Capability 12 / 14 · Connect and organize

Match knowledge access to the organization that owns it.

Governed foundationAvailable nowStage: Ingest

Segment knowledge by business unit, provision users and groups through enterprise identity systems, and map directory groups to EKOS roles and organization membership.

IDENTITY / SCIM 2.0Provisioned

Your identity provider

Compliance group +1 member

EKOS group mapping

Compliance → Reviewer role

  • tenant-wideSecurity Policies corpusvisible
  • compliance orgAudit Evidence corpusvisible
  • people orgHR Procedures corpusnot visible

Identity comes from verified credentials, never from caller-supplied headers. Deactivate the account upstream and the next request fails closed, while past review decisions stay attributable.

Illustrative product view · directory provisioning mapped to roles and visibility

The problem

Large enterprises need one knowledge platform without automatically exposing every document to every team or maintaining a separate manual account spreadsheet.

What EKOS does

Verified credentials establish tenant and actor context, server-side queries apply organization and corpus visibility, and a SCIM service-provider surface manages users, groups, and soft deactivation.

  • Tenant-wide and organization-scoped visibility
  • Verified credential-derived identity context
  • SCIM user and group provisioning
  • Directory group-to-role mapping
  • Soft deactivation that blocks later access

How it works

  1. Verified JWT credentials establish the user and tenant; caller-supplied tenant or actor headers are never trusted.

  2. An upstream identity provider provisions users and groups, updates memberships, and soft-deactivates people through the SCIM 2.0 surface.

  3. EKOS administrators map directory groups to product roles and manage organization membership.

  4. Server-side query paths scope every read to the tenant, the caller's organizations, and subscribed corpora.

  5. Role and membership checks resolve against current identity records, so a deactivated user fails closed on the next request while past decisions stay attributable.

Business outcome

Knowledge access and product roles can follow the organization's current identity lifecycle while historical decisions remain attributable.

Proof and human control

Provisioning, role mapping, membership, and deactivation actions are evaluated against current identity records and retained in the audit trail.

Example in practice

An employee joins the Compliance directory group, receives the mapped role and organization access, then loses subsequent access after the upstream identity system deactivates the account.

Scope today

Current segmentation is enforced through verified request context and server-side application and query scoping.

Next step

See your own documents become a trail of proof.

A working session with the EKOS team: bring a policy set, a framework, and a hard question. We will walk the loop end to end.