Pen TestingCloud PostureShadow-AI discoveryCI/CDContinuous PlatformReportsIdentity & accessAgent Trust Fabric
Identity & access

Sign-in, roles, and enterprise identity.

Passwordless magic-link sign-in, four workspace roles scoping every asset, scan and finding, and per-workspace OIDC with SCIM 2.0 provisioning on Enterprise. Deprovisioning cuts access for real.

Start a scan Read the docs
4 roles
owner, admin, member, viewer
OIDC
Okta, Entra ID, Google or Auth0, with JIT provisioning
Immediately
deactivating a user revokes their live tokens and blocks new sign-in
SCIM 2.0 Per-tenant SCIM bearer token · valid only on /scim/v2
Deprovisioning is not a flag flip
Deactivating a user in your IdP revokes their live tokens immediately and blocks any new sign-in. The SCIM token is separate from your account token and only works on the SCIM routes.
Roles
owner everything, incl. billing and members
admin the workspace, not billing
member scan, remediate, knowledge
viewer agentless
In your IdP
OIDC web app
redirect  https://scan.millenniums.ai/api/sso/callback
scopes    openid email
domain    acme.com  → new users JIT-provisioned as members
Removing a member revokes their live tokens immediately Enterprise
The matrix

Four roles, and exactly where each one stops.

Read
Scan
Remediate
Integrations
Members
Billing
owner
admin
member
viewer

Removing a member, or deactivating them in your IdP, revokes their live tokens immediately — the row does not just grey out.

How access is governed
01
Sign-in
Self-serve signup on a work email, then a passwordless magic link exchanged for an access token. Rotate the token to issue a fresh one and revoke every old one at once.
02
Roles
Every asset, scan and finding is scoped to the workspace. Owner holds billing, tokens and members; admin runs the workspace without billing; member does the work; viewer reads.
03
SSO and SCIM
Per-workspace OpenID Connect, owner-configured, with new users in the configured domain provisioned just in time — and SCIM 2.0 to provision and deprovision automatically.

Roles, and what each one can do.

Enterprise plan for SSO and SCIM
Role
Can
owner
Everything, including billing, token and member management
admin
Manage the workspace — scan, remediate, knowledge, integrations, members — but not billing
member
Do the work: scan, remediate, knowledge
viewer
Agentless

White-box scans and repo discovery use your own GitHub connection, authorized through OAuth.

Enterprise identity, without a bespoke integration.

Configure SSO