Dashboard
Phases 1-9 complete: foundation, Authentik/AD sync, correlation, User/Group View, Access Catalog, request/approval workflow with SoD checks, access reviews with remediation, and a transaction-atomic audit trail with CSV evidence export. OIDC login (Phase 10) is next.
People can request catalog access at Request Access; approvers review it at Approvals, with SoD conflicts flagged automatically. Approved requests actually provision access in Authentik/AD (dry-run-gated — see Settings). Start bulk certification campaigns at Review Scopes; revoked access lands in the Remediation Queue for explicit processing. No login exists yet, so these pages use an explicit person-picker instead of a session — Phase 10 closes that gap.