2026-07-24 16:59:17 +00:00
|
|
|
External authentication produces a protocol-neutral identity that links to a distinct, possibly credential-less Elsa User before Elsa issues credentials. Links are keyed by target tenant, immutable Connection ID, validated issuer namespace, and provider-stable subject, never by email or user name; an extensible Unlinked Identity Policy handles missing links. Elsa composes its open string permission vocabulary through configured Permission Grant Sources, with provider claims requiring explicit mappings or boundaries and optional non-authoritative Permission Descriptors used only for authoring.
|