Identity (OIDC)
One OIDC login surface for six brands; each product keeps its own logo and copy.
01 / ECOSYSTEM
Six products run independently and compose as a federated suite through open protocols and an optional shared control plane — what is shared is identity, entitlement and protocols, never business logic.
01 / VALUE CHAIN
Creation and learning lead to device connectivity and data insight, then visual security and remote operations, and finally settlement where agents and humans are peers.
Create
Skills, artifacts and training content
Connect
Device onboarding, telemetry, incidents and Safety Kernel
See
Reports, dashboards, exports and embeds
Watch
Visual events, alert state and acknowledgements
Control
Remote sessions, recording and audit
Earn
Tasks, receipts and ledger settlement
02 / PLATFORM
The control plane is optional; product planes stay autonomous. When central services stop, each product degrades exactly as its manifest declares — Casbin is never bypassed.
CONTROL PLANE
One OIDC login surface for six brands; each product keeps its own logo and copy.
Plans, Trial, License, seats and billing in one place; commercial rights never enter the JWT.
Resource-level ACL stays in each product; permissions ship with the resource.
CAPABILITY UNITS
Multi-vendor model routing, key vault and usage metering.
Shared mail and notification module with a unified sender identity.
Identity, ACL and entitlement clients ship as npm packages — no cross-repo source imports.
03 / INTEGRATION
Cross-product integration uses OIDC, HTTP, MQTT and versioned events only — no runtime imports or shared business schemas.
04 / ERRORS
HTTP status codes mean the same thing across products for orchestration and audit.
AuthN failed; identity outages never degrade to anonymous access.
Commercial rights insufficient (Trial expired, plan mismatch, quota exhausted).
Casbin denial; License never bypasses resource permissions.
05 / PROTOCOLS
Integrate through open standards first to reduce lock-in and migration cost.
06 / AUTONOMY
Each product owns its database, migrations, Casbin policy and release cadence. It must still start and pass readiness when every sibling product is down.
- Each product owns its database, migrations, Casbin policy and release cadence
- It must still start and pass readiness when every sibling product is down