Enterprise

Governed for the teams that answer for the response.

KnownScope is designed to drop into an enterprise environment: behind your identity provider, inside your tenancy model, and alongside the tools your team already operates. These are architecture commitments and product direction, described honestly for a product in private preview.

The operating model

Fits your identity, tenancy, and tooling.

Items marked Direction or Planned describe where the product is heading for private preview and beyond. We do not present them as generally available today.

01Direction

Provider-neutral SSO

Identity is designed to sit behind your provider, not to replace it. The direction is standards-based SSO over SAML and OIDC, SCIM provisioning, and mapping identity-provider groups to KnownScope roles, so access follows the identity you already run. These are the building blocks we are working toward, not capabilities available today.

02

Coarse, understandable authorization

Owner, Worker, and Viewer are deliberately few and legible. Authorization you can reason about beats a permission matrix no one can audit, especially during an incident.

03

Tenant isolation

Each tenant’s Campaigns and data are isolated, with authorization enforced on the server rather than assumed in the interface. Isolation is the default, so the boundary holds regardless of the client.

04Planned

API-first integration

The direction is parity between the first-party interface and the API, so your automation and existing tools act on the same Campaign model your responders do.

05

Portable, cloud-native architecture

KnownScope runs as a cloud-native service today, built on standard cloud primitives rather than a single proprietary platform, so deployment stays portable and your team is not locked to one vendor’s runtime.

06

Operational ownership & recoverability

Non-destructive history and export mean the data is yours to hold, inspect, and recover. Operational ownership is a design constraint, not an upsell.

What we don't claim

No unverified compliance or SLA claims.

This site does not assert certifications, audit attestations, or service-level guarantees. When formal assurance material applies, it will be published where it can be verified, and named plainly. Until then, we would rather earn trust in a conversation than borrow it with a badge.

Private preview

Let's talk deployment.

Tell us about your identity requirements, deployment constraints, and the response work you need to govern. We will follow up about private-preview access and what a fit looks like.