All evidenceGRD-02 / Identity & access

How does Connect control identities and devices?

Which access and device controls exist today?

Direct answer

Connect combines Argon2id passwords with short-lived access tokens, rotating refresh sessions, visible devices and targeted session revocation. FIDO2/WebAuthn credentials, email verification, token-bound password recovery, confirmed account deletion, panic mode and duress-password paths are implemented.

Authentication, device management and administrative access controls in the current web and API implementation.
Claim ledger04 ENTRIES
IAM-01Implemented

Passwords use Argon2id and access tokens remain short-lived.

Evidence basis

Authentication service, configuration bounds and negative route tests.

Deliberate boundary

Secure password storage prevents neither phishing nor compromised endpoints.

IAM-02Internally evidenced

Refresh tokens rotate and reuse revokes the affected token family.

Evidence basis

Session logic and automated reuse/revocation tests.

Deliberate boundary

An already compromised unlocked endpoint remains a separate risk.

IAM-03Implemented

Devices, sessions, login history and passkeys are manageable security objects.

Evidence basis

WebAuthn routes, device/session endpoints and management interfaces.

Deliberate boundary

No tenant model, SSO or SCIM provisioning.

IAM-04Internally evidenced

Email verification, password recovery, account deletion, panic mode, duress-password access and device revocation use separate confirmed flows.

Evidence basis

Authentication routes, security interfaces and negative tests for verification, reset, deletion, panic, duress authentication, push removal and local browser cleanup.

Deliberate boundary

Server revocation cannot physically erase an endpoint that remains offline or compromised. Local cleanup runs on the next eligible sign-in path, can be blocked by open browser state and reports that condition explicitly.

What does not follow
  • Passkeys do not replace organisational policy or MDM.
  • Device verification is not forensic endpoint integrity validation.
  • The current production release is not a complete zero-trust IAM system.
Evaluate before adoption
  1. 01How are invitations, role changes and departures approved?
  2. 02Which devices may participate and how quickly must they be revoked?
  3. 03Are SSO or SCIM mandatory before rollout?
FAQ / FACTS

Short answers

Which access and device controls exist today?

Yes. The implementation includes FIDO2/WebAuthn registration, authentication and removal. This is not an external certification of the full authentication model.

Yes. Devices and related sessions can be revoked; the effect should be exercised regularly in the actual operating model.