OpenVLAN SSH authenticates every session against your identity provider and records what happens next.
When you run ssh db-prod, the OpenVLAN client intercepts the connection instead of using your key file.
The tailnet checks your SSO identity, your device, and the ACL for that host. No password, no copied authorized_keys.
Enable check mode and every keystroke lands in an asciinema replay your auditors can watch.
Shared root keys become one identity per person, issued and revoked by your IdP. Bastion chains become direct laptop-to-host sessions with nothing to rotate. And manual audit screenshots become a side effect: enable check mode and every keystroke lands in an asciinema replay your auditors can watch.
Same command your team already types. Completely different security posture.