Platform › Access & Security
Access
Who may sign in, which directory vouches for them, what they may reach once they are in, who is signed in at this moment, the duties that must not be combined, administrator authority borrowed for a fixed window, and one person’s identity borrowed for another to debug with.
In Platform → Access & Security · 7 screens
| Screen | Kind | What it is | Columns | Fields | Actions |
|---|---|---|---|---|---|
| Users | Workspace | Who may sign in, which roles they hold, and where they are allowed to work. | 0 | 0 | 0 |
| Roles | Workspace | What a role may reach: modules, locations and warehouses. | 0 | 0 | 0 |
| Single Sign-On | Workspace | One connection per directory — SAML 2.0, OpenID Connect, OAuth 2.0, WS-Federation, CAS, LDAP, SCIM and the rest — and the email domains each of them answers for. A group signs @group.com in through one and @acquired.co.uk through another. | 0 | 0 | 0 |
| Signed In Now | Workspace | One row per live session rather than per person, so somebody working on a laptop and a tablet appears twice. Ending one stops the token working on its next request — which is what “sign out” never used to do. | 0 | 0 | 0 |
| Segregation of Duties | Workspace | Pairs of duties that should not sit with one person, and who currently holds both. Administrators are exempt — they hold every grant by definition. | 0 | 0 | 0 |
| Elevated Access | Workspace | Administrator authority borrowed for a fixed window, against a written reason, a ticket and two approvals. It ends on its own. | 0 | 0 | 0 |
| Assumed Identity | Workspace | Signing in as another person to reproduce their transaction, for a fixed window, against a written reason, a ticket and two approvals. Read-only unless it was approved otherwise, an administrator can never be the subject, and every call made with it is recorded and readable afterwards. | 0 | 0 | 0 |