The business case · Identity
Keycloak, by the risk it changes
An identity and access management server. Its standard token exchange lets a client exchange a token issued for one client for a token aimed at another, carrying the identity of the party on whose behalf the request is made. Written as an answer, an agent acting on a token that starts from a named person's login acts as that person, not as an ownerless service account.
Open source: Apache-2.0 · CNCF (incubating) · get involved
The deployment: The model's typical deployment, with the answers this project addresses stated as they are without it: it acts under a service account nobody owns.
The model: the RiskGraph Explorer's 49 facts, 49 risks and 10 roles, copied into this site with its provenance; the register below is computed, not written. How.