Identity
ENFORCEDOne MADOMIC OIDC identity across every portal and future standalone domain.
PHASE 2 · SECURITY CONTROL PLANE
Every sensitive portal will inherit the same security equation: identity + tenant + membership + entitlement + permission + resource scope.
One MADOMIC OIDC identity across every portal and future standalone domain.
Every institutional request is revalidated against an active organization membership.
Roles are permission bundles; the default decision is deny.
Subscription and feature access remain separate from organization permission.
Sensitive operational tenants target dedicated databases with opaque secret references.
Sensitive activity is designed for append-only attribution and security review.