RBAC · SSO · Audit Log

User & Permission Management

Granular role-based access control for DPP teams. Define roles, manage permissions, audit every action. SSO via SAML and OAuth. ISO 27001 compliant.

Why Granular Permissions?

Different DPP team members need different access: marketing edits brand content, compliance reviews ESPR fields, suppliers upload data, executives view dashboards. RBAC ensures everyone has exactly what they need — no more, no less.

Pre-Built Roles

Admin: Full access; manage users & billing
Compliance Officer: Review/approve DPPs
Marketing: Edit content & templates
Supply Chain: Manage suppliers
Auditor: Read-only with audit log access
Custom: Define your own permissions

Single Sign-On (SSO)

Integrate with your identity provider: Azure AD, Okta, Google Workspace, Auth0, Ping Identity. Just-in-time provisioning and SCIM 2.0 user lifecycle management.

Compliance & Audit

All actions logged: who, what, when, from where. Tamper-evident hashing; logs retained 7 years. Compliant with ISO 27001, SOC 2 Type II, GDPR Article 32.

Frequently Asked Questions

Yes — define any combination of 50+ permission scopes. Save as templates for reuse.

SAML/OAuth available on Growth tier and above. SCIM 2.0 user provisioning is Enterprise-only.

Append-only with cryptographic hashing; export to your SIEM in real time.

Yes — IP whitelist, country block, or VPN requirement. Conditional access policies on Enterprise tier.

Yes — bcrypt hashing, 2FA mandatory for admin roles, no password reuse for last 5 entries.

Yes — TOTP (Google Authenticator), SMS, hardware tokens (YubiKey), and SSO MFA inheritance.

Yes — granular export permissions; certain roles can view but not export sensitive data.

Related DPP Topics

Configure Team Permissions

Free 30-day trial. Test SSO with your IdP.

Request Demo