Plane 01
Aurora
Identity and Authorization Plane
Agents and Humans
- sso protocols
- oidc · saml · passkey
- isolation
- firefly namespaces
- audit
- every decision
- compliance
- soc2 · iso · lgpd
Before any agent acts, Aurora answers a single question — who is acting, and with what authority?
Aurora is the OS access layer. It models every actor — human employee, AI agent, partner system, citizen — as a first-class identity, with namespaces, scopes and policies. Bring your own identity provider; Aurora speaks OpenID Connect, SAML, SPIRE and passkey natively.
Tenants are isolated as FireFly namespaces, so a single deployment can run many organisations, jurisdictions or trust levels without leaking context. Every authorization decision becomes an audit event the rest of the OS can reason about.
Identity is no longer a login screen. It is the grammar that decides what an agent is authorized to think about.
What it delivers
BYO-IdP catalogue
OIDC, SAML, passkey, SPIRE — federate Okta, Azure AD, Auth0 or run your own.
Tenant namespaces
Hard namespace isolation, with policy and quota inherited downward.
Authorization grammar
Compose policies as readable rules; visualise decisions before they reach production.
Compliance posture
SOC 2, ISO 27001 and LGPD controls designed as living read-models, not annual PDFs.