A governed application lifecycle from publisher to removal
NexinID has delivered a product-neutral application lifecycle for qualified profiles. It keeps publisher review, immutable application versions, organization decisions, human access, runtime admission, and lifecycle cleanup as distinct, auditable steps.
What “delivered” means here
The lifecycle foundation is delivered and has been validated with qualified development profiles. Production approval remains specific to the selected client profile, connector, deployment, and product. This is not an OpenID conformance, certification, every-profile, or universal-production claim.
Eight governed decisions, not one oversized “install” button
Each stage has its own authority and can fail closed without inventing state in the consuming application.
Review the publisher
A publisher establishes its organization and domain evidence. Publisher creation and independent platform review remain separate authorities.
Freeze the application revision
The publisher submits an immutable revision with its client profile, redirect and logout behavior, requested privileges, resource audiences, legal links, and runtime expectations.
Issue a versioned environment
Development, staging, and eligible production environments keep credentials, endpoints, policy, and revision identity separate. Production promotion is independently reviewed.
Review administrator consent
The consumer organization sees the exact publisher, revision, privileges, resources, behaviors, policy evidence, risk, expiry, and commercial association before approving, denying, or narrowing consent.
Create the organization installation
An installation binds the approved application environment to one consumer organization. Catalog visibility, payment, or navigation alone does not imply installation or consent.
Assign human access
Administrators explicitly assign memberships, groups, or organization-wide human access, while members may use a separately reviewed request flow. Device and service authority stay separate.
Admit runtime access
NexinID evaluates current membership, installation, assignment, permission, entitlement, resource, and policy state at runtime instead of embedding long-lived application grants in a token.
Revoke, deprovision, and remove
Logout, consent revocation, assignment removal, outbound provisioning or deprovisioning where configured, installation removal, and application retirement remain explicit lifecycle operations with audit evidence.
Enter the right organization without leaking unrelated memberships
Qualified application profiles can use resumable signed-in entry for personal, existing-organization, and new-business destinations. When an application requests an exact organization, NexinID validates that active membership and does not turn the flow into a general organization picker.
NexinID governs identity; products retain their domain
NexinID owns identity, organization context, consent, installation, assignment, protocol grants, runtime authorization, audit, and configured lifecycle delivery. It does not absorb product onboarding, commercial offers, licensing policy, application-domain roles, or customer business data.
| Concern | Authority |
|---|---|
| Publisher, revision, environment, consent, installation, assignment, runtime admission | NexinID |
| Offer, checkout, subscription, entitlement and seat policy | The owning commerce and licensing services |
| Product onboarding, workspace setup and business workflow | The owning product |
| Provisioning and deprovisioning | NexinID lifecycle orchestration plus the explicitly configured connector |