Airlock as a Service Knowledge Base

Glossary

In the context of Airlock as a Service, we use the following terminology:

Term

Definition

Airlock Console

The management application through which administrators manage → organizations, → tenants, → Tenant IAM configurations, users, and related service settings according to their assigned roles and permissions.

Airlock as a Service DevOps team

The Airlock team responsible for deploying, operating, maintaining, and monitoring the infrastructure and applications that provide Airlock as a Service

application

A web application which is protected by authentication and authorization.

authentication flow

A configurable sequence of authentication and authorization steps that determines how a user is authenticated and which access requirements must be fulfilled.

deployment

A tenant-specific runtime in Airlock as a Service that contains the → Tenant IAM with its current configuration and serves the → tenant’s end-user traffic.

end user (user)

A → user for whom the functionality of an → application is ultimately intended and to whom the authentication and identity management settings defined in a Tenant IAM configuration apply.

Airlock 2FA

A strong two-factor authentication solution integrated into Airlock IAM that provides a ready-to-use mobile app and supporting services for second-factor authentication and transaction approval, including an offline time-based one-time passcode method.

IAM configuration

A structured configuration of Airlock IAM plugins and their properties and relationships that defines the functional behavior of one or more Tenant IAMs.

identity propagation

A set of methods by which Airlock IAM provides information about an authenticated user to a target application in a format suitable for that application.

Identity Provider (IdP)

An entity in a federated identity transaction that creates an assertion about a subscriber and transmits the assertion to a relying party, usually in the context of SAML 2.0 or OAuth 2.0/OIDC.

Management Platform

A software system comprising the services, applications, and components that collectively provide the functions for administering Airlock as a Service.

mobile app

An → application designed to run on a mobile device.

organization

An Airlock-as-a-Service entity that represents a customer as the contracting party, defines the boundary for the customer’s data, and is identified by the customer’s legal name and domicile.

Runtime Platform

A Kubernetes cluster used to host and run → Tenant IAM instances for Airlock as a Service tenants.

SaaS Admin (user)

A → user of Airlock as a Service who belongs to exactly one → organization and performs administrative tasks for that organization and its → tenants within the scope of the assigned roles and tenant access.

SaaS Superadmin (user)

A → user who is a member of the Airlock as a Service DevOps team and is authorized to manage → organizations and → SaaS Admin accounts but not to access tenants, their configurations, or their data.

SSO (single sign-on)

A statement about an authenticated end user issued by another system that contains the user’s name or ID and optionally roles and other attributes and that is typically digitally signed and time-limited (the → end-user must be authenticated and authorized only once to access multiple apps).

stage (verb)

To deploy software, a configuration, or another change to a staging environment for testing under production-like conditions before deployment to the production environment.

tenant

A logical partition of a software environment that groups and segregates configuration, data, resources, and access rights associated with a particular → organization or → user group (→ SaaS Admins manage tenants and edit tenant configurations).

Tenant IAM

The Airlock IAM runtime instance assigned to a tenant that executes the tenant-specific IAM configuration and provides authentication, authorization, identity management, and self-services for that tenant's end users.

user

A person who interacts with Airlock as a Service or accesses an application protected by a Tenant IAM (whenever the person’s role is relevant, a more specific term such as → end user, → SaaS Admin, or → SaaS Superadmin is used).