Articles

Private IAM, enterprise SSO, evidence.

Short perspectives for framing an identity control plane: integration, governance, audit, migration and operations.

ArchitectureMay 17, 2026 · 6 min

HankoShell above Active Directory, Entra ID, Okta and Google Workspace

HankoShell applies above existing identity sources to turn groups, claims and corporate authentication into governable application access.

Read article →
Product5 min

When enterprise SSO becomes a control plane

Enterprise SSO gains value when it connects applications, tenants, sessions, policies, entitlements and evidence in one control surface.

Read →
Doctrine5 min

IAM audit: evidence for IT and security leaders

IAM audit becomes more useful when access, sessions, roles, changes, exports and reversibility form an operable evidence pack.

Read →
Doctrine6 min

From authentication to an identity control plane

HankoShell turns identity into an operable surface: stable issuer, governable access, audit, reversibility and enterprise capabilities.

Read →
Architecture5 min

Migrating Keycloak, Auth0 or Authentik to stable IAM

A successful IAM migration starts from existing backends, stabilizes applications and turns exports, configuration and audit into usable evidence.

Read →
Product5 min

Self-hosted enterprise SSO: the right IAM foundation

Self-hosted enterprise SSO gains value when stable issuer, governance, audit, connectors and evidence live in the same private IAM foundation.

Read →
Architecture5 min

Why machine identity belongs in private IAM

Service accounts, secrets, certificates, SPIFFE and PKI give the IAM control plane the machine depth required by critical applications.

Read →
Doctrine5 min

Operating evidence becomes an IAM asset

Audit, exports, migration, runbooks and reversibility turn IAM into a defensible foundation for product, platform and security teams.

Read →
Architecture5 min

SaaS, open source or private appliance: choosing the right product model

The right identity choice depends on the operating model, sovereignty, reversibility and the capabilities already available.

Read →
Vision4 min

Sign-in as a trust surface

Sign-in gives the first signal of control: clear identity, governed access, stable experience and available evidence.

Read →
Product4 min

Entries, roles and exits as a product journey

The access lifecycle becomes clearer when it is handled as a product journey: entry, role, change, exit and evidence.

Read →