Microsoft Entra SSO
Sign in with Entra ID; refresh-token rotation with replay detection. Per-tenant RBAC across dev, admin and platform roles.
Enterprise
Forge is built for teams whose releases face an auditor. Entra SSO, tenant-scoped registries, and four layers between a verdict and a pushed tag — with a four-eyes rule the database enforces.
Enterprise
Sign in with Entra ID; refresh-token rotation with replay detection. Per-tenant RBAC across dev, admin and platform roles.
Every audit and release is scoped by client_id. Per-client policy floors layer on top of the framework — stricter, never weaker.
Admin-only sign-off with a hash-chained, tamper-evident audit trail. The push-service polls and ships only after approved=true.
No flag turns a NO-GO into a GO. The verdict is the gate, and four independent layers sit between that verdict and a pushed tag.
Separation of duties
Forge will not release without a fresh GO verdict on the same SHA.
A human admin signs off in-app. Requester and approver must be different people — a database constraint decides that, not a convention.
A separate service performs the push with its own scoped deploy key, compare-and-swap against the expected old ref, then reads the remote back into a receipt.
Server-side push rules reject a push from any other identity — configured by you, on your Git host.
We'll walk through all four layers — including what each one does and does not cover — and how Forge evidence maps to your control framework.