Admin & org

Roles, MFA and access control

Enforce MFA for every user, run role-based access and prove it to buyers with a live report.

5 min read · updated July 2026

Step-by-step

  1. 1

    Enforce MFA

    Admin → Security → Enforce MFA. Existing users are prompted to enrol on next login.

    Enforce MFA
  2. 2

    Review roles

    Team page shows role by user. Do a quarterly review and export the log as evidence.

  3. 3

    Export the MFA report

    Reports → Access controls → MFA enforcement. Attach to buyer questionnaires.

What corporate buyers look for
  • "Is MFA enforced for all users with access to customer data?"
  • "How are roles assigned and reviewed?"

What this workflow produces: The MFA enforcement report + role review log answers the two most common access-control questions in one shot.

FAQ

Do you support SSO / SAML?

Yes on the Business plan (Google, Microsoft, Okta, generic SAML).

Can auditors access without a seat?

Yes — Auditor role is free and scoped to read-only for the audit period.

Ready to run this in your workspace?

Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.

Related

ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation