Skip to main content

IAM and Identity Team Guide designed

This path is for the teams that own or review identity, federation, MFA, authorization scope, and shared access policy.

What IAM Should Learn First

  1. GPUaaS product IAM is not the same as raw IdP administration.
  2. Platform IAM owns product roles, memberships, scopes, service accounts, and audit-backed authorization posture.
  3. The external identity provider remains an enforcement and federation boundary, not the sole product source of truth.

IAM Decision Route

If IAM needs to answer...Open this firstThen go here
what the product exposes to users and adminsAccount and AccessMFA Walkthrough
what the API expects for auth, scopes, and sessionsDeveloper API AuthDeveloper Implementation Map
how shared-platform identity contracts are supposed to scale to other productsShared Platform BuildersBuild on AI Cloud
where provider administration stops and product IAM beginsArchitecture Review PackSecurity & Production Readiness

Reading Pack

IAM Review Themes

ThemeWhat matters
Federation boundaryWhat the IdP owns versus what platform IAM owns
MFA product postureUser/admin/operator journeys, recovery, and sensitive-op follow-up
Scopes and service accountsHow developers and future products consume shared identity contracts
Tenant/project authorizationHow GPUaaS scopes product actions independently of external identity

Portal-Native Answer

If the reader needs the direct answer instead of just the reading route, start with IAM Capabilities and Boundaries. This page remains the team guide and route map; the capabilities page is the concise product IAM model.