Team access and security
Manage workspaces, members, roles and site access for your analytics team, and secure sign-in with SSO, SCIM, two-factor authentication and an audit log.
Workspaces and members#
A workspace owns sites, members, billing, API tokens and webhooks. Everyone in it is a member with one role and access to all sites or selected sites.
- Invite from Workspace settings → Members. Invitations are emailed and expire. You can revoke pending ones.
- Change role or site access at any time. "All sites" includes sites added later.
- Remove a member: their API tokens for this workspace stop working immediately.
- Transfer ownership to another member (owners only).
Per-site access can also be managed from a site's Access tab.
The Free plan allows 3 members. Paid plans are unlimited.
In this section#
- Roles & permissions, including custom roles.
- Single sign-on with guides for Okta, Microsoft Entra ID, Google Workspace and JumpCloud.
- SCIM provisioning.
- Two-factor authentication.
- Audit log.
Workspace security settings#
Under Workspace settings → Security:
- Enforce two-factor authentication for every member (Business).
- Allowed sign-in methods (password, email link, passkeys, Google, GitHub, SSO).
- Session lifetime.
- IP allowlist for access to the app (Business).
- Verified domains: people with an email on your domain can join automatically with a default role.
See what each built-in role (Owner, Admin, Editor, Analyst, Viewer, Billing) can do, how custom roles work on Business, and how API tokens narrow access.
Set up single sign-on for your analytics workspace with SAML 2.0 or OpenID Connect: IdP values, email domains, just-in-time provisioning and enforcing SSO.
Connect Okta to Privatus Analytics with SAML 2.0 or OpenID Connect single sign-on. Create the app integration, copy the values, assign people and test.
Connect Microsoft Entra ID (Azure AD) to Privatus Analytics with SAML 2.0 single sign-on, step by step: enterprise app, claims, certificate and testing.
Connect Google Workspace to Privatus Analytics with a custom SAML app for single sign-on, including the ACS URL, entity ID, Name ID and provisioning options.
Connect JumpCloud to Privatus Analytics with SAML 2.0 single sign-on: create the custom app, enter the SP entity ID and ACS URL, bind user groups and test.
Set up SCIM 2.0 to create, update and remove workspace members automatically from your identity provider, with the base URL, token and supported endpoints.
Turn on two-factor authentication with an authenticator app or passkeys, save recovery codes, and enforce 2FA for every member of your analytics workspace.
Use the audit log to see who changed sites, members, API tokens, SSO and billing, and when. Filter by actor, action or date, and export entries to CSV.