SigmaTrust Docs · Access Control, SSO & SCIM
Access Control, SSO & SCIM
Role-based access, team scoping, and standards-based user provisioning.
Role-based access control
Access is governed by configurable role definitions: which modules a role can see and what it can do there. Department- and team-level scoping narrows records to the user’s own scope, and data-visibility configuration lets administrators tune who sees what without code changes.
SCIM 2.0 provisioning
A SCIM 2.0 endpoint supports automated user lifecycle management from identity providers — create, update and deactivate users from your IdP instead of managing accounts by hand.
Passwordless and MFA-ready sign-in
Native passkey (WebAuthn) registration and login are built in, aligning platform access with the phishing-resistant authentication your frameworks increasingly require.
Least-privilege defaults
New roles start from minimal access and are granted up — the model your ISO 27001 A.5/A.8 and SOC 2 CC6 evidence wants to describe.
FAQ
Which identity providers work with SCIM provisioning?
Any IdP that speaks standard SCIM 2.0 (Azure AD/Entra, Okta and peers). Configuration details are provided during onboarding.
Can we restrict a team to only its own records?
Yes — department/team scoping plus data-visibility configuration control record access per role, configurable by your administrators in the UI.
