Skip to content
Weave templates

Hybrid Identity & SSO Flow

On-prem Active Directory synchronised into a cloud IdP, HR as the joiner/mover/leaver source via SCIM, conditional access and MFA in the middle, and SAML / OIDC federation out to every application.

Template previewWeave
Rendering…

Make it your own.

{
  "nodes": [
    { "id": "onp",  "type": "pool",      "label": "On-premises identity",              "x": 20,  "y": 60, "width": 380, "height": 420, "fill": "rgba(254,243,199,0.34)", "stroke": "#b45309" },
    { "id": "cidp", "type": "container", "label": "Cloud identity provider",           "x": 460, "y": 40, "width": 340, "height": 560, "fill": "rgba(237,233,254,0.26)", "stroke": "#6d28d9" },
    { "id": "apps", "type": "container", "label": "SaaS & internal applications",      "x": 880, "y": 40, "width": 380, "height": 560, "fill": "rgba(219,234,254,0.26)", "stroke": "#1d4ed8" },

    { "id": "ad",   "type": "user-group", "label": "Active Directory — 4,200 users", "x": 50, "y": 110, "width": 190, "height": 104, "fill": "#fef3c7", "stroke": "#b45309", "bold": true },
    { "id": "adfs", "type": "component",  "label": "AD FS — legacy federation",       "x": 50, "y": 250, "width": 190, "height": 104, "fill": "#fef3c7", "stroke": "#b45309" },
    { "id": "conn", "type": "conveyor",   "label": "Directory sync agent",            "x": 50, "y": 370, "width": 190, "height": 104, "fill": "#fef3c7", "stroke": "#b45309" },

    { "id": "tnt",  "type": "fingerprint", "label": "IdP tenant — SSO",           "x": 490, "y": 90,  "width": 180, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9", "bold": true },
    { "id": "mfa",  "type": "key",         "label": "MFA — FIDO2 + push",         "x": 490, "y": 230, "width": 180, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },
    { "id": "ca",   "type": "gear",        "label": "Conditional access policies","x": 490, "y": 370, "width": 190, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },
    { "id": "scim", "type": "user-group",        "label": "SCIM provisioning",          "x": 490, "y": 480, "width": 180, "height": 104, "fill": "#ede9fe", "stroke": "#6d28d9" },

    { "id": "m365", "type": "briefcase",        "label": "Productivity suite",   "x": 910,  "y": 90,  "width": 170, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
    { "id": "crm",  "type": "storefront",       "label": "CRM — SAML 2.0",       "x": 1090, "y": 90,  "width": 160, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
    { "id": "awsid","type": "aws-iam",          "label": "IAM Identity Center",  "x": 910,  "y": 230, "width": 140, "height": 110, "fill": "#fff7ed", "stroke": "#f97316" },
    { "id": "k8s",  "type": "kubernetes",       "label": "Internal apps — OIDC", "x": 1070, "y": 230, "width": 180, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
    { "id": "ztna", "type": "vpn-tunnel",       "label": "ZTNA gateway",         "x": 910,  "y": 370, "width": 140, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },
    { "id": "leg",  "type": "component",        "label": "Legacy app via app proxy", "x": 1070, "y": 370, "width": 180, "height": 104, "fill": "#dbeafe", "stroke": "#1d4ed8" },

    { "id": "usr", "type": "user-circle", "label": "Employee — managed laptop", "x": 40,   "y": 560, "width": 170, "height": 104, "fill": "#e0f2fe", "stroke": "#0369a1" },
    { "id": "hr",  "type": "clipboard",   "label": "HR system — source of truth", "x": 490, "y": 640, "width": 190, "height": 104, "fill": "#dcfce7", "stroke": "#15803d" },
    { "id": "bg",  "type": "note",        "label": "Break-glass admin accounts — excluded from CA, hardware keys only", "x": 880, "y": 640, "width": 240, "height": 100, "fill": "#fef9c3", "stroke": "#ca8a04" },
    { "id": "log", "type": "bar-chart",   "label": "Sign-in logs to SIEM",      "x": 1160, "y": 640, "width": 180, "height": 104, "fill": "#f1f5f9", "stroke": "#475569" }
  ],
  "edges": [
    { "id": "h1",  "source": "ad",   "target": "conn", "label": "password hash sync" },
    { "id": "h2",  "source": "conn", "target": "tnt",  "label": "sync every 30 min", "thickness": 2 },
    { "id": "h3",  "source": "adfs", "target": "tnt",  "label": "federation, retiring", "style": "dashed" },
    { "id": "h4",  "source": "hr",   "target": "scim", "label": "joiner / mover / leaver" },
    { "id": "h5",  "source": "scim", "target": "tnt",  "label": "provision + deprovision" },
    { "id": "h6",  "source": "usr",  "target": "tnt",  "label": "sign-in", "thickness": 3 },
    { "id": "h7",  "source": "tnt",  "target": "mfa",  "label": "challenge" },
    { "id": "h8",  "source": "tnt",  "target": "ca",   "label": "evaluate policy" },
    { "id": "h9",  "source": "ca",   "target": "mfa",  "label": "require step-up", "style": "dashed" },
    { "id": "h10", "source": "tnt",  "target": "m365", "label": "OIDC" },
    { "id": "h11", "source": "tnt",  "target": "crm",  "label": "SAML 2.0" },
    { "id": "h12", "source": "tnt",  "target": "awsid","label": "SAML to roles" },
    { "id": "h13", "source": "tnt",  "target": "k8s",  "label": "id_token" },
    { "id": "h14", "source": "tnt",  "target": "ztna", "label": "SAML" },
    { "id": "h15", "source": "tnt",  "target": "leg",  "label": "Kerberos delegation" },
    { "id": "h16", "source": "tnt",  "target": "log",  "label": "audit stream", "style": "dashed" },
    { "id": "h17", "source": "bg",   "target": "tnt",  "label": "break-glass", "style": "dashed" }
  ]
}