Identity, tenant boundaries, and evidence are first-class architecture.
The public site names the target controls, but production security claims require server-side proof, Zitadel configuration evidence, and ServerOps receipts.
Zitadel OIDC and role mapping are identity prerequisites.
Tenant-scoped APIs must enforce authorization server-side.
Training records, source material, and learner state require retention policy.
Compliance exports are gated until LRS and evidence-store contracts pass.