YOUR IDENTITY SERVICE
People, access and activity.
Sign in with an explicitly assigned local administrator account.
Administrator sign-in required
Use your local administrator account and registered passkey.
Sign inManagement access
Verify your passkey to make changes. Verification lasts five minutes.
People
50 per pageOne use, valid for 15 minutes. It is not saved in your browser.
| Person | Identity type | Status | Keys | Sessions | Actions |
|---|
Linux identities and access
Assign identities, enroll machines and set access rules. Changes apply when an agent refreshes its signed policy. Existing offline leases remain valid until expiry.
Registered keys
Group memberships
Primary membership and numeric IDs are fixed. Adding a group can grant access on every host with a matching group rule.
Assign a Linux identity
Use an existing enabled account. Choose unused IDs from 10000 to 4294967294 and check for conflicts on your machines. Assignment creates a primary group with the same name and cannot be edited.
Groups and membership
| Group | GID | Members |
|---|
Hosts and enrollment
| Host | Status | Last contact | Saved policy | Actions |
|---|
Download once and transfer privately to the intended machine. On that machine, run as root with the installed agent:
identity-agent enroll /var/lib/identity-agent < host-invitation.json identity-agent managed /var/lib/identity-agent
This creates the machine identity; installing PAM/NSS integration is a separate step. A localhost issuer needs the lab’s secure forwarding or a reachable HTTPS deployment.
Configured rules
Effective access
This is the issuer’s current policy, not proof that a machine has received it. Privileged commands require fresh online authentication through identity-sudo.
Host login rules
A direct grant replaces that user’s service list and clears an explicit denial. Deny user overrides both direct and group grants. Removing a group grant does not deny access provided by another rule.
Privileged command rules
Allow one exact command and argument list for a group on a host. Group members also need effective login access. Arguments are literal: no shell expansion or wildcard matching.
Online native security-key access
Choose which enrolled key can authenticate directly on a host. This requires existing service access and a reachable issuer; it does not grant offline login or sudo commands.
Offline reboot mode
Strict (default) requires online trust after reboot. Laptop clock mode permits existing signed offline grants across reboot using the machine clock. It cannot detect complete disk-and-clock rollback. Requires a separate host administrator opt-in; does not grant login or offline sudo.
Bounded offline sudo
Optional elevation using one key and an existing exact-command rule. Requires local root opt-in. Disconnected revocation waits for lease expiry or reconnection. Authentication caching is separately bounded; zero requires a key for every invocation.
Bounded offline login
Requires an eligible, non-synced ES256 passkey and existing host login access. Removing a grant prevents new leases; an already issued lease lasts until expiry. Offline sudo requires its own explicit command grant and local root opt-in.
Lists show 50 items per page using the dashboard’s page controls. Type an exact user or host name to inspect it directly. Application-specific roles are not implemented.
Applications
Renewal and device sign-in are explicit permissions. Revoking grants does not disable future sign-in.
| Application | Client type | Renewal | Device sign-in | Coordinated logout | Actions |
|---|
Recent activity
Administrator actions identify the actor and target. Credentials and bearer tokens are excluded.
| Time | Event | Identity / actor |
|---|