About This Architecture
Compass Pilot implements a three-tier authentication architecture spanning Dev, QA, and Prod environments on OCI, with Microsoft Entra ID as a shared external SAML identity provider. Users authenticate through Compass Pilot ClickOnce clients to environment-specific Hyland Identity Services, which federate with the centralized Entra ID SAML IdP for credential validation. Each tier routes authenticated requests through Hyland API Servers to OnBase Server backends, ensuring consistent identity governance across development, testing, and production workloads. Fork this diagram on Diagrams.so to customize environment-specific configurations, add additional IdP providers, or document your own multi-tenant Hyland deployment. This pattern demonstrates least-privilege federation and environment isolation best practices for enterprise content management platforms.