gabriel / musehub public
docs patch update-architecture-docs #3 / 3
AI Agent gabriel · 8 days ago · Aug 24, 2026 · Diff

docs: add MuseHub cloud identity/AWS operating model and Google Workspace identity architecture docs; ignore .DS_Store

sha256:eb0928124669c933c0ef852bea1ad0c56649cf21bd7e9663c3b51004771b0591 sha
+71 symbols
2 changed · 1057 in snapshot files
sha256:e5ed5a6f5fd6a2c6575fa6eee51b290c375fc816d9e8f696af84816c1a606fdb snapshot
+71
symbols added
2
files changed
1057
files in snapshot
0
dead code introduced
Semantic Changes 71 symbols
+ docs/
+ src/
+ tests/
+ tools/
+ MuseHub AWS and Google Workspace Identity Architecture section MuseHub AWS and Google Workspace Identity Architecture L1–312
+ AWS account topology section AWS account topology L38–53
+ Root email aliases section Root email aliases L47–53
+ table section table L40–44
+ Administrative operating rules section Administrative operating rules L204–226
+ Do section Do L206–216
+ Do not section Do not L216–226
+ Architecture at a glance section Architecture at a glance L15–38
+ code[mermaid] variable variable code[mermaid] L17–30
+ Current decisions and rationale section Current decisions and rationale L226–238
+ table section table L228–237
+ Document maintenance section Document maintenance L300–312
+ Glossary section Glossary L285–300
+ table section table L287–299
+ IAM Identity Center configuration section IAM Identity Center configuration L95–111
+ table section table L97–106
+ Identity and access model section Identity and access model L53–95
+ Authentication: Google Workspace section Authentication: Google Workspace L55–67
+ Authorization: IAM Identity Center section Authorization: IAM Identity Center L86–95
+ Provisioning: SCIM section Provisioning: SCIM L67–86
+ Production-readiness sequence section Production-readiness sequence L270–285
+ Purpose section Purpose L7–15
+ Remaining work section Remaining work L238–270
+ Governance and operations section Governance and operations L260–270
+ Identity and access section Identity and access L240–250
+ Infrastructure and deployment section Infrastructure and deployment L250–260
+ Root-user and credential posture section Root-user and credential posture L143–185
+ Existing deployment IAM user section Existing deployment IAM user L165–176
+ Root access keys section Root access keys L159–165
+ Root users section Root users L145–159
+ SSH keys are different from AWS access keys section SSH keys are different from AWS access keys L176–185
+ User lifecycle section User lifecycle L111–143
+ Changing access section Changing access L123–127
+ Offboarding a teammate section Offboarding a teammate L127–143
+ Onboarding a teammate section Onboarding a teammate L113–123
+ Verification commands section Verification commands L185–204
+ code[bash] variable variable code[bash] L189–194
+ MuseHub Cloud Identity and AWS Account Operating Model section MuseHub Cloud Identity and AWS Account Operating Model L1–326
+ Purpose section 1. Purpose L7–17
+ Programmatic and deployment access section 10. Programmatic and deployment access L201–218
+ Target state for automation section Target state for automation L207–218
+ Onboarding a teammate section 11. Onboarding a teammate L218–231
+ Offboarding a teammate section 12. Offboarding a teammate L231–242
+ Security work completed section 13. Security work completed L242–257
+ Remaining work section 14. Remaining work L257–286
+ Identity and authorization section Identity and authorization L259–267
+ Production infrastructure section Production infrastructure L267–278
+ Security follow-up section Security follow-up L278–286
+ Verification checklist section 15. Verification checklist L286–302
+ Sensitive-data handling section 16. Sensitive-data handling L302–316
+ Change-management rule section 17. Change-management rule L316–326
+ Architecture at a glance section 2. Architecture at a glance L17–45
+ code[mermaid] variable variable code[mermaid] L19–37
+ System responsibilities section 3. System responsibilities L45–56
+ table section table L47–55
+ AWS account inventory section 4. AWS account inventory L56–73
+ table section table L60–65
+ Workforce identity authority section 5. Workforce identity authority L73–91
+ Required rule section Required rule L85–91
+ Authentication and provisioning section 6. Authentication and provisioning L91–130
+ 1 SAML authentication section 6.1 SAML authentication L93–107
+ table section table L97–104
+ 2 SCIM provisioning section 6.2 SCIM provisioning L107–120
+ 3 Deprovisioning behavior section 6.3 Deprovisioning behavior L120–130
+ IAM Identity Center configuration section 7. IAM Identity Center configuration L130–148
+ Current permission assignment section Current permission assignment L136–148
+ Human AWS access procedure section 8. Human AWS access procedure L148–170
+ Production safety check section Production safety check L162–170
+ Root mailbox and root-user model section 9. Root mailbox and root-user model L170–201
+ Root-user rules section Root-user rules L192–201
+ table section table L174–179
Files Changed
+2
1057 in snapshot

0 comments

No comments yet. Be the first to start the discussion.

To add a comment, use the Muse CLI: muse hub commit comment sha256:eb0928124669c933c0ef852bea1ad0c56649cf21bd7e9663c3b51004771b0591 --body "your comment"