Architectures/Entitlement · identity · conformance
Public reference architecture

Developer Cloud & Console

From product discovery to production evidence without credential sprawl.

Keep visibility, requested scope, effective rights, one-time identity, conformance and production promotion as distinct server-authoritative lifecycles.

Know which component owns the state—and what it must never infer.

Every layer exposes an authoritative responsibility and an explicit non-authority boundary.

01
APP-09

Browser console

OwnsNavigation, display and ephemeral one-time dialog

Must not inferCannot grant rights, persist secret or promote production

02
Secure web boundary

Portal BFF

OwnsSession, role, step-up, CSRF and field filtering

Must not inferNot the entitlement or credential source of truth

03
SAAS-10

Developer control plane

OwnsProjects, effective rights, credentials, traces and lifecycle

Must not inferCatalogue visibility is never authorization

04
Sandbox / conformance / production

Product gateways and runners

OwnsContract execution and signed evidence

Must not inferPassing test evidence does not create production access

State advances through evidence—not optimistic UI.

Each transition names both the action and the identity or version evidence that makes it reproducible.

  1. 01

    Select context

    Bind organization, program, project, environment, actor and revision.

    project/environment IDs · role · session
  2. 02

    Request rights

    Validate exact module, territory, platform, term and purpose.

    request/audit IDs · pending state · policy
  3. 03

    Create identity

    Issue only effective sandbox scopes and return secret once.

    masked row · fingerprint · expiry · no persisted secret
  4. 04

    Diagnose and conform

    Use redacted traces and signed versioned fixtures/checks.

    correlation · redaction · suite/contracts/policies
  5. 05

    Evaluate promotion

    Expose every mandatory gate and retain human/propagation boundary.

    readiness revision · blockers · approval/receipt

Interfaces that a production program must own.

01

Project/catalogue

Organization, environment, products, modules and versions.

02

Entitlement/credential

Exact rights, request lifecycle and one-time material.

03

Trace/conformance

Redacted correlation, fixtures, checks and signatures.

04

Promotion/release

Gates, reviewers, propagation, notices and migrations.

Failure states stay truthful and useful.

Stale project/readiness revision

Return conflict and require complete context refresh.

Control plane unavailable

Keep verified docs/read-only metadata; block protected actions.

Trace redaction incomplete

Reject browser delivery rather than expose protected payload.

All technical gates pass

Reach ready-for-human-approval only; do not issue production access.

Privilege follows the narrowest useful boundary.

  • Secure BFF session and server-side role/field policy
  • One-time secret excluded from persistence, URL, logs and analytics
  • Hard sandbox/production identity and network separation
  • Trace redaction before developer store
  • Phishing-resistant step-up and immutable privileged audit

A green demo is not a production acceptance case.

  • 01Tenant/role/field isolation and stale revision tests
  • 02One-time secret non-persistence and rotation/revocation
  • 03Docs link/example and contract-version conformance
  • 04Trace privacy and high-cardinality query behavior
  • 05Promotion gate, human approval and offboarding evidence

Compose the system without collapsing product ownership.

Each product can be bought and operated independently while sharing identity, context and lifecycle contracts.

OEM program workshop

Turn the Developer Cloud & Console reference into your program architecture.

Confirm target products, vehicle and cloud boundaries, source systems, contract versions, deployment, validation and lifecycle ownership.