Enterprise Identity & Access Layer (EIAL)

Federated IdP · RBAC + ABAC · MFA · tenant-scoped sessions · audit

Identities

3,234

MFA Coverage

60%

Active Sessions

5

Policies Enforced

5/6

Federated Identity Providers

connected

UaePass

OAuth 2.0 / SAML

1,840 usersnative
connected

Google Identity

OIDC

920 usersoptional
connected

Email / Password

Built-in

410 usersenforced
connected

Slack SSO

OAuth 2.0

64 usersoptional

RBAC Permission Matrix

CRUD per OS module
RoleWorker OSCompliance OSFinancial OSPartner OSSocial OSDesign OS
Platform Admin4
RCUD
RCUD
RCUD
RCUD
RCUD
RCUD
Tenant Admin18
RCU·
RCU·
RCU·
RCU·
RCU·
RCU·
Partner142
RC··
R···
R···
RCU·
RCU·
R···
Recruiter86
RCU·
R···
····
R···
R···
R···
Employer210
R···
R···
R···
····
····
····
Applicant2640
RCU·
R···
R···
····
····
····
Viewer38
R···
R···
R···
R···
R···
R···

Access Policies (ABAC + Session)

P-001ABAC

Tenant isolation via tenant_id RLS

P-002RBAC

MFA required for admin + financial roles

P-003Session

Session timeout 8h for non-admin

P-004ABAC

UaePass required for UAE government flows

P-005ABAC

Partner scope limited to own referrals

P-006ABAC

Design write requires Studio tier

AI Access Provisioning

describe a user → EIAL recommends role + scope

Active Sessions

dennis@ailysi.com

Ailysi HQ · macOS · Chrome · 94.200.x.x

low2m ago

recruiter@abiworkers.com

Abiworkers · iOS · Safari · 94.201.x.x

low14m ago

partner@gold12.com

Partner Gold-12 · Android · Chrome · 5.107.x.x

medium1h ago

employer@sccd.ae

SCCD Center · Windows · Edge · 94.205.x.x

low3h ago

applicant@ph.net

Abiworkers · Android · Chrome · 203.0.x.x

low5h ago

Access Audit Trail

4m ago[platform_admin]Granted Design OS write to tenant_admin@abiworkers
22m ago[EIAL Policy]Blocked partner access — cross-tenant RLS violation
1h ago[UaePass]Identity linked: applicant@ph.net → UaePass EID
2h ago[EIAL Policy]MFA challenge passed: recruiter@abiworkers.com
4h ago[platform_admin]Policy P-006 created (Design write → Studio tier)