Skip to content
Demo environment — data shown is illustrative
WorkforceObservatory

People analytics for IT & security

The analytics platform your security review was designed for: on-premises, OIDC-integrated, auditable — and zero runtime calls to the public internet.

Workforce Observatory — access control with role-based scopes and organization policies

Deployment model

  • Containerized stack (API, workers, web, PostgreSQL) via Docker Compose
  • Kubernetes/OpenShift is the target path for scaled deployments
  • Operates without public network dependency; air-gap-capable delivery
  • Connector secrets resolved server-side, never exposed to the browser

Identity & authorization

  • Corporate OIDC; federation path to ADFS/Keycloak with Active Directory
  • RBAC roles — admin, analyst, viewer — plus organization scopes
  • Enforcement in the API on every query, including custom metrics
  • Audit events for authentication, publishing and configuration changes
Workforce Observatory — access control with role-based scopes and organization policies

Data architecture

  • Immutable Bronze payloads, typed Silver canonical tables, governed Gold
  • Open formats — Parquet — no proprietary lock-in
  • Versioned mappings, schemas and metrics; explicit, idempotent reprocessing
  • Durable job queue with per-attempt object paths and status

Extensibility without risk

  • Connector SPI for new sources — declarative, reviewed, pinned artifacts
  • Optional modules enabled per deployment; no customer-supplied code executed
  • Governed AI agents with allowlisted tools only
  • Data endpoints expose governed reads — the API is the only query path

Questions IT and security teams ask

Does it phone home or call external services?

No. The stack is designed to operate without runtime dependencies on public networks. Connector credentials stay in your environment and are never returned to the browser.

How does authentication work in production?

Via your corporate OIDC provider — Microsoft Entra ID, ADFS or Keycloak federated with AD. Roles and organization scopes map from your groups; the API enforces them on every request.

Can we extend it with our own connectors?

Yes, through the connector SPI — declarative, versioned artifacts that go through review. The platform does not execute untrusted customer code.

What about upgrades and disaster recovery?

Releases ship as pinned image digests and versioned contracts. Backup/restore and upgrade/rollback are part of the deployment runbook we agree per environment.

Run it past your security review

We will walk your team through the deployment model, identity boundary and data flows.