Identity manages the following entities for a tenant:

A user consists of the following:

A role consists of the following:

A permission consists of the following:

A permittable group consists of the following:

A designator consists of the following: (for a future version)

A service token consists of the following: (for a future version)

The data saved for the tenant in identity includes:

A special note about identifiers: (for example user identifier, role name, and service token name)

The users "seshat" and "guest" cannot be created. They have a special meaning for anubis and are therefore reserved.

The role "disabled" cannot be created or deleted. Assigning this role to a user has the effect of taking away all that users permissions and therefore disabling him.