Early access — partly shipped, API-first
Estimated 26.9.1· central rotation, first week of September
Integration Control
One registration per application, granted customer by customer
When RealmSSO fronts a portfolio of applications rather than a single one, every application needs its own trust relationship inside every customer tenant, and registering those by hand is work that grows with both numbers at once. Integration Control makes those relationships first-class objects instead: register an application once — or the identity system it already trusts — then grant it per customer. RealmSSO provisions the matching trust configuration into each granted customer realm, including realms created later, and serves each integration team exactly the values it needs for a given customer. Access is default deny throughout: a customer gets an application only where a grant says so, so one registration never quietly reaches a customer who never bought it. That much is real and driven over the API today. Central credential rotation and automated reconciliation are still design, and there is no configuration UI for any of it.
Why Integration Control?
Everything you need for enterprise-grade identity federation.
Register Once, Grant Per Customer
Register an application — or the identity system it already trusts — a single time. From that one record RealmSSO stamps the matching trust configuration into each customer realm you grant it to, so adding a product to your estate is one registration plus a grant, instead of one registration per customer.
Access Is Default Deny
A registration reaches a customer only where a grant says so. Nothing is stamped estate-wide, because putting one product’s client, secret and audience inside a customer realm that never bought it is how tenants get coupled to each other. A new customer realm picks up the products that customer has been granted, and no others.
Per-Customer Values, Served Not Chased
Each integration team can read exactly the values its own side needs for a given customer, from one place, in a form its automation can consume. The hand-off between the identity team and an application team stops being an email with settings pasted into it.
One Record Holds the Intended State
Because every granted realm is provisioned from the same registration, integrations cannot quietly diverge customer by customer. The handout reports each customer as provisioned, absent, or unreachable, so a gap between intent and reality is something you can read rather than go looking for. Closing that gap automatically is direction, not a capability today.
Lifecycle as a Platform Operation
An integration is granted or revoked per customer, and its per-customer status is readable from the same record — with grants, revocations and provisioning landing in the audit trail. Cutting one customer’s access to one application is a revoke rather than a request to whoever configured it last. Revoking deprovisions immediately; central rotation of credentials and signing certificates is not built yet, and rotation needs a coordinated window with the product team rather than a button.
Availability — early access
Part of this now ships, which is why the cards above are worded as what the platform can do rather than as a finished product. Registration, per-account grants with default deny, provisioning into each granted customer realm, and the per-customer values hand-off are real and driven over the API — see /features/identity-gateway for what that covers. Central rotation of an integration's credentials and signing certificates is not built, and there is no UI for any of it. Treat the rotation and reconciliation wording above as the direction, not as something you can switch on today.
Interested in early access?
The control-plane half of this is now real: registration, per-account grants with default deny, provisioning into each granted customer realm, and the per-customer values hand-off, all over the API. What is not built is central credential and certificate rotation, and there is no configuration UI for any of it — so this is not yet a capability you switch on. If a portfolio of applications behind one identity platform is the problem you have, we would rather hear from you while the rest is still open than after it is fixed.