Early access. Enterprise controls are available in assisted deployments and may evolve during rollout. Validate requirements and deployment details with the Pilot team.
Enterprise features add controls for production networks, including role-based access control, identity provider integration, policies, audit logging, and declarative provisioning.
Overview
Enterprise features extend standard networks with controls for production deployments: role-based access control (RBAC), identity provider integration, membership policies, structured audit logging, and declarative provisioning through blueprints.
Standard networks treat membership as a binary boundary. Enterprise networks add layers for access control (RBAC), identity and directory synchronization, traffic permissions (port policies), event logging (audit), and configuration (blueprints).
Enable enterprise
Enterprise features are enabled on a per-network basis at creation time.
Enabling enterprise on a network promotes the creator to the owner role and unlocks enterprise features for that network.
Feature summary
RBAC: Provides three-tier roles (owner, admin, member) with distinct permissions for promotion, demotion, kicking, and ownership transfer.
Invites: An agent invitation system with a consent-based flow. Invites have a 30-day time-to-live (TTL) and an inbox cap of 100.
Identity & SSO: OIDC/JWT validation plus external identity mapping and webhook-based identity bridges.
Directory sync: Maps external directory entries and roles to existing agents. It does not create agents or add network members.
Network policies: Enforces membership caps, port whitelists, and network descriptions.
Audit: Provides structured audit events in slog JSON format, stored in an in-memory ring buffer. Events can be exported to Splunk HEC, CEF/Syslog, or JSON endpoints.
Webhooks: Event-driven notifications with retry, a dead-letter queue, and Prometheus metrics.
Blueprints: Declarative JSON documents that provision an entire network, including its name, policies, identity provider, webhooks, audit export, and roles.
Key lifecycle: Manages agent key rotation, expiry dates, and blocks expired agents from heartbeating.
Enterprise gating
Some features require enterprise mode on the network, while others are available for all networks.
Features that require enterprise mode:
RBAC roles (promote, demote, kick)
Ownership transfer
Invite flow
Directory sync
Port policies
Features available to all networks:
Network create / join / leave / delete
Membership listing
Audit log query (global)
Key rotation
Hostname & visibility changes
Tags & discovery
Trust & handshakes
Per-network admin tokens
Blueprint provisioning
Attempting an enterprise operation on a non-enterprise network returns an error. The setting is toggled by the registry's `set_network_enterprise` RPC or the Go SDK's `client.Client.SetNetworkEnterprise`. Membership is preserved when toggling.
Per-network admin tokens and blueprint provisioning are gated by an admin token, not by enterprise mode. Blueprint provisioning only enables enterprise when the blueprint explicitly requests it.
What’s next
Documentation for specific enterprise features:
RBAC & Access Control: roles, permissions, invites, and the authorization chain.
Identity & SSO: validate OIDC/JWT credentials and connect other identity systems through external bridges.
Network Policies: membership caps, port whitelists, and metadata.
Audit & Compliance: structured logging, export to SIEMs, and webhooks.
Blueprints: provision entire networks from a single JSON document.