文件
瀏覽文件

Team access and security

Manage workspaces, members, roles and site access for your analytics team, and secure sign-in with SSO, SCIM, two-factor authentication and an audit log.

以 Markdown 檢視

Workspaces and members#

A workspace owns sites, members, billing, API tokens and webhooks. Everyone in it is a member with one role and access to all sites or selected sites.

  • Invite from Workspace settings → Members: enter up to 50 email addresses, then choose a role and site access. Invitations are emailed and expire after 14 days. You can revoke pending ones.
  • Change role or site access at any time. "All sites" includes sites added later. You can't change your own access, or give someone a role or sites beyond your own.
  • Remove a member: their API tokens for this workspace stop working immediately. Members can also leave on their own.
  • Transfer ownership to another member (owners only). The previous owner becomes an admin. The owner can't be removed or leave before that.

Inviting, changing and removing members need the members.manage permission (see Roles & permissions). Per-site access can also be managed from a site's Access tab.

The Free plan allows 3 members, and pending invitations count toward that limit. Paid plans are unlimited.

Members and invitations are REST resources under /workspaces/<workspace id>/members and /workspaces/<workspace id>/invitations, and MCP tools named members_* and invitations_*. The API reference lists every input.

In this section#

Workspace security settings#

Workspace settings → Security holds the sign-in rules for everyone in the workspace. Changing them needs the workspace.manage permission, which the Owner and Admin roles have.

Setting Options Plan
Require two-factor authentication On or off Business
Allowed login methods Email and password, Email login link, Passkey, Google, GitHub, SSO (SAML/OIDC) All
Sign members out after No limit, 8 hours, 24 hours, 7 days or 30 days All
IP allowlist IP addresses and CIDR ranges, IPv4 or IPv6 Business
Support access On or off, for 7 days at a time All
  • Require two-factor authentication. Members without an authenticator app or a passkey are sent to set one up before they can open the workspace. See Two-factor authentication.
  • Allowed login methods apply to every member, and at least one method must stay selected. The owner can always log in with a password or a passkey, so a login rule can't lock the owner out. Someone who belongs to several workspaces can use only the methods that all of them allow. When SSO is enforced, members sign in through SSO only.
  • Sign members out after ends a session that many hours after the member signed in, however active they are. Someone who belongs to several workspaces gets the shortest lifetime among them.
  • IP allowlist. Only the listed addresses can open the workspace in the app or use its API tokens. Put one entry per line, such as 203.0.113.0/24 or 2001:db8::/32. An empty list allows any address. The list must include the address you are saving from (the page shows it), so you can't lock yourself out.
  • Support access lets Privatus Analytics support view the workspace for 7 days from the time you save. Support staff cannot see your workspace unless you allow it. Turn it off to end access at once. Access is read-only and every view is written to the audit log.

Note: On a plan below Business the two Business settings are shown switched off. If a workspace moves to a lower plan, its 2FA requirement and IP allowlist are kept but stop applying until it is back on Business.

Security settings are a REST resource at /workspaces/<workspace id>/security (GET to read, PATCH to change) and the MCP tools workspace_security_get and workspace_security_update. Over the API, session_ttl_hours takes any whole number of hours up to 2,160 (90 days), and 0 means no limit. The API reference lists every input.

Team roles and permissions

See what each built-in role (Owner, Admin, Editor, Analyst, Viewer, Billing) can do, how custom roles work on Business, and how API tokens narrow access.

Single sign-on (SSO) with SAML or OIDC

Set up single sign-on for your analytics workspace with SAML 2.0 or OpenID Connect: IdP values, email domains, just-in-time provisioning and enforcing SSO.

Set up SSO with Okta

Connect Okta to Privatus Analytics with SAML 2.0 or OpenID Connect single sign-on. Create the app integration, copy the values, assign people and test.

Set up SSO with Microsoft Entra ID

Connect Microsoft Entra ID (Azure AD) to Privatus Analytics with SAML 2.0 single sign-on, step by step: enterprise app, claims, certificate and testing.

Set up SSO with Google Workspace

Connect Google Workspace to Privatus Analytics with a custom SAML app for single sign-on, including the ACS URL, entity ID, Name ID and provisioning options.

Set up SSO with JumpCloud

Connect JumpCloud to Privatus Analytics with SAML 2.0 single sign-on: create the custom app, enter the SP entity ID and ACS URL, bind user groups and test.

SCIM user provisioning

Set up SCIM 2.0 to create, update and remove workspace members automatically from your identity provider, with the base URL, token and supported endpoints.

Two-factor authentication (2FA)

Turn on two-factor authentication with an authenticator app or passkeys, save recovery codes, and enforce 2FA for every member of your analytics workspace.

Workspace audit log

Use the audit log to see who changed sites, members, API tokens, SSO and billing, and when. Filter by actor, action or date, and export entries to CSV.