Foundation in progress

Identity infrastructure for accountable access

Identity infrastructure you can operate—and defend.

Magellan is being built for teams that need tenant-isolated authentication, controllable sessions, policy-driven access, and audit evidence across every critical identity path.

The initial account model is free. No paid tier, pricing page, or checkout in this release.

Architecture preview Identity control plane
Design target
Identity path Correlated Login → session → token
Audit boundary Separated Durable security record
Tenant context Explicit Every critical decision
Change control Bounded Flags, rollout, rollback
Planned signal flow Destination
Authentication eventAllowlisted operational context
Corridora
Security-relevant actionAuthoritative, unsampled record
Audit ledger
Administrative changeActor, tenant, result, reason
Evidence

Built around the questions accountable teams ask

What changed? Who had access? Can we revoke it? Can we prove it?

Shared accountability

Clear controls for every team responsible for trust.

Identity affects uptime, incident response, access review, and audit readiness. Magellan’s direction is designed around the people who carry those responsibilities after launch.

01 Operations

Keep identity diagnosable.

Follow authentication, token, session, and policy paths with enough context to separate a user issue from a platform issue.

  • Correlated operational signals
  • Explicit service ownership
  • Controlled rollout and rollback
02 Security

Make access boundaries explicit.

Carry tenant scope across each decision, constrain administrative authority, and make revocation a designed path—not an incident-time improvisation.

  • Tenant-isolated control paths
  • Session and token lifecycle controls
  • Least-privilege administration
03 Compliance

Produce evidence without reconstruction.

Preserve security-relevant activity in a dedicated audit record with clear ownership, retention, and export behavior.

  • Separate security-audit history
  • Attributable administrative change
  • Evidence tied to real controls

A focused identity foundation

Start with the controls that make identity credible.

Magellan will publish capabilities against explicit delivery states. The first product milestone is a tenant-safe identity core—not a checklist that outruns implementation.

01
Authenticate

A deliberate entry point

Password registration, work-email verification, secure session establishment, and a path to TOTP and WebAuthn.

Planned
02
Sessions

Control the active state

Visible sessions, bounded lifetimes, rotating refresh credentials, per-session revocation, and global logout.

Planned
03
Authorize

Keep decisions tenant-scoped

A focused RBAC baseline for end users and tenant administrators before richer policy models are introduced.

Planned
04
Integrate

Start from current protocols

OIDC and OAuth 2.0 first, with explicit client, redirect, consent, key-rotation, and token-validation contracts.

Planned
Operational model Planned
IdentityTokenSessionPolicy

Operational telemetryAllowlisted logs, traces, metrics

Corridora

Security auditDurable, attributable events

Separate ledger

A telemetry outage must never block authentication or audit durability.

For operations

See the path, not just the symptom.

The planned operating model correlates critical identity paths while preserving a strict boundary between service health and the security record.

01

Trace critical pathsConnect login, session, token, and policy outcomes with bounded context.

02

Operate against objectivesUse release markers, synthetic checks, SLOs, and owned alerts.

03

Fail without changing accessKeep telemetry asynchronous and fail-open for identity operations.

Security & trust

Trust starts with boundaries you can explain.

Magellan’s planned architecture separates public content, hosted authentication, administration, key custody, operational telemetry, and security audit responsibilities.

Architecture-as-code will keep those relationships tied to implementation. Compliance claims will be made only at the level achieved—never inferred from a vendor list or roadmap.

Review the delivery sequence
01

Tenant isolation first

Carry an immutable tenant boundary through identity, session, token, policy, and audit paths.

02

Least privilege by role

Separate end-user, tenant-administrator, and platform-operator authority and recovery.

03

Evidence from operation

Produce security evidence from real control execution instead of a parallel compliance narrative.

04

Controlled change

Design rollout, kill switches, migration safety, and rollback alongside each risky capability.

Delivery sequence

Deepen the platform without overstating what is ready.

Each stage earns the next one through tested boundaries, failure behavior, and operating evidence. Timing remains subject to implementation and design-partner feedback.

  1. 01
    Now

    Public foundation

    Establish the brand, operating principles, public marketing surface, and inert account-flow previews.

  2. 02
    Next

    Verified identity core

    Turn signup and login into tenant-safe services with email verification, session controls, audit events, and operator recovery.

  3. 03
    Then

    Application integration

    Introduce OIDC/OAuth 2.0, client administration, key rotation, policy enforcement, and release evidence.

  4. 04
    Later

    Federation and lifecycle

    Evaluate SAML, SCIM, richer ABAC, audit streaming, risk signals, and compliance packaging against customer need.

API documentation will begin with OpenAPI.

The API definition is not yet published. When it is ready, references will be generated from the versioned OpenAPI source and documentation access will require a Magellan account.

View docs approach

A disciplined starting point

Preview the free account flow.

Account services are not connected yet. The signup, sign-in, and email-verification screens show the intended entry path without collecting credentials or creating users.

Preview free signup View sign-in preview