Enter the governed workspace.
Authentication proves who is present. AVC then resolves organization, membership, role, capability and session scope before consequential actions become available.
- Identity before authority
- Signing in never grants unrestricted access.
- Organization scoped
- Every session belongs to an explicit principal and tenant boundary.
- Evidence retained
- Protected actions remain attributable, reviewable and revocable.
Protected entry
Access
AVC Platform
01AuthenticateCloudflare Access and the configured identity provider.
02Resolve scopeAVC principal, organization, role, capability and session.
03Enter workspaceOnly approved surfaces and actions become available.
Configuration required. The public origin never collects passwords or stores identity tokens.
Private alpha boundary
Operator applications remain subject to their own security, deployment and production-approval gates.