Directory journeys
Table of Contents
The roster is the administrator's starting point, and creating an account is the journey that fills it. Both treat an account as a record in a directory rather than as one person's own details.
The roster journey has no single entity behind it. Its usefulness comes from joining the account, its sign-in state, its parties and its roles into one row, so the administrator can see who is locked, who is online, and who must change their password at next sign-in. That join is the journey's real work.
An account is not always a person. It has four types — user, service,
algorithm and llm — and only the first has a photo, a job title, a contact
record or a party in the ordinary sense. A non-human account is still an
identity that logs in, holds roles and appears in provenance, so it is created
and managed here, but the journey is not the same one.
1. Journeys
| Journey | Actor | Gist |
|---|---|---|
| See who has access | tenant administrator | Read the roster and each account's state |
| Bring someone in | tenant administrator | Create a person's account with its parties, roles and first password |
| Register a service account | tenant administrator | Create a non-human identity for a service, an algorithm or an LLM |