MULTI-IDP SUPPORT

Flexible identity. Governed access.

Let different parts of your organisation authenticate through the identity providers that already fit their environment. Secrato supports identity configuration across tenants and workspaces while giving central teams clearer oversight of how access is governed across the organisation.

IDENTITY AT SCALE

Support different identity environments without losing control

Complex organisations rarely rely on a single identity setup. Subsidiaries, regions, business units and acquired companies may each operate with their own directories, domains and access requirements.

Secrato lets identity configuration follow that structure while keeping permissions and access governed within one environment.

HOW IT WORKS

How it maps to Secrato

TENANT LEVEL

Primary SSO per tenant. Optional secondary OTP for failover. Domain verification and trust policies.

WORKSPACE LEVEL

Override IdP or inherit tenant SSO. Map IdP groups to individual users. Local accounts with policy gates.

SUB-WORKSPACE LEVEL

Fine-grained role bindings for site teams. Evidence of access reviews per site. Automatic de-provisioning on events.

Email & Account Models

MULTI-DOMAIN

A multi-domain model allows multiple verified email domains to operate securely within one unified SaaS environment.

SINGLE EMAIL, MANY SCOPES

A single email identity with multiple scopes enables unified login and secure, role-based access across multiple workspaces or tenants.

LOCAL ACCOUNTS

A local account is a platform-managed user identity authenticated directly via email and password, offering flexible and secure access without requiring external SSO or directory integration.

Security & Compliance

RBAC & GROUP MAPPING

RBAC and group mapping enable automated, policy-based access control, ensuring users inherit the right permissions through identity integrations and predefined roles.

PROVISIONAL & LIFECYCLE

Establish secure onboarding, continuous compliance enforcement, and controlled offboarding, ensuring every account remains compliant and tightly governed from creation to removal.

AUDIT & VISIBILITY

Audit and visibility provide full traceability and real-time insight into platform activities, enabling continuous oversight, compliance validation, and rapid incident response.

CAPABILITIES

Built around the work that matters

Bring multiple domains together

Support several verified email domains within one governed environment, with sign-in policies applied according to the relevant domain.

Keep access separate by context

A single identity can hold roles across multiple tenants or workspaces while each access assignment remains scoped independently.

Support without an external provider

Provide platform-managed accounts where an external identity provider is not available, allowing those users to access Secrato within the same governed environment.

Maintain an alternative sign-in path

Support a secondary one-time-code authentication step as a fallback to primary tenant sign-in.

Govern access from entry to exit

Support provisioning, ongoing access management and controlled offboarding, with user and group information synchronised from connected identity providers.

Keep activity visible

Maintain traceable access activity to strengthen oversight and provide clearer context when access needs to be reviewed or investigated.

EU DATA SOVEREIGNTY

GRC data is processed on self-managed infrastructure in a Belgian datacentre, within the EU legal and regulatory environment.

Belgium · EU

Common questions

Can different parts of the organisation use different identity providers?

Yes. Identity can be configured at tenant level, while workspaces and sub-workspaces can inherit that configuration or use their own. This allows different parts of the organisation to retain the identity setup that fits their environment.

Yes. A single identity can hold roles across multiple tenants or workspaces. Each access assignment remains scoped independently, so permissions in one area do not automatically carry into another.

Secrato can support platform-managed local accounts for teams that do not use an external identity provider, allowing them to access the platform within the same governed access model.

Let identity adapt as your organisation grows

Different entities should not have to abandon the identity environments that already work for them simply to fit a central GRC platform. See how Multi-IDP Support can fit your identity structure and the tenants and workspaces it needs to govern.

Secrato