Companies start from an identity source
In many organizations, IAM first means Active Directory, Microsoft Entra ID, Okta or Google Workspace. These systems already carry users, groups, authentication rules and IT operating habits.
That foundation is an important asset. HankoShell sits above these sources to give applications a stable, readable and operable access surface.
HankoShell’s role above the directory
HankoShell becomes the application control plane. Identity sources keep accounts and corporate authentication. HankoShell turns those signals into a product access model: tenants, roles, application entitlements, session policies, MFA, audit and exports.
Applications then consume HankoShell as a stable OIDC issuer. They get a clear contract with discovery, JWKS, OIDC clients, redirect URIs, themes, sessions and evidence.
What changes for applications
A critical application needs to know who can access, in which tenant, with which role and under which conditions. AD, Entra, Okta or Google Workspace groups bring the enterprise context. HankoShell translates that context into governable application decisions.
This layer becomes useful when several applications, enterprise customers or environments need to share the same access logic. The model stays coherent for product, platform, IT and security teams.
Value for existing organizations
For an equipped enterprise, HankoShell extends the existing foundation. Directories and IdPs remain the entry points. Applications gain a control plane dedicated to their needs: enterprise SSO, application roles, access reviews, audit, MCP connector, exports and reversibility.
This view also helps B2B software vendors. A customer may arrive with Entra ID, Okta or Google Workspace. HankoShell provides the surface that connects that customer identity to tenants, entitlements and evidence expected by the product.
The right product message
HankoShell goes beyond the sign-in page. HankoShell is the layer that turns existing identity sources into controlled application access.
The message becomes simple: keep your identity sources, give applications a private, operable and defensible IAM control plane.