Access
Authentication
OIDC, SAML, and API keys share one tenant, role, and audit boundary — the same identity model as hosted enterprise GRC workspaces.
Server auth
Identity boundaryBrowser SSO + API keys share one tenant and audit model
01IdP sign-inOIDC or SAML with Okta, Entra ID, Google, or generic IdP.
02Map to tenant userVerified email → tenant → role (or API key for headless).
03Issue sessionHttpOnly cookie or API key hash — no parallel auth silo.
04Enforce RBACScopes gate console, connectors, snapshots, and agents.
05Audit every requestActor, tenant, route, decision — same boundary as hosted SSO workspaces.
Loading session…
Connecting to the security data lake and checking the latest trust state.
Login methods
Browser SSO uses your company IdP. API keys serve agents, CI, and MCP clients with the same RBAC envelope.
Loading auth methods…
Connecting to the security data lake and checking the latest trust state.