People & posture
Accounts, tokens, directories, and conditions on the device itself.
Accounts
- Local accounts — Two roles: Admin changes things, User reads. That is the whole model.
- API tokens — Sent as a bearer token, acting as you with your role until they expire or you delete them. Shown once.
- Service accounts — For machines. One owns tokens and cannot sign in, so its access does not end when the person who set it up leaves. Creating one needs a signed-in admin — an API token cannot do it, so a leaked token cannot manufacture more of itself.
Directory login
Pro. People sign in with their LDAP or Active Directory credentials, and directory groups map to mesh groups so membership follows the directory rather than being maintained twice.
An expired licence still authenticates people through the directory. Expiry must never lock everyone out.
Single sign-on and provisioning
- OIDC is a preview — Free while it is one, and honestly labelled: it has had less real-world exposure than the rest of this list.
- SCIM — Creating, renaming, groups, and deactivation that ends sessions, deletes tokens and revokes devices. Only three attributes are kept — MangoFly is not trying to be your directory. No real tenant has been pointed at it yet.
Posture checks
Pro. A policy can require the device to satisfy conditions rather than merely belong to a group: a minimum MangoFly version, network ranges it must or must not be inside, per-OS version rules, or required programs. The Failing Now column shows how many devices currently do not satisfy a check — the number to look at before attaching it to anything important.
Enforcing checks that already exist is never licence-gated, and neither is deleting them. An expired licence freezes changes; it does not quietly stop enforcing what you asked for.