Identity provider register
Tracks local pilot identity, future OIDC provider and enterprise client SSO paths.
Internal GCCAP operating surface
GCCAP does not delete operating records, trial packs, hardware activation surfaces or evidence automation layers. They are preserved for authorised client portal, command-centre and internal operating use while the public website stays clean for airline first impressions.
Open portal accessInternal GCCAP surface
Internal system phase creates the identity control layer needed before GCCAP can safely onboard external airline and caterer users at scale. It defines the migration path from pilot passwords and admin tokens toward managed identity, MFA, SSO, hardened sessions, user lifecycle controls and access reviews.
StatusInternal / restricted surface. Not part of the public client walkthrough.
Operational layer
The identity foundation does not pretend GCCAP has final enterprise identity already connected. It creates the control plane that decides when GCCAP can move from local pilot access to production MFA and SSO.
Tracks local pilot identity, future OIDC provider and enterprise client SSO paths.
Defines which users must have MFA before external or production use.
Defines HTTPS-only cookie sessions, idle timeouts, revocation, audit and session secret requirements.
Defines creation, role changes, disablement, quarterly reviews and least-privilege role boundaries.
Decision clarity
Build 17 keeps the distinction explicit so GCCAP does not mistake local test access for enterprise-grade identity.