Documentation Get help

Security

This section is for your IT and security team. It covers how people sign in, how to connect your identity provider, how to give and remove access, and what you can monitor. The settings are under Settings → Organisation and Settings → Users & Access.

How people sign in

  • Emailed link, then a second factor. Without single sign-on, people get a sign-in link by email that only works for a short time. Flowstate then asks for a passkey or a code from an authenticator app. The second factor is always on.
  • Single sign-on. People on your email domains go to your identity provider instead, using SAML 2.0 or OAuth 2.0. Your identity provider’s multi-factor rules apply, so enforce them there.
  • Your rules. You choose which email domains can sign in, how long people stay signed in, and whether people who haven’t been invited can join. See Sign-in settings.

What do you want to do?

JobGuide
Invite people and choose their roleInvite people and manage their access
Send people to your identity provider with SAMLSet up SAML single sign-on
Send people to your identity provider with OAuth or OpenID ConnectSet up OAuth single sign-on
Create accounts and set roles from your identity providerProvision accounts with SCIM
Send security events to your SIEMSend security events to your SIEM
See who changed a person, team or projectReview the activity log
Give another system access to the REST APICreate and manage API keys
Look up what a permission allowsRoles and permissions

Rolling out the Cloud Proxy? Your security team should read Cloud Proxy security and privacy first.