Admin & org
Roles, MFA and access control
Enforce MFA for every user, run role-based access and prove it to buyers with a live report.
5 min read · updated July 2026
Step-by-step
- 1
Enforce MFA
Admin → Security → Enforce MFA. Existing users are prompted to enrol on next login.

- 2
Review roles
Team page shows role by user. Do a quarterly review and export the log as evidence.
- 3
Export the MFA report
Reports → Access controls → MFA enforcement. Attach to buyer questionnaires.
What corporate buyers look for
- "Is MFA enforced for all users with access to customer data?"
- "How are roles assigned and reviewed?"
What this workflow produces: The MFA enforcement report + role review log answers the two most common access-control questions in one shot.
FAQ
Do you support SSO / SAML?
Yes on the Business plan (Google, Microsoft, Okta, generic SAML).
Can auditors access without a seat?
Yes — Auditor role is free and scoped to read-only for the audit period.
Ready to run this in your workspace?
Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.
Related
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
