Access controls your CISO will sign off on.
RBAC + SAML SSO + SCIM provisioning + per-record scoped sharing + audit log + per-region data residency. Built for the security review, not the sales pitch.
Part of the People hub.
Core capabilities.
Role-based access
Predefined roles (Admin, Manager, IC, Guest) + unlimited custom roles. Granular per-hub, per-action permissions.
SAML SSO + SCIM
Okta, Azure AD, Google Workspace, OneLogin, Auth0. SCIM provisioning auto-deactivates departing users.
Scoped sharing
Share a record (a person, an SOP, a KPI) with specific people for a set time. Auto-expire support.
Audit log
Every read, write, export, share — logged with user, timestamp, IP, device. Searchable; exportable; tamper-evident.
Data residency
EU, India, or US data residency. Pinned at workspace creation; honored end-to-end for storage, AI, and backups.
Guest accounts
Free guest accounts for contractors, board members, external auditors. Scoped read-only access; never count toward seat billing.