CPCE users can use OAUTH2 login using either OKTA or Cognito IDP. Once authenticated, RBAC Authorizer validates the role assigned to the user and provides a JWT token that can used by respective Apps to show the correct UI and for users to call platform API's directly (if required).
Users can be provisioned from the CP console or can be synced from Synapps (for existing agents using legacy apps). These users need to have a corresponding role attached to access the applications - Configuration roles or Agent roles