Security & sovereignty

Access and secure operations.

A secure use case needs more than a login. Ownership, permission, approved models and later review must fit together.

Permissions must match the specific use case.

Access to the platform does not by itself determine which data a person may see or which tools they may execute. These decisions are made for the relevant workspace and work context. Roles should therefore follow the actual task as closely as possible.

Ongoing operations also require changes and security-relevant activity to remain attributable to the correct context. Technical controls support this work, but they do not replace named ownership or the organization’s operating rules.

From sign-in to a traceable activity

The control chain begins with identity and does not end with execution. Relevant activity must remain attributable to the right context.

In the platform

What can be controlled and reviewed in practice.

Members and roles

Workspace admins manage invitations, seats and the Admin, Member and Viewer roles. Role changes take effect immediately, and at least one admin is always retained.

Identity lifecycle

Microsoft Entra ID can create, update and deactivate members through SCIM. Each SCIM change is recorded in the audit log with the affected user and changed fields.

Bounded usage

Admins can cap usage categories per usage tier and assign tiers to individual members. Limits distinguish text, image, API and other usage.

Verifiable details

Workspace roles
Admin, Member and Viewer
Provisioning
Automatic creation, updates and deactivation through Entra ID SCIM
SCIM auditability
Changes appear as scim.user.* entries in the audit log
Usage controls
Separate limits for text, images, API and other functions

Important context

A technical control does not replace clear organizational ownership. Both must be established before productive operation.

Ask our security team

For questionnaires, technical reviews or a specific use case, our team provides the appropriate level of detail.

Contact the security team