> ## Documentation Index
> Fetch the complete documentation index at: https://veridical-dev.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Identity and governance

> SSO, MFA, membership, policy, and audit

Hosted identity is verified by WorkOS and mapped to a Veridical workspace.
Owners manage membership and the supported owner, admin, member, and viewer
roles. Every control-plane mutation is authorized against the workspace and
written to the audit log.

Enterprise governance includes:

* required SSO and MFA policy;
* SCIM enablement and directory lifecycle policy;
* workspace/repository review and analyzer policy;
* tier, quota, model-provider, BYOK, and execution routes;
* residency, retention, CMK reference, and deployment mode;
* audit export and integration policy.

Deployment license features gate BYOC/self-host, SSO, SCIM, audit export, CMK,
and BYOK independently. Missing or expired entitlements fail closed.

Identity-provider configuration and directory activation remain operator
actions in WorkOS and the customer's identity system.
