capabilities / backend-owned control

Capabilities

Anchor connects resource inventory, account operations, policy, sessions, posture, and evidence so privileged work stays governed from request to review.

capability backend signal why it matters
01 Resource truth
Inventory + accounts

Resources, privileged accounts, scopes, owners, status, and metadata stay in one backend model.

02 Policy control
RBAC + effective policy

Roles, scoped access, policy bindings, and resolved controls explain who can do what.

03 Credential work
Verify / rotate / reconcile

Sensitive account operations run as tracked jobs with step results and operational evidence.

04 Session access
Anchor Connect

Brokered sessions stay tied to actor, target, account, reason, policy, and component trust.

05 Review posture
Logs + Compass

Events, audit records, drift, stale access, failed work, and ratings become review signals.

06 API automation
Same backend path

The UI and API use the same objects, jobs, policy checks, and evidence model.