Authentication

Sign-in uses Zoho OAuth for login and AWS Cognito for identity, then maps each user to a role.

Auth model

Users sign in through Zoho OAuth, which handles the login handshake. Identity is backed by AWS Cognito, so every authenticated user resolves to a single stable identity across the platform. Once identity is established, the platform maps the user to a role, and that role determines which approval gates and management actions are available.

Sign-in flow

The flow is a straight handoff: the browser initiates OAuth with Zoho, Zoho returns to the platform, Cognito establishes identity, and the platform attaches the mapped role to the session.

UserZoho OAuthAWS CognitoRole mappingUPDP sessionloginidentityrole
Sign-in resolves a Zoho OAuth login into a Cognito identity, then maps it to a UPDP session role.

Sessions and roles

A session carries the user identity and the assigned role. The role is the single source of authority for what a user can do: which gates they can approve, and whether they can manage the team. Members hold view-first access and can request elevation, which an Admin confirms.

RoleWhat it controls
AdminApproves account setup and IAM role creation, manages the team, and confirms role elevation requests.
Tech LeadReviews generated Terraform and guards the deploy at the tech-lead gates.
Project ManagerReviews documentation and owns the final handover gate.
MemberView-only access to runs and reports; can request elevation, which an Admin confirms.

Nothing critical applies without a human gate

Roles decide who owns each approval gate. A run never applies infrastructure or completes handover until the role that owns the relevant gate approves it.
Was this page helpful?View as llms.txt