A model architecture · the possibilities, not our build
What the system knows about you,
between the login and the answer
Watch a single question travel the whole estate. The picture stays put; the request moves through it, and underneath, the mechanism changes with it. This is the shape an identity-scoped assistant takes in a real company — most of it bought, not built.
front channel — the browser sees it back channel — server to server inside your process a system you buy, not build
Three stages open a second level — use a button, the corner mark, or double-click the box.
The reference model · not a picture of our build
What this looks like in an enterprise, when everything is there
Seven planes. This is the architecture an identity-scoped assistant wants in a real estate — most of it bought, not built, and most of it already standing in a company that has an HR system and a directory. Our kit implements a deliberate subset; the switch below shows which, so the template can be read as a template without pretending it is all running.
implemented and measured the enterprise template
The three that decide the design
Why it is built this way and not the obvious way
The subject claim is not an employee number
Guaranteed unique within the issuer and nothing more. Entra makes it pairwise — two of your own apps get two different values for the same person. An HR system has never heard of it.
OIDC Core §2, §8.1A hierarchy cannot live in group claims
Entra stops at 150 groups in SAML, 200 in a JWT — nested groups counted — then drops the claim entirely for a pointer to Graph. Okta caps at 100 and fails the request. A reporting line needs a group per manager per depth.
Entra optional claims · Okta authz-server claimsThe directory cannot walk the tree
Graph's manager points one level up, directReports one
level down. transitiveReports is beta and returns a count, not people.
You cannot enumerate an org tree from it at all.
Honest about what is not known
Two things this page deliberately does not show
No millisecond figures
No vendor publishes per-hop latency for the authorize redirect, the token exchange or the key fetch. Rather than put a plausible number on screen, there is none. The one timing fact that matters is structural and is drawn: the key fetch is cached out of band, not done per request.
No claim that all of this is running
This is a reference model. Our kit implements a deliberate subset of it — the filter, the labels, the walk, the one call and the audit row. The switch above marks which. The rest is the shape a real deployment takes, drawn so an integrator can build it.