Identity anchor
GitHub logins, AWS users, and Entra or Okta objects get tied together through an anchor. That is how you get one view of standing privilege instead of three admin portals.
Transitive access resolution shows why a principal has access by tracing nested group, team, and role membership paths across providers (a bounded membership graph, not full effective-permission math). When a single request spans multiple providers, a compensating saga fulfills the bundle atomically and rolls back automatically on partial failure, with an operator remediation view for anything stuck.