CodamAIDocs
Subject area

Security principles

The principles behind every CIAS process, in one place: refuse when in doubt, indistinguishable refusals, no defaults for permissions, and behavior during outages.

Topics in this subject area

  1. 1.Reject when in doubt

    No default tenant, no default administrator role, required configuration without a default. Why an application would rather not start than start generously.

  2. 2.Rejections that reveal nothing

    Unknown and suspended look the same, public endpoints always answer the same way, admin rejections are identical. Why this way nobody can probe for information.

  3. 3.When CIAS or Keycloak fails

    What happens during an outage: the tenant gate answers from memory, registration and administration answer with 503, a failed provisioning stays repeatable.

Search