architecture
Every way an external system touches identity, with its protocol, direction and cadence.
-
07
Tenant, Management Group & Environment Topology
Where role assignments bind, and why a development identity cannot reach production.
-
08
Authorization Layers
Four gates, four different questions — and what happens when one is skipped.
-
09
Identity & Entitlement Data Model
The state an access decision reads, and how a person joins to a permission.
-
10
Identity Data Flow
How a hire in Workday becomes an entitlement in an application, and evidence in an archive.
-
11
Identity Data Zones, Classification & Retention
What identity data exists, who owns each zone, and how long it stays.
-
12
Workforce SSO & Conditional Access
One employee sign-in, including the parts that usually do not happen.
-
13
Conditional Access Policy Matrix
Eight personas, and what each is required to prove before access is granted.
-
14
API Authorization
One API call, from client token to the row it is allowed to read.
-
15
Workload Identity Patterns
Four kinds of workload, and how each proves who it is without holding a secret.
-
16
Privileged Elevation
How an administrator obtains production rights, and how they go away again.
-
17
Joiner, Mover, Leaver
The lifecycle, including the population that has no leaver event at all.
-
18
Secret & Certificate Lifecycle
The loop that has to close without a deployment.
-
19
External Identity
A customer signing in, a partner employee reaching a corporate resource, and the line between them.
-
20
Deployment & Network Architecture
What runs where, what is private, and which failure domain belongs to whom.
-
21
Identity as Code
How an access change reaches production, and what stops a bad one.
-
22
Identity Observability & Detection
Seven signal families, and what each one causes to happen.
-
23
Access Review & Recertification
Who still needs what, decided by someone who can actually tell.
-
24
Zero-Trust Zones & Enforcement Points
Where an attacker arrives, what stops them, and what an administrator still cannot reach.
-
25
Multi-Tenant Isolation
Three layers, because each one alone has a known bypass.
-
26
Break-Glass & Identity Recovery
The path that exists precisely because every other path has failed.
-
27
Threats & Failure Modes
Eight ways this platform is degraded or attacked, and what is left over after the mitigation.
Everything as it was delivered.
These files are served exactly as they were produced — the diagram pages keep their own house style because that is the artifact, not a rendering of it.