Govern
Authentication And Identities
Choose how people and services authenticate and how principals and groups are represented in Duck.
Use this guide when you are setting the foundation for access control.
Inputs
- your identity provider choice
- service-auth requirements
- an owner for principal and group lifecycle
Flow
- choose the primary auth path for people
- choose the approved auth path for automation
- define how principals and groups are created and maintained
- avoid broad shared credentials except for explicit service use cases
What Good Looks Like
- people authenticate through the organization’s intended identity path
- service identities are scoped narrowly
- groups represent real access domains, not one-off convenience buckets