Login events are not authorization evidence
When regulators ask you to "prove it," IdP logs only get you partway. They show that someone authenticated. They do not show why that person was allowed to export an invoice, approve a payout, or read another tenant's data. That proof maps to a runtime architecture: PEP — enforce the decision in the app/API/gateway PDP — evaluate policy close to the app (hybrid/local beats remote-only on the hot…
We haven't written up this one. Dev.to has the full story — the link below goes straight to it.