Keep identity diagnosable.
Follow authentication, token, session, and policy paths with enough context to separate a user issue from a platform issue.
- Correlated operational signals
- Explicit service ownership
- Controlled rollout and rollback
Identity infrastructure for accountable access
Magellan is being built for teams that need tenant-isolated authentication, controllable sessions, policy-driven access, and audit evidence across every critical identity path.
The initial account model is free. No paid tier, pricing page, or checkout in this release.
Built around the questions accountable teams ask
Shared accountability
Identity affects uptime, incident response, access review, and audit readiness. Magellan’s direction is designed around the people who carry those responsibilities after launch.
Follow authentication, token, session, and policy paths with enough context to separate a user issue from a platform issue.
Carry tenant scope across each decision, constrain administrative authority, and make revocation a designed path—not an incident-time improvisation.
Preserve security-relevant activity in a dedicated audit record with clear ownership, retention, and export behavior.
A focused identity foundation
Magellan will publish capabilities against explicit delivery states. The first product milestone is a tenant-safe identity core—not a checklist that outruns implementation.
Password registration, work-email verification, secure session establishment, and a path to TOTP and WebAuthn.
Visible sessions, bounded lifetimes, rotating refresh credentials, per-session revocation, and global logout.
A focused RBAC baseline for end users and tenant administrators before richer policy models are introduced.
OIDC and OAuth 2.0 first, with explicit client, redirect, consent, key-rotation, and token-validation contracts.
Operational telemetryAllowlisted logs, traces, metrics
CorridoraSecurity auditDurable, attributable events
Separate ledgerA telemetry outage must never block authentication or audit durability.
For operations
The planned operating model correlates critical identity paths while preserving a strict boundary between service health and the security record.
Trace critical pathsConnect login, session, token, and policy outcomes with bounded context.
Operate against objectivesUse release markers, synthetic checks, SLOs, and owned alerts.
Fail without changing accessKeep telemetry asynchronous and fail-open for identity operations.
Security & trust
Magellan’s planned architecture separates public content, hosted authentication, administration, key custody, operational telemetry, and security audit responsibilities.
Architecture-as-code will keep those relationships tied to implementation. Compliance claims will be made only at the level achieved—never inferred from a vendor list or roadmap.
Review the delivery sequenceCarry an immutable tenant boundary through identity, session, token, policy, and audit paths.
Separate end-user, tenant-administrator, and platform-operator authority and recovery.
Produce security evidence from real control execution instead of a parallel compliance narrative.
Design rollout, kill switches, migration safety, and rollback alongside each risky capability.
Delivery sequence
Each stage earns the next one through tested boundaries, failure behavior, and operating evidence. Timing remains subject to implementation and design-partner feedback.
Establish the brand, operating principles, public marketing surface, and inert account-flow previews.
Turn signup and login into tenant-safe services with email verification, session controls, audit events, and operator recovery.
Introduce OIDC/OAuth 2.0, client administration, key rotation, policy enforcement, and release evidence.
Evaluate SAML, SCIM, richer ABAC, audit streaming, risk signals, and compliance packaging against customer need.
The API definition is not yet published. When it is ready, references will be generated from the versioned OpenAPI source and documentation access will require a Magellan account.
A disciplined starting point
Account services are not connected yet. The signup, sign-in, and email-verification screens show the intended entry path without collecting credentials or creating users.