Workspace and Project isolation
Membership, role, and runtime access decisions stay scoped to the Workspace and Project context.
- Workspace roles
- Project roles
- Environment-aware access
Lamba keeps Workspace and Project boundaries explicit across authentication, memberships, sessions, webhooks, audit trails, and incident communication.
Lamba trust boundary
Identity, access, events, and operations
Workspace
Scoped membership context
Project
Scoped membership context
Lamba account
Scoped membership context
Session
Evidence for review workflows
Webhook
Evidence for review workflows
Audit trail
Evidence for review workflows
Reviewable controls
Security, legal, status, and technical references stay connected so reviewers can move from posture to evidence without searching across the whole product.
Membership, role, and runtime access decisions stay scoped to the Workspace and Project context.
OIDC flows are built around Authorization Code, PKCE, exact redirect matching, and short-lived session signals.
Webhook and lifecycle events are designed for signed delivery, replay checks, and delivery review.
Status, audit trails, trace identifiers, and incident communication keep critical auth paths inspectable.
Procurement packet
Use these links for integration review, incident communication, status visibility, and legal checks from one trust surface.
Trust center
Start with a Workspace, connect your first Project, and keep identity, access, growth signals, and operational evidence in one model.