Vendor Kit

Six reference products on top of the Aurelion kernel.

Aurelion Lens, Glyph, Journey and Pulse are live reference implementations. Lobby (CIAM) and Throne (PAM) are next. The kit bundles forkable product source, a shared design system, pitch decks, SBPMs and enablement material — so partners can ship operator-grade identity-security products and pitch them, not just compile them.

What the Vendor Kit Is

A product layer plus the material to take it to market.

The vendor kit is more than forkable source. It is a curated set of operator-facing applications that each consume a different combination of kernel engines, packaged together with the presentations, SBPMs, comparison sheets and demo scripts partner teams need to pitch and position the platform. Four products are live today — Lens, Glyph, Journey and Pulse — covering ISPM, workforce IdP, lifecycle operations and ITDR. Two more — Lobby (CIAM) and Throne (PAM) — are next on the roadmap. Every product reuses the same inventory, the same engines and the same design system, but ships with its own brand identity.
  • Four live reference products

    Lens, Glyph, Journey and Pulse — covering ISPM, workforce IdP, ILM and ITDR on a single kernel. Fork them as OEM products or run them as live evaluation demos.
  • Source layout

    Each product is a Next.js or React app with its own theme tokens and feature slices, wired to the Aurelion kernel.
  • Shared design system

    Restrained-glass operator UI: one theme file, one set of tokens, per-product brand accents.
  • Pitch decks, SBPMs & enablement

    Sales-ready presentations, SBPMs, comparison sheets and demo scripts — so partner teams can pitch and position the kit, not just compile it.
ISPM · Identity Analytics

Aurelion Lens

See every identity, audit access, surface the risk posture. Lens is the ISPM and identity analytics layer of Aurelion — continuous visibility, audit and risk posture for every identity. CSV ingest sessions, column mapping and reusable policy runs over normalized access facts surface orphaned, unused, privileged and terminated-subject access as severity-graded findings with actionable remediation suggestions.

  • Ingest sessions
    CSV imports, dataset inspection and mapping into the shared inventory model.
  • Policy runs
    Orphaned, unused, privileged and terminated-subject access — deterministic policies on real facts.
  • Findings & recommendations
    Severity-graded findings with actionable remediation suggestions per access kind.
Engines used
  • Access analysis engine
  • Effective access projection
  • Inventory (access facts, findings)
  • Audit reporting
lens.aurelion.local
Aurelion Lens interface screenshot
ILM · Employee Lifecycle

Aurelion Journey

Operate the identity lifecycle as a live case queue. Journey turns the kernel's lifecycle orchestration into an operator UI for identity-change workflows. Cases are derived from MQ events, manual triggers and HR-system feeds. Each case carries the subject, lifecycle state transition and the runs that must complete to close it.

  • Case queue
    Active, attention and today buckets across employee and NHI subjects.
  • State transitions
    Onboarding, leaver, on-leave, active — typed transitions with audit trail.
  • Operator surface
    Filters, manual cases, automation config and lifecycle policies in one console.
Engines used
  • Lifecycle orchestration engine
  • Identity event pipeline
  • Inventory (identities, lifecycle state)
  • ITSM gateway
journey.aurelion.local
Aurelion Journey interface screenshot
IdP · Workforce Identity

Aurelion Glyph

The identity authority for workforce and machine access. Glyph is the workforce IdP — OIDC, SAML, MFA, passkeys and token issuance for employees, contractors and service identities, with first-class AuthZen support for externalised authorization decisions. Pairs with Journey for lifecycle and Pulse for live threat response.

  • Authentication
    Password, magic-link, MFA and passkeys — first factor through step-up, for workforce and machine identities.
  • Federation & SSO
    OIDC and SAML single sign-on with OIDC discovery and JWKS — one identity authority across the estate.
  • AuthZen PDP
    Externalised authorization decisions over the shared access model, on the AuthZen 1.0 wire protocol.
Engines used
  • Authentication engine
  • AuthZen PDP
  • NHI discovery
  • Identity event pipeline
  • Inventory (workforce identities)
glyph.aurelion.local
Aurelion Glyph interface screenshot
ITDR · Live Threat Surface

Aurelion Pulse

Watch identity threats as they happen. Pulse is the realtime ITDR console — live detections, open incidents and identities at risk streamed from the identity event pipeline over SSE. Detections, incidents and risk projection compose into a single operator dashboard for SOC and identity-security teams.

  • Live detections
    Impossible travel, MFA fatigue, token reuse, anomalous payouts — streamed in realtime.
  • Open incidents
    Investigating, triaging, contained — incident states tracked across the SOC queue.
  • Identities at risk
    Per-identity risk projection from active detections, open incidents and effective access.
Engines used
  • Identity event pipeline
  • Access analysis engine
  • Effective access projection
  • NHI discovery (for service identities)
pulse.aurelion.local
Aurelion Pulse interface screenshot
On the roadmap

Two more products are next.

Lobby and Throne extend the vendor kit into customer identity and privileged access. Both build on the same authentication engine, identity event pipeline and inventory model the live products already use.

Coming soon
CIAM · Customer Identity

Aurelion Lobby

The customer-facing front door of the platform.

Lobby is the upcoming CIAM product — sign-up, sign-in, social and passwordless flows, consent, progressive profiling and customer-account self-service, built on the same authentication engine and inventory model as the rest of the kit.

Engines planned
  • Authentication engine
  • Identity event pipeline
  • Inventory (customer identities)
  • PDP (consent & policy)
Coming soon
PAM · Privileged Access

Aurelion Throne

Govern privileged access — sessions, secrets and break-glass.

Throne is the upcoming PAM — vaulted credentials, just-in-time elevation, session recording and break-glass workflows for human admins and privileged service identities. Built on the same authentication engine, inventory and event pipeline as the rest of the kit.

Engines planned
  • Authentication engine
  • Identity event pipeline
  • Inventory (privileged identities)
  • PDP (elevation policy)
Six products, one foundation

Different operator workflows. Same kernel underneath.

Each product is independent on the surface but reads from and writes to the same shared identity-security model. Findings raised in Lens reference the same subjects Journey closes lifecycle cases on, Pulse correlates against the same effective access projection, and Glyph issues, federates and governs the identities those flows operate on. Lobby and Throne will extend the same model to customer and privileged access.
  • ISPM · Identity Analytics

    Aurelion Lens

    See every identity, audit access, surface the risk posture.

  • ILM · Employee Lifecycle

    Aurelion Journey

    Operate the identity lifecycle as a live case queue.

  • IdP · Workforce Identity

    Aurelion Glyph

    The identity authority for workforce and machine access.

  • ITDR · Live Threat Surface

    Aurelion Pulse

    Watch identity threats as they happen.

  • Soon
    CIAM · Customer Identity

    Aurelion Lobby

    The customer-facing front door of the platform.

  • Soon
    PAM · Privileged Access

    Aurelion Throne

    Govern privileged access — sessions, secrets and break-glass.

Use the Vendor Kit

Fork it, rebrand it, ship it.

Partners can use Lens, Journey and Pulse as starting points for commercial OEM products or as evaluation demos for enterprise customers.