Public roadmap -- honest

Where LingerCut fits your stack

Beachhead is GitHub org non-human identity. Live means the cut + independent replay path exists in product code. Wait means we have not shipped that connector -- and we will not list Okta as live to look like an IdP app.

Okta / Entra revoke is not our proof

Entra user and Entra service principal are live connectors. Okta is not. After an Okta-class identity event, leftover sessions and grants still need an independent bounce. That is the IR playbook -- not "LingerCut is an Okta app."

GitHub org NHI -- beachhead

Beachhead. Inventory org SSO authorizations and fine-grained PATs labeled CI / non-human, cut, then absence re-list (never clone or push with the PAT). VALID or WITHHELD.

GitHub self-grant

OAuth self-grant revoke plus independent GET /user replay (read-only). Not clone/push.

Google self-grant

OAuth revoke + refresh-token / userinfo / tokeninfo probe. Never send mail or create calendar events as proof.

Google Workspace Admin

Directory users.tokens inventory, delete, then adversarial re-list. Absence is the proof, not the Admin console checkbox.

Entra / Microsoft user

Graph revokeSignInSessions + refresh-token / Graph GET /me probe. Entra cannot be the only verifier of leftover Entra trust. No mail send as proof.

Entra service principal

Machine leftover. Live path when MICROSOFT_SP_LIVE=1 + tenant + app credentials. removePassword then adversarial re-get.

AWS IAM access keys

Deactivate + STS GetCallerIdentity (read-only) or Inactive/absence re-list. Never PutObject or create-resource as proof. AWS deactivate is not an independent bounce by itself.

GitLab group leftovers

Personal / group / project access tokens and deploy tokens. Cut then absence re-list. Never clone, push, or trigger a pipeline as proof. GitLab revoke is not a VALID receipt.

GitLab self-grant

OAuth revoke plus independent GET /user replay (read-only). Refresh-token probe when GitLab issued one. Not clone/push.

Okta as a LingerCut connector

Not built -- and not the point. LingerCut is leftover trust after an IdP event, not an Okta app. Okta/Entra revoke is not our proof. After an Okta-class incident, use the IR playbook and live connectors above.