27 views, in reading order. Every view ships three ways: an HTML page, an SVG that re-opens in diagrams.net fully editable, and draw.io source.
A multi-tenant, zero-trust identity and access platform on Azure covering human, external and workload identity, authentication, layered authorization, privileged access, governance, secrets and auditability. The set reads in six acts: what sits inside the boundary, how the parts fit, where identity data lives and who owns it, what happens at runtime, how it is operated, and why it is safe. Five decisions carry the whole design — a second tenant for customer identity so the boundary is structural rather than procedural (views 03 and 19); managed identity and workload identity federation so long-lived credentials are eliminated instead of rotated (view 15); three separate authorization layers because an app role can never answer whose data a caller may touch (views 08 and 25); zero standing privileged access, with PIM as the only path rather than the preferred one (view 16); and every role, policy and Conditional Access rule deployed as code with drift reconciled daily (view 21).
svg/<view>.svg or drawio/<view>.drawio in draw.io Desktop or at app.diagrams.net to edit. The SVG carries the diagram inside it, so it is both the picture and the source. This folder is self-contained — copy it whole and every link still resolves.