This edition publishes the evaluation question and work still required. It contains no scored vendor points.
What must be true
- Required applications and authentication methods work.
- Termination removes access within the declared objective.
- Emergency access and recovery can be controlled and audited.
Candidate scope
Two publicly documented offerings form a small pilot. Inclusion is for methodology development, not a claim that these are the only or best choices. Exact tiers and test configurations must be frozen before scoring.
| Offering | Scope | Status |
|---|---|---|
| Microsoft Entra ID | Workforce identity; tenant, license, and required add-ons must be specified. | Unassessed Capability: null Operating: null |
| Okta Workforce Identity | Workforce identity with Identity Engine; purchased products and tiers remain unselected. | Unassessed Capability: null Operating: null |
Evidence still needed
- The exact app roster and selected editions
- Lifecycle, session revocation, and recovery tests
- Implementation effort and complete commercial assumptions
How the evaluation will work
- Fix the workload, organizational assumptions, product editions, and mandatory requirements.
- Publish criterion-specific 0–5 anchors before collecting results.
- Collect reproducible observations, source dates, and operating measurements. Preserve contradictory evidence.
- Use the rubric below without filling unknowns with estimates.
- Have a second reviewer reproduce results. Publish only after both axes reach 80% coverage and critical requirements have explicit results.
| Axis | Criterion | Weight |
|---|---|---|
| capability | Required functions | 40% |
| capability | Representative effectiveness | 30% |
| capability | Evidence and explainability | 15% |
| capability | Required data exchange | 15% |
| operating | Staffing and administration | 30% |
| operating | Environment and deployment | 25% |
| operating | Integration maintenance | 20% |
| operating | Portability and exit | 15% |
| operating | Cost predictability | 10% |
Threshold: 70/100 on each axis. A missing-evidence interval that spans 70 prevents a definitive quadrant label. A critical failure blocks a shortlist recommendation.
Download this research protocol ↓