Your identity provider, with nobody in between.
Single sign-on through OpenID Connect or SAML 2.0, provisioning through SCIM 2.0, and directory sync from Entra ID or Okta — each one talking to your provider from your own side. There is no LockFlare server in the loop, because there is no LockFlare server.
At a glance
A bridge that never makes keys.
A provisioned person is still a person with a key of her own. The bridge opens the door; it does not hold the key.
How it joins someone
The provider creates the user through SCIM. The person files her own join request from her own Sonda, with her own key slot. The bridge approves it — checking every minute that the address is active at the provider, the invitation is current, and SSO has been passed if required.
How it removes someone
A person removed at the provider is paused, not deleted; an administrator revokes in Sonda, which turns the keys of every project the person could read. A directory sync pauses people in no group and reactivates those put back.
What it enforces
The seat cap of the license. Revocable provisioning keys that a Sonda Server also refuses once revoked. A report of approved, reactivated, deactivated, awaiting and unmanaged, mailed if you like.