IdP and SSO — identity and access

How your company identity talks to the platform, and who sees what.

1 min read · Last updated: 2026/08

What an IdP is

An Identity Provider is the service that holds your company identities and vouches for them when a system asks who is who. It is what enables single sign-on: a person logs in once and applications trust that session.

The practical advantage shows on offboarding: revoking the identity at the IdP removes access from every application at once, without relying on someone remembering each system.

Role-based permissions

Inside the platform, access is role-based (RBAC): each person sees only the devices and metrics in their scope. The account owner decides who is an administrator or a partner.

RoleSeesCan act
OwnerThe whole fleetEverything, including billing and roles
AdministratorThe whole fleetPolicies, lockdowns and reports
Team managerTheir group onlyReports and shifts for the group
Read onlyDefined scopeNothing — consultation only

Access windows

Beyond who can log in, the company sets when and from where: the hours and geographic regions each device is allowed to run in. Outside the window, access does not open — and the attempt is logged.

Windows are configured per group, so operations in different time zones live in the same fleet without a manual exception device by device.

Up next

Device lockdown

From blocking a single port to shutting the machine down remotely — and when to use each level.

Keep reading

チームの運用を、 より正確に?

今日から無料で始められます。カード登録は不要、設定は 5 分未満です。

7 日間の無料トライアル
カード登録不要
いつでも解約可能
リアルタイムの画面モニタリングUSB ポートと Bluetooth のロック自動打刻によるシフト管理ポリシーで許可されたサイトとプログラム位置情報と地理的な範囲端末の予防的ロックチームの生産性レポートエンドツーエンドの AES-256 暗号化リアルタイムの画面モニタリングUSB ポートと Bluetooth のロック自動打刻によるシフト管理ポリシーで許可されたサイトとプログラム位置情報と地理的な範囲端末の予防的ロックチームの生産性レポートエンドツーエンドの AES-256 暗号化