I call it a "domain controller" because it keeps a directory of users and hosts, accessible via LDAP. This source of truth drives the Certificate Authority role which can cryptographically assert authn/authz and distribute those assertions to member hosts in the form of certificates, password hashes, etc. A DC may also securely distribute time to its hosts, which is important for accurately calculating the validity of a certificate.
A classic DC would authenticate windows logins and rely on an external network. My design authenticates just TLS and web-app logins (not windows) but also provides an authenticated layer 3 network. So it's hardware-attested zero trust -- something that's difficult to securely assemble out of existing SaaS.
This would be overkill for a typical call center (large scale, high churn, low trust) but perfect for a team working on sensitive IP (smaller scale, low churn, high trust.) Research and development, administrating expensive systems (regional manufacturing?) or for collaborative work on sensitive documents (legal?)