Documentation
Running SanctiKey.
These are the operator guides: what the console does, what each permission tier can actually do, and how to wire your identity provider to it. They describe the product as deployed, not as planned.
Anything you can count is generated from the code that enforces it. The permission tables in Users and permissions are built from the same scope definitions your session is authorized against, so they cannot quietly go stale the next time a capability is added.
Available now
Users and permissions
The four permission tiers and the exact scopes each one carries, how partitions differ from permissions, and what happens when a user holds more than one tier.
Federation
Connecting SAML or OIDC single sign-on, and the step people miss: a federated user arrives with no permissions until an administrator assigns a tier.
Being written
These sections are listed rather than half-written. Every one of them describes a feature that is already deployed and usable from the console today; only the guide is outstanding. If you need one of them before it lands, ask us and we will walk you through it directly.
Getting started
First administrator sign-in, multi-factor enrollment, and a tour of the console.
Keys
Creating keys, key types and usage, rotation posture, and the deletion lifecycle.
Certificate authority
Hierarchy, CSR signing, issuance, revocation, and the public CRL and OCSP endpoints.
Audit
What is recorded, how to export it, and how long it is retained.
Escrow and Keyout
What conveys and what does not, in the same words as the legal terms.
Limits
Quotas, throttling, and what happens when you reach a hard cap.