Tenant onboarding
Define organization, trust boundary, data residency, operators and evidence retention.
PRODUCT MANUAL
Role-based guide for tenant onboarding, RP registration, Passkey approval, multi-CA routing, activation, protected signing and evidence operations.
OPERATING JOURNEY
Define organization, trust boundary, data residency, operators and evidence retention.
Register redirect/origin, OAuth client, mTLS identity, scopes and branding.
Configure route, credentials, health, eligibility and approved failover.
Map OIDC subject and verified identity to signing accounts.
Register credential under the approved RP ID and authenticator policy.
Configure format, algorithm, provider, verifier and evidence policy.
Submit hashes, signer, context, approval and expiry.
Render document identity, purpose, amount and relying-party facts.
Generate challenge and verify assertion, origin, RP ID and policy.
Issue short-lived single-use SAD/authorization.
Invoke HSM/QSCD/SAM through the approved provider route.
Assemble manifest, detached signatures and supporting evidence.
Collect TSA, certificate path, OCSP/CRL and report.
Track asynchronous state and deliver governed notifications.
Handle expiry, provider outage, partial verification and approved rollback.
Export correlated evidence, operational metrics and support package.
ADMINISTRATOR CHECKLIST
DEVELOPER CHECKLIST