◎The Identity Lens · reference model

A model architecture · the possibilities, not our build

What the system knows about you,
between the login and the answer

Watch a single question travel the whole estate. The picture stays put; the request moves through it, and underneath, the mechanism changes with it. This is the shape an identity-scoped assistant takes in a real company — most of it bought, not built.

The request travelling from the identity provider through the scope filter to one model call

front channel — the browser sees it back channel — server to server inside your process a system you buy, not build

Look inside

Three stages open a second level — use a button, the corner mark, or double-click the box.

Identity provider

The reference model · not a picture of our build

What this looks like in an enterprise, when everything is there

Seven planes. This is the architecture an identity-scoped assistant wants in a real estate — most of it bought, not built, and most of it already standing in a company that has an HR system and a directory. Our kit implements a deliberate subset; the switch below shows which, so the template can be read as a template without pretending it is all running.

implemented and measured the enterprise template

The three that decide the design

Why it is built this way and not the obvious way

The subject claim is not an employee number

Guaranteed unique within the issuer and nothing more. Entra makes it pairwise — two of your own apps get two different values for the same person. An HR system has never heard of it.

OIDC Core §2, §8.1

A hierarchy cannot live in group claims

Entra stops at 150 groups in SAML, 200 in a JWT — nested groups counted — then drops the claim entirely for a pointer to Graph. Okta caps at 100 and fails the request. A reporting line needs a group per manager per depth.

Entra optional claims · Okta authz-server claims

The directory cannot walk the tree

Graph's manager points one level up, directReports one level down. transitiveReports is beta and returns a count, not people. You cannot enumerate an org tree from it at all.

Microsoft Graph user resource

Honest about what is not known

Two things this page deliberately does not show

No millisecond figures

No vendor publishes per-hop latency for the authorize redirect, the token exchange or the key fetch. Rather than put a plausible number on screen, there is none. The one timing fact that matters is structural and is drawn: the key fetch is cached out of band, not done per request.

No claim that all of this is running

This is a reference model. Our kit implements a deliberate subset of it — the filter, the labels, the walk, the one call and the audit row. The switch above marks which. The rest is the shape a real deployment takes, drawn so an integrator can build it.

A model architecture for identity-scoped answers. The identity stages are drawn from vendor documentation and the OIDC specification; the filter, the walk and the 71-of-124 split are measured from a running kit.

The three second levels: the chunk counts, the 5-chunk employee file, the organisation and the four per-role totals are run from the kit's own chunker and filter over its generated sample data. The several sources, the connectors and the directory path are the reference model, cited to the Data & Visibility catalogue as read on 2026-09-14.