GitHub org NHI -- beachhead
Beachhead. Inventory org SSO authorizations and fine-grained PATs labeled CI / non-human, cut, then absence re-list (never clone or push with the PAT). VALID or WITHHELD.
Public roadmap -- honest
Beachhead is GitHub org non-human identity. Live means the cut + independent replay path exists in product code. Wait means we have not shipped that connector -- and we will not list Okta as live to look like an IdP app.
Entra user and Entra service principal are live connectors. Okta is not. After an Okta-class identity event, leftover sessions and grants still need an independent bounce. That is the IR playbook -- not "LingerCut is an Okta app."
Live
Beachhead. Inventory org SSO authorizations and fine-grained PATs labeled CI / non-human, cut, then absence re-list (never clone or push with the PAT). VALID or WITHHELD.
OAuth self-grant revoke plus independent GET /user replay (read-only). Not clone/push.
OAuth revoke + refresh-token / userinfo / tokeninfo probe. Never send mail or create calendar events as proof.
Directory users.tokens inventory, delete, then adversarial re-list. Absence is the proof, not the Admin console checkbox.
Graph revokeSignInSessions + refresh-token / Graph GET /me probe. Entra cannot be the only verifier of leftover Entra trust. No mail send as proof.
Machine leftover. Live path when MICROSOFT_SP_LIVE=1 + tenant + app credentials. removePassword then adversarial re-get.
Deactivate + STS GetCallerIdentity (read-only) or Inactive/absence re-list. Never PutObject or create-resource as proof. AWS deactivate is not an independent bounce by itself.
Personal / group / project access tokens and deploy tokens. Cut then absence re-list. Never clone, push, or trigger a pipeline as proof. GitLab revoke is not a VALID receipt.
OAuth revoke plus independent GET /user replay (read-only). Refresh-token probe when GitLab issued one. Not clone/push.
Wait
Not built -- and not the point. LingerCut is leftover trust after an IdP event, not an Okta app. Okta/Entra revoke is not our proof. After an Okta-class incident, use the IR playbook and live connectors above.