New design introduces few powerfull concepts
- API/SPI separation that should enable easier adoption of different identity managers or identity stores in the future.
- Notion of Identities and Groups (organizations) with flexible relationships between them
- Concept of a Role that is a typed connection between Identity and Group object. This enables to map sentence like "John is the Manager of XX Team" to "John (Identity) is the Manager (RoleType) of XX Team (Group)"
- Abstract attributes and credentials
We are awaiting your feedback!
1 comment:
You know, I'm glad I ran into this 'blog entry. I'd been under the impression as if the IDM design documented in that link was already in effect. It will affect some design proposals, if it is not. I'm glad I haven't gone very far with those proposals, as yet. Here's to the new design, assuming it makes it from proposal, into implementation.
Post a Comment