Selling to Fortune 500? GreatCTO auto-attaches enterprise-pack with multi-tenant isolation decision (RLS / schema / DB-per-tenant), SSO (SAML / OIDC / SCIM), SOX ITGC (access control / change mgmt / SoD), immutable audit logs, plus SOC2 Type 2 readiness and admin-impersonation safety.
multi-tenant · saml · oidc · scim · soc2 · sox · audit-log · tenant-id · row-level-security
The pack rides on top of your base archetype (web-service, ai-system, fintech, …) — it doesn't replace it. Auto-injects reviewer agents into the pipeline + opens human gates listed below.
Multi-tenant isolation (RLS / schema / DB) · SAML / OIDC / SCIM · SOX ITGC · immutable audit logs · data-residency · tier-based feature flags · admin-impersonation safety · SOC2 Type 2 readiness
gate:plan + gate:ship.| Gate | Owner | Trigger |
|---|---|---|
gate:tenant-isolation | security + architect | before any cross-tenant feature |
gate:sox-itgc | compliance + IT lead | for changes to access control / SoD |
gate:audit-log-immutable | security | before any production write |
Each EVAL has ≥5 test cases, pass threshold, regression interpretation, cross-refs to TM + gates. Run via your existing test framework.
EVAL-enterprise-tenant-isolation-rls.mdEVAL-enterprise-saml-scim-roundtrip.mdEVAL-enterprise-sox-sod-violation-detect.mdEVAL-enterprise-audit-log-tamper.mdEVAL-enterprise-admin-impersonation-trail.mdpacks: in PROJECT.md./migrate to re-run detection with updated rules.$ npx great-cto init