At Radiant, we treat identity and access management as part of the infrastructure control plane rather than as a separate login layer. Every action across an AI factory, from provisioning GPU capacity and configuring networks to accessing storage or deploying Kubernetes workloads, begins with an identity, a permission and a decision about whether that action should proceed.
The challenge is that AI factories are operated by far more than people signing into a console. Service accounts call APIs, Kubernetes workloads access platform resources, nodes communicate with management services and automated systems continuously provision, monitor and repair infrastructure. As these environments scale, identity must remain consistent across every service and interface or access will fragment into separate systems that become increasingly difficult to govern.
Radiant brings authentication, identity federation, authorization, workload identity, lifecycle provisioning and audit into a common platform model, allowing identity and policy to follow users and workloads across compute, networking, storage and managed services. Together, these capabilities create a clear chain of control from the identity requesting access to the resource being accessed and the audit record generated by the decision.
Radiant IAM at a Glance
One Identity Layer Across the Platform
A consistent access model begins with a trusted understanding of who the user is. We connect the Radiant platform to customers’ enterprise identity providers through standards-based federation, using OIDC and SAML 2.0 to provide single sign-on across platform and tenant-facing services.
Domain-based identity routing allows organizations with multiple email domains, subsidiaries or operating entities to direct users to the appropriate identity provider, while token validation checks the signature, issuer, audience, expiration and required claims before an identity is trusted. This reduces the need to create and maintain separate cloud credentials while allowing customers to retain control through their established enterprise identity systems.
The same federated model extends across the dashboard, command-line interface, APIs and managed services, so identity remains consistent regardless of how infrastructure is accessed. Directory integration also allows user identities and group memberships to be resolved by dependent services such as high-performance storage, where enterprise identity must translate into POSIX permissions without creating a second access model.
Once an identity has been established, Radiant carries that context into the authorization layer, where the platform determines precisely what the user can do and where those permissions apply.
Least Privilege Across the Infrastructure Stack
We apply role-based access control (RBAC) across managed services and infrastructure, allowing permissions to be defined around specific actions, scoped to environments such as development, staging or production, and aligned with operational functions such as infrastructure provisioning, image management or auditing.
Roles can be assigned to enterprise-managed groups rather than individual users, with access inherited through group membership sourced from identity-provider claims or synchronized through automated provisioning. This allows the customer’s organizational structure to become the basis for infrastructure access while reducing the inconsistency and administrative overhead associated with managing permissions one user at a time.
Our organization-level guardrails extend this control across projects, clusters, networks, storage and compute resources, where policies cascade through subordinate environments and cannot be weakened through lower-level configuration. If an attempted deployment conflicts with an organization’s security policy, the platform can deny the action when the resource is created or updated and record the decision in the audit trail.
This creates a consistent least-privilege model for human users, but the same discipline must also extend to the much larger and faster-moving population of machine identities operating throughout the AI factory.
An Automated Identity Lifecycle
Access can become outdated whenever an employee joins a team, moves between projects or leaves the organization, and the risk increases when each infrastructure service requires a separate manual update. We close that gap by connecting identity lifecycle changes directly to the Radiant authorization layer.
Radiant supports automated user and group lifecycle management through SCIM 2.0, enabling enterprise identity systems to create, update and remove identities while synchronizing group membership across managed services. Federated groups become first-class access-control objects that can be connected to roles and policies, allowing an update in the customer’s enterprise directory to propagate through the platform without requiring separate changes in every infrastructure domain.
Our programmatic interfaces extend this operating model to organizations, projects, users, service accounts and logs, allowing identity administration to become part of repeatable infrastructure workflows rather than a queue of manual support requests. Access can therefore move with the organization while the policies governing it remain consistent.
Automated lifecycle management reduces permission drift, but the most sensitive infrastructure operations still require stronger protection at the point of access.
One Security Boundary Across Every Interface
We protect administrative access with multifactor authentication and allow authorized administrators to enforce federated SSO across an entire tenant. Once that policy is enabled, regular users can be prevented from falling back to local usernames and passwords, reducing the number of credentials that must be stored, monitored and eventually revoked.
These controls apply consistently across the Radiant dashboard, CLI, APIs and management interfaces, creating a common authentication boundary around sensitive infrastructure operations. A privileged action therefore receives the same identity protection regardless of whether it is initiated by a person using the console or by an automated workflow calling an API.
Consistent protection limits how administrative access can be obtained, while comprehensive auditing makes every use of that access visible and accountable.
From Access Decision to Audit Record
We generate audit records across authentication events, authorization decisions and management or control-plane API activity, capturing the context required to understand not only what changed, but also who initiated the change and why the platform allowed or denied it.

Radiant connects the acting identity, access request, evaluated policy and authorization outcome in a traceable audit record. These records can include the tenant, project, region, service, resource identifier, acting identity, timestamp, source address, requested action and authorization result. Customers can retain and export this information into their wider security operations environment, allowing Radiant activity to be investigated alongside events from other enterprise systems.
Operate Securely at Scale with Radiant FlightDeck
Across the Radiant platform, enterprise federation establishes trusted identities, role-based access limits what they can do, workload identity extends the same controls to machines, lifecycle automation keeps permissions current and audit records make every decision traceable. Radiant FlightDeck brings these capabilities into the operational context of the infrastructure they govern.
From FlightDeck, operators can manage users, roles, service accounts, workload identities, MFA and OIDC federation alongside security groups, encryption and key management. They can also search logs, audit trails, administrative actions, filesystem activity and policy events across infrastructure and tenants, creating a connected view of identity, policy and operational activity.
Because state, identity, policy and inventory share one data model, an infrastructure event can be traced from the affected component to the workload it supports, the tenant that owns it, the policy governing it and the audit record of every action taken. As AI factories become larger and more automated, FlightDeck keeps identity connected to infrastructure state, making access control visible, traceable and operable from one place.
‍