CerbiShield / Governed Applications
Identity stays with Entra.
Control lives with the workload.
A governed application is a stable, tenant-scoped identity for the software participating in Cerbi governance. Associate existing workload principals, authorize access, and retain evidence across the lifecycle.
Shipped capability
Register.
Authorize.
Revoke. Audit.
Tenant administrators authenticate with Microsoft Entra. Cerbi validates workload tokens, enforces viewer/editor assignments server-side, and requires an active installation entitlement.
Revoking an assignment or disabling an application invalidates cached authorization. Subsequent unauthorized access is denied; authorization fails closed.
- 01
Register
Create a stable, tenant-scoped governed application.
- 02
Authorize
Associate existing Entra workload principals; assign viewer or editor access.
- 03
Govern
Validate the workload token and active installation entitlement for governed access.
- 04
Observe
Read back governance profiles and review the recorded lifecycle.
- 05
Revoke
Revoke an assignment or disable the application; authorization fails closed.
- 06
Audit
Retain the authorization lifecycle, including changes and denials.
Clear identity boundaries.
| Microsoft Entra | Cerbi |
|---|---|
| Owns customer identities and issues workload tokens. | Registers tenant-scoped governed applications and associates existing principals. |
| Remains the external identity authority. | Validates workload identity, installation entitlement, and viewer/editor authorization. |
| Customer credentials remain with the customer’s identity systems. | Supports governance-profile creation and read-back, assignment revocation, application disablement, and lifecycle audit. |
Cerbi does not create customer credentials or trust role claims supplied in the request body. Authorization denial is an access-control result; it is not a telemetry event’s terminal governance outcome.
A founder-led logging-risk review
Find the control gap.
Test one workload.
Bring a Scanner finding, a sensitive-field concern, or an evidence requirement. Compare existing controls first. If a gap remains, agree one workload, one policy, an evaluation window, and evidence to review before deciding on a recurring CerbiShield deployment.