Pen TestingCloud PostureShadow-AI discoveryCI/CDContinuous PlatformReportsIdentity & accessAgent Trust Fabric
Identity & access
Sign-in, roles, and enterprise identity.
Passwordless magic-link sign-in, four workspace roles scoping every asset, scan and finding, and per-workspace OIDC with SCIM 2.0 provisioning on Enterprise. Deprovisioning cuts access for real.
4 roles
owner, admin, member, viewer
OIDC
Okta, Entra ID, Google or Auth0, with JIT provisioning
Immediately
deactivating a user revokes their live tokens and blocks new sign-in
SCIM 2.0
Per-tenant SCIM bearer token · valid only on /scim/v2
Deprovisioning is not a flag flip
Deactivating a user in your IdP revokes their live tokens immediately and blocks any new sign-in. The SCIM token is separate from your account token and only works on the SCIM routes.
Roles
owner
everything, incl. billing and members
admin
the workspace, not billing
member
scan, remediate, knowledge
viewer
agentless
In your IdP
Removing a member revokes their live tokens immediately
Enterprise
The matrix
Four roles, and exactly where each one stops.
Read
Scan
Remediate
Integrations
Members
Billing
owner
admin
member
viewer
Removing a member, or deactivating them in your IdP, revokes their live tokens immediately — the row does not just grey out.
How access is governed
01
Sign-in
Self-serve signup on a work email, then a passwordless magic link exchanged for an access token. Rotate the token to issue a fresh one and revoke every old one at once.
02
Roles
Every asset, scan and finding is scoped to the workspace. Owner holds billing, tokens and members; admin runs the workspace without billing; member does the work; viewer reads.
03
SSO and SCIM
Per-workspace OpenID Connect, owner-configured, with new users in the configured domain provisioned just in time — and SCIM 2.0 to provision and deprovision automatically.
Roles, and what each one can do.
Enterprise plan for SSO and SCIMWhite-box scans and repo discovery use your own GitHub connection, authorized through OAuth.