Cbox ID
Admin guides
Admin guides
These are for the administrator of an organization — the person in the console
who connects an identity provider, invites the team, registers apps and answers to
an auditor. They are not developer documentation: building against Cbox ID lives
in the framework docs that ship with
cboxdk/laravel-id,
and deploying the platform lives under
operations.
Each guide is the long form of the "?" beside a page title in the console. The console explains itself in two or three sentences; when that is not enough, the "Read the guide" link lands here.
Getting a new organization running
- Roles — decide who can do what before you invite anyone.
- Apps & API keys — register the first app people will sign in to.
- Single sign-on — let people use the company account they already have.
- Social sign-in — Google, GitHub, Apple and the rest, plus how connecting one to an existing account works.
- Sync users in — have your provider create and deactivate people for you.
Keeping it running
- Sync users out — push your people into your other SaaS products.
- Webhooks — get told when something happens.
- Inline hooks — have a say while it happens.
- Token vault — credentials your apps use elsewhere.
- Agent approvals — approving something an app or agent asks to do as you.
- Trusted devices — a phone as the authenticator that answers those approvals.
Proving it is under control
- Access reviews — certify who still needs what.
- Role conflicts — roles that must never be combined.
- Activity log — the tamper-evident record of every change.