• L. Haddadsigned in via SSO

Sign-in

Sign in the way your company already does

Use single sign-on through SAML or OIDC, or a username and password where that isn’t set up. Your session refreshes on its own, so there’s no second login. Each company signs in at its own address, with its own settings.

  • Single sign-on through SAML or OIDC
  • Username and password where single sign-on is not in place
  • Each company signs in at its own address, with its own settings
  • New accountT. Nakamura, BRF2
  • Email verified
  • Password set

Users

Add a person, set their role

Add a person, verify their address, and set a first password. If someone forgets a password, they reset it themselves, no call needed. Every user for the company and site shows up in one screen.

  • Users listed per company and site in one screen
  • Email verification on a new account
  • Password reset by the user, or set by an administrator
  • Role: Line SupervisorCell B, Weld Line 1
  • Line Supervisor Copy role Assign users

Roles and permissions

Build a role once, then copy it for the next

Create a role and choose which Modules and actions it can reach. Copy an existing role as the starting point for the next one. A person can hold one role or several.

  • Create and edit roles per company
  • Copy a role as the starting point for a new one
  • A user holds one role or several
  • Sites for T. Nakamura Northbay Industrial Brantford Plant 2 Windsor Plant 1

Access scope

Limit each person to the sites they work at

Someone assigned to two plants sees those two and nothing more. Site access is set on the person, so the same role works at every site without opening up more than it should. Adding a site is a change to one account.

  • Site access assigned per user at the account level
  • One role reused across sites without widening reach
  • Adding a site is a change to one account
  • Line Lead, assigned Plant 1 only
  • Line Lead denied at Plant 2

Access denied

Base access on role and site

Access follows the role and the site a person is assigned to, not what an individual record says. A blocked route lands on a plain denied page. Your own administrators set every role and every site assignment.

  • No classification or marking on an individual record
  • A blocked route lands on a plain denied page
  • Roles and site access are set by your own administrators

FAQ

Ask who can see what, and where.

30 minutes on your identity provider and how access is scoped by role and site.