Step 1
Verify where BlackShield puts administrative control
In BlackShield, the controls buyers usually ask about are visible in product: `/identity`, `/api-keys`, `/audit`, `/compliance`, and `/tenant-rights`.
- Open `/identity` and confirm tenant admins can configure OIDC, validate provider settings, map groups to roles, rotate SCIM tokens, and review identity audit events.
- Open `/api-keys` and confirm API keys can be created, listed, and revoked from the tenant workspace.
- Open `/tenant-rights` and confirm tenant admins can see tenant scope before running destructive actions.