Client-controlled runtime
The product retains its own local configuration, audit trail, licence state and operational workflow.
Where Trust Begins
Identity security
Identity mesh, local IAM, SSO-ready federation, SCIM/LDAP/OIDC/SAML connector governance, and role claims. The product is positioned as a client-controlled security engine with professional deployment, audit and integration boundaries.

Core responsibility
local IAM, MFA, SSO bridge, roles and service identities
Roles: Super Admin, Identity Admin, Access Reviewer, Auditor, User, Service Account, Break-glass Admin
Authentication: Primary product for local identity, MFA, SSO federation, and service identity tokens.
Linked with: Optional identity backbone for Unified Cyber Security Command Center and all Phylaxis products, plus Nomion, Tekmerion evidence, and Kleidion secrets.
Boundary: If Eidon is offline, standalone products use local admin auth and cached identity only if policy allows.
Cybstyx model
The product should be strong alone first. Integration improves visibility and coordination, but it must not become an uncontrolled dependency.
The product retains its own local configuration, audit trail, licence state and operational workflow.
SecOwl can receive approved events and show posture or evidence if the client enables the adapter.
Products may connect to identity, evidence, licence, secrets or timeline services when policy allows.
Administrative changes, service events and proof exports should remain auditable.