The identity fabric
Topology
One identity truth governs every principal — human and non-human. Five roles model an enterprise identity stack: a source-of-record (HRIS), governance (IGA), a change gate (ITSM), a CI/asset registry (CMDB), and a privileged-access broker (PAM). Provisioning grants access slowly and under change control; a signaling bus broadcasts change in real time. Everything integrates over open standards, and every console is one login behind Duo.
The governance stack
Each role mirrors its market leader's signature workflow over synthetic data; the customer supplies it via their own products, Duo-gated at the Cloudflare Access edge.
| Role | Function | Modeled on | Owns |
|---|---|---|---|
| HRIS | Source-of-record for humans | Workday HCM | Worker records · the worker feed IGA pulls |
| IGA | Governance & JML — reconcile, review, govern | SailPoint / Saviynt | The HRIS∪AD∪Entra∪Duo∪CII inventory · the plan |
| ITSM | Change-as-access gate + audit spine | ServiceNow ITSM | Every apply — nothing self-grants |
| CMDB | CI / asset-identity registry + device trust | ServiceNow / Device42 | The Service catalog · hardware-ID reconciliation |
| PAM | Privileged-access broker — JIT elevation + vault checkout | CyberArk / BeyondTrust | Time-boxed JIT grants · vault-brokered credentials · break-glass · the SSF/CAEP session-revocation it emits on expiry |
Detect → respond
SSF/CAEP-capable signaling is the enforcement leg; Cisco XDR is what pulls the trigger — the detection & response apex (ITDR) that turns a correlated identity threat into a real-time revoke.
| Stage | What happens | In this lab |
|---|---|---|
| Signal | CII hands XDR the identity vector — human, NHI, and attack-path risk | CII / Oort risk webhook + SSF/CAEP session-revocation signaling |
| Correlate | XDR fuses that vector with endpoint · network · email · DNS telemetry into one identity incident | Splunk SIEM detections stand in for the XDR correlation |
| Respond | XDR closes the loop — session-kill / quarantine enforced back through Duo, Secure Access, and ISE | one signed SSF/CAEP SET drops the session — detect → revoke |
In production Cisco XDR runs this loop at enterprise scale; the lab proves the same shape — Splunk detections plus SSF/CAEP-capable signaling — end to end.
Three domains
The fabric spans three names, each with a job:
grayskulltech.com
The apex / public edge — the Cloudflare zone and tunnels. Where identity meets the internet.
lab.grayskulltech.com
AD, Duo, and the app realm. Where the fabric and its directory actually run.
identity.grayskulltech.com
This portal — the human front door to the consoles and the fabric's reference/training pages.