Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.5 KiB

Identity Federation Implementation Template

Federation Details

Setting Value
Azure AD Tenant ID
Federated Domain
AD FS Farm Name
AD FS Service URL https://fs.___/adfs/ls/
Federation Protocol SAML 2.0 / WS-Federation
Backup Auth Password Hash Sync / Pass-Through Auth

AD FS Configuration

Setting Value
AD FS Version
Service Account gMSA recommended
Token-Signing Cert Expiry
Auto-Rollover Enabled Yes / No
WAP Deployed Yes / No

Claims Rules

Rule Name Source Attribute Claim Type Description
UPN userPrincipalName NameID Primary identifier
ImmutableID objectGUID (base64) ImmutableID Azure AD anchor
Email mail emailaddress User email

Validation Results

Test Status Notes
AD FS metadata reachable Pass/Fail
Token-signing certificate valid Pass/Fail
Domain federation configured in Azure AD Pass/Fail
SP-initiated SSO flow Pass/Fail
IdP-initiated SSO flow Pass/Fail
MFA enforcement Pass/Fail
Smart lockout configured Pass/Fail
Sign-in logs showing federated auth Pass/Fail

Disaster Recovery

  • Password hash sync enabled as backup
  • Staged rollout to managed auth tested
  • Break-glass cloud-only admin accounts created
  • AD FS farm disaster recovery plan documented
  • Secondary AD FS farm in DR site (if applicable)