Integrations
Easytiou fits into an existing information system without replacing identity, fleet management, SIEM or business procedures.
Identity providers
The provider is selected according to country, organisation policy, requested level and availability. A versioned mapping translates the external level into an Easytiou level.
- Easytiou creates a context-bound request and redirects the user to the authorised provider.
- The provider authenticates the person and returns a verifiable assertion.
- The backend validates issuer, audience, freshness and achieved level.
- Only necessary attributes and their provenance are linked to the account.
An alternative provider is used only when pre-approved and compatible with the required level. Any degradation remains visible.
Timestamp providers
The evidence-bundle digest may be sent to a timestamping service to establish its existence at a given time. The provider response is archived with the report.
- The full document is not sent when only its digest is required.
- The provider and policy appear in the manifest.
- A failure never silently becomes a success.
- Failover to an alternative provider is logged.
SSO, directory and fleet management
| Integration | Purpose | Trust data |
|---|---|---|
| Enterprise SSO | Authenticate administrators and employees | Session, group and authentication method |
| Directory / SCIM | Provision accounts and roles | Stable identifier, membership and status |
| MDM/UEM | Assess a managed device | Ownership, compliance and freshness |
| Enterprise PKI | Recognise a fleet device | Certificate chain and proof of possession |
The certificate must be valid, not revoked, bound to a key held by the device and, where policy requires it, checked against MDM/UEM.
SIEM and security alerts
An organisation can receive minimised security events over Syslog with TLS or, depending on plan, a signed webhook. Public families include device revocation, post-revocation attempts, attestation failure, protocol anomaly and provider failover.
{
"schema_version": "1.0",
"alert_id": "alt_01J...",
"category": "DEVICE_REVOKED",
"severity": "high",
"event_ref": "evt_01J...",
"occurred_at": "2026-10-04T09:41:22Z",
"recommended_action": "Review active sessions"
}Messages never include tokens, biometric data, challenge secrets or information that could reproduce a private signal.
Webhooks
Candidate business webhooks announce a status change without transferring the full evidence bundle. The consumer then retrieves the authorised resource through the API.
- Body signature and delivery timestamp.
- Stable event identifier for deduplication.
- At-least-once delivery: consumers must be idempotent.
- Bounded retries with delivery status in the administration console.
- Secret rotation without planned interruption.
Verify signature and freshness, then retrieve the resource from the API before any irreversible operation.
Videoconferencing
Teams, Zoom or equivalent connectors are planned to bind evidence to a workstation and meeting instance. This requires an application or plugin approved by the relevant platform and is not part of the currently available baseline.
Try “identity”, “MDM” or “SIEM”.
