Read-only console gallery
Every page of the portal, without live data.
Open each workspace, then each page. This shows layout and role boundaries only. It grants no access and changes no record.
Enterprise organizationRead only
Organization console
Company sign-in, staff directory, one-time support.
SSO, SCIM and support sessions. Community roles stay separate. Tokens are copy-once.
This page
Identity pages
Live status is this organization’s SSO and SCIM.
| Page | Operator | Must not | Evidence |
|---|---|---|---|
| SSO | Issuer and domains | Allow personal inboxes | Last saved time |
| SCIM | Copy URL and token once | Store the secret in Sahyog | Prefix and last used |
| Directory | Provisioned staff | Invent people | Connector sync |
| Support | Approve or deny | Leave access standing | Ticket and expiry |
On the live page
Work this role can do
1Save company sign-in2Create or rotate a SCIM token3Decide a support request4Disable SCIM with confirm
Access boundaries
Least privilege by default
- No standing support access
- Secrets not re-shown
- MFA for mutations
Production access
Preview is not permission.
Real consoles appear only after an authorized role, valid scope and required two-step verification are confirmed.