Built for: IT, security and programme administrators.
Roles and modules
Organisation roles
Admin, manager, analyst and viewer, each with its own permissions.
Module roles
Roles within each module, plus custom roles defined by your organisation.
Module access
People are assigned to the modules they need, and assignments can expire.
Teams and business units
Group people into teams and map your organisation as a hierarchy.
Row-level data scoping
Scopes restrict the data a person can see to a part of your hierarchy: a region, a country or a single site. The scope follows them everywhere, including dashboards they share, so a location manager sees their location and a regional director sees their region.
Identity and oversight
- SCIM 2.0 provisioning of users and groups from your identity provider.
- Multi-factor authentication with authenticator apps and passkeys.
- Access reviews that let owners confirm or revoke access, with expired access removed automatically.
- An activity history with CSV export, and a feed your SIEM can pull from or receive.
- Legal holds that keep records from being deleted.
- IP allowlisting on request.
Works with
- Security and privacy: eU hosting, isolation, encryption and data subject rights.
- Reporting and dashboards: scheduled reports, dashboards and notifications.