Security
This section is for your IT and security team. It covers how people sign in, how to connect your identity provider, how to give and remove access, and what you can monitor. The settings are under Organisation → People & roles and Organisation → Sign-in & security. If your organisation doesn’t use Organisation yet, they’re under Settings → Users & Access and Settings → Organisation.
How people sign in
- Email code or Google and Microsoft, then a second factor. Without single sign-on, people sign in at platform.flowstate.inc with a six-digit code sent to their work email, or with Google or Microsoft. Flowstate then asks for a passkey or a code from an authenticator app. The second factor is always on. People who’ve added a passkey can sign in with it straight away.
- Single sign-on. People on your email domains go to your identity provider instead, using SAML 2.0 or OAuth 2.0. Your identity provider’s multi-factor rules apply, so enforce them there.
- Your rules. You choose which email domains can sign in, how long people stay signed in, and whether people who haven’t been invited can join. See Sign-in settings.
What do you want to do?
| Job | Guide |
|---|---|
| Invite people and choose their role | Invite people and manage their access |
| Send people to your identity provider with SAML | Set up SAML single sign-on |
| Send people to your identity provider with OAuth or OpenID Connect | Set up OAuth single sign-on |
| Create accounts and set roles from your identity provider | Provision accounts with SCIM |
| Send security events to your SIEM | Send security events to your SIEM |
| See who changed a person, team or project | Review the activity log |
| Give another system access to the REST API | Create and manage API keys |
| Look up what a permission allows | Roles and permissions |
Rolling out Flowstate Desktop? Your security team should read Data residency and what’s captured first.