Constitutional Dual-Realm Identity
Exactly one workforce realm and one CIAM realm per CRTL tenant. Realm isolation is architecture, not configuration. Bootstrap, JML, and visitor-to-customer lifecycles each emit realm-scoped ProvenanceFrame events.
Multi-Model Access Control
RBAC, ABAC, CBAC, ReBAC, TBAC, and PoRBAC in one engine. Purpose-of-request capture lands in the ProvenanceFrame purpose field. Policy-at-time-T replay reconstructs historical authorization graphs for audit queries.
ProvenanceFrame Event Spine
Canonical evidence wrapper on every timeline-x event: actor, origin, product, action, target, result, regulatory tags, retention class, and causal linkage via caused_by_event_id. CBOR byte authority, protobuf internal wire, JSON operator projection.
11-Point Event Backbone
Actor, actor class, origin, session ID, login ID, product, subsystem, action, action target, action magnitude, and result — populated on every log, metric exemplar, and trace span or marked with typed not-applicable reasons.
EvidenceEnvelopeV1 Signing Layer
ES256, RS256, ED25519, ML-DSA-65, SLH-DSA-SHA2-192s, and hybrid composite signatures. Key rotation and revocation ceremonies are themselves evidentially recorded. Three composable evidence tiers: software, HSM-backed, hardware-attested.
Merkle Anchoring & Witness Cosigning
Per-realm RFC 6962/9162 Merkle logs with signed tree heads at write, second, and minute cadences. Consistency proofs chain STH history. Optional Sigsum-pattern witness cosigning and public blockchain anchoring.
RFC 3161 Timestamp Authority
External QTSP client for connected deployments. Locally-hosted RFC 3161 responder for air-gapped sites with GPS-disciplined time and HSM-signed TST tokens. Every published STH carries counter-signed temporal proof.
WORM & Retention Enforcement
Hot fs-verity, warm object-lock, cold LTO-9 WORM tiers. Per-event-class retention aligned to SOX, HIPAA, FDA Part 11, eIDAS, GDPR, FedRAMP, and PCI-DSS defaults. MOIRA reactive rules execute daily retention sweeps.
Legal Hold & Cross-Realm Scope
Dual-approval legal hold suspends retention enforcement per realm, principal, event class, or time window. Hold application and release are signed timeline-x events bounded by CrossRealmDelegation attributes.
Universal Federation Gateway
SAML 2.0 IdP and SP, LDAP/AD with SASL and upstream connector, SCIM v2 REST with filter and ETag semantics, OIDC/OAuth2 with PKCE, DCR, CIBA, and logout profiles, RADIUS EAP-TLS and MS-CHAPv2, plus six-provider social login with claim-mapping DSL.
B2B SSO Broker & Cross-Realm Trust
FederationDomain, CrossRealmTrust, FederationParty, and ExternalIdPBinding primitives. Multi-tenant broker sessions with isolated trust anchors. Cross-realm assertion mint and verify with Part 2 policy hooks.
Credential & Session Hardening
Argon2id passwords, RFC 6238 TOTP with replay protection, FIDO2/WebAuthn passkeys with attestation verification, recovery codes, 256-bit session tokens, device binding, idle and absolute timeout enforcement, concurrent session limits, and admin kill.
OIDC/OAuth2 Core & Extensions
Authorization Code with PKCE, Client Credentials, Refresh Token, token introspection, JWKS from GeomDB-backed storage. Per-client branding on consent screens. private_key_jwt and mTLS client authentication methods.
Realm-Scoped Whitelabel
Logo, colors, fonts, sandboxed custom CSS, custom domains with managed or provided TLS, base64 email templates, 12-language localization with RTL, and per-realm TOTP issuer branding — live within five seconds, no restart.
Customer Record & Privacy Primitives
CIAM merge, dedup, impersonate-with-audit, DSAR export bundles, RTBF cascades with legal-hold consultation, preference-center consent receipts, and account closure with the 30-day grace / 90-day retain / 7-year archive retention ladder.
Evidence Export & Compliance Packs
CAdES B-LTA, PAdES B-LTA, ASiC-E, COSE Bundle, and native evidence_bundle_v1 formats. Each carries chain-of-custody manifest, Merkle proofs, STHs, TSTs, and certificate chains to the trust root.
CRTL Constitutional Gate Binding
Every protected mutation: ResolveIdentity, pre-sign authorization, staged evidence refs, EvaluateEvidenceGate, then side effect. ControlSurfaceEnvelope fields carry evidence_frame_ref, evidence_gate_result_ref, and evidence_write_status — fail closed on gate rejection.
Complete Control Surface Parity
REST, gRPC, CLI \argus namespace, SDK methods, SQL monitoring views, GUI/admin panels, WebSocket, health, and SET/SHOW configuration — each surface maps to the same operation contracts and emits identical evidence.
Post-Quantum & Hardware Attestation
crypto_post_quantum feature composes hybrid classical + ML-DSA signatures. evidence_tier_hardware_attested binds TPM2_Quote over PCRs 0-15 with nonce-bound signing ceremonies and TCG Canonical Event Log replay.
Ultra-Converged Product Embedding
argus_core linked into DXP, XRP, and every satellite runtime — not a standalone daemon. Kanidm substrate absorbed with GeomDB storage adapter, Timeline-X audit exclusive, and platform OpenTelemetry observability derived from the event spine.