Delivered for qualified profiles

A governed application lifecycle from publisher to removal

NexinID has delivered a product-neutral application lifecycle for qualified profiles. It keeps publisher review, immutable application versions, organization decisions, human access, runtime admission, and lifecycle cleanup as distinct, auditable steps.

What “delivered” means here

The lifecycle foundation is delivered and has been validated with qualified development profiles. Production approval remains specific to the selected client profile, connector, deployment, and product. This is not an OpenID conformance, certification, every-profile, or universal-production claim.

Lifecycle

Eight governed decisions, not one oversized “install” button

Each stage has its own authority and can fail closed without inventing state in the consuming application.

01

Review the publisher

A publisher establishes its organization and domain evidence. Publisher creation and independent platform review remain separate authorities.

02

Freeze the application revision

The publisher submits an immutable revision with its client profile, redirect and logout behavior, requested privileges, resource audiences, legal links, and runtime expectations.

03

Issue a versioned environment

Development, staging, and eligible production environments keep credentials, endpoints, policy, and revision identity separate. Production promotion is independently reviewed.

04

Review administrator consent

The consumer organization sees the exact publisher, revision, privileges, resources, behaviors, policy evidence, risk, expiry, and commercial association before approving, denying, or narrowing consent.

05

Create the organization installation

An installation binds the approved application environment to one consumer organization. Catalog visibility, payment, or navigation alone does not imply installation or consent.

06

Assign human access

Administrators explicitly assign memberships, groups, or organization-wide human access, while members may use a separately reviewed request flow. Device and service authority stay separate.

07

Admit runtime access

NexinID evaluates current membership, installation, assignment, permission, entitlement, resource, and policy state at runtime instead of embedding long-lived application grants in a token.

08

Revoke, deprovision, and remove

Logout, consent revocation, assignment removal, outbound provisioning or deprovisioning where configured, installation removal, and application retirement remain explicit lifecycle operations with audit evidence.

Signed-in entry

Enter the right organization without leaking unrelated memberships

Qualified application profiles can use resumable signed-in entry for personal, existing-organization, and new-business destinations. When an application requests an exact organization, NexinID validates that active membership and does not turn the flow into a general organization picker.

Personal entry remains distinct from organization membership.
Existing-organization entry preserves the requested organization context.
New-business entry hands product onboarding to the owning product after identity completes.
Public account creation and acquisition policy are a separate release boundary.
Authority boundaries

NexinID governs identity; products retain their domain

NexinID owns identity, organization context, consent, installation, assignment, protocol grants, runtime authorization, audit, and configured lifecycle delivery. It does not absorb product onboarding, commercial offers, licensing policy, application-domain roles, or customer business data.

ConcernAuthority
Publisher, revision, environment, consent, installation, assignment, runtime admissionNexinID
Offer, checkout, subscription, entitlement and seat policyThe owning commerce and licensing services
Product onboarding, workspace setup and business workflowThe owning product
Provisioning and deprovisioningNexinID lifecycle orchestration plus the explicitly configured connector