IdP and SSO — identity and access

How your company identity talks to the platform, and who sees what.

1 min read · Last updated: 08-2026

What an IdP is

An Identity Provider is the service that holds your company identities and vouches for them when a system asks who is who. It is what enables single sign-on: a person logs in once and applications trust that session.

The practical advantage shows on offboarding: revoking the identity at the IdP removes access from every application at once, without relying on someone remembering each system.

Role-based permissions

Inside the platform, access is role-based (RBAC): each person sees only the devices and metrics in their scope. The account owner decides who is an administrator or a partner.

RoleSeesCan act
OwnerThe whole fleetEverything, including billing and roles
AdministratorThe whole fleetPolicies, lockdowns and reports
Team managerTheir group onlyReports and shifts for the group
Read onlyDefined scopeNothing — consultation only

Access windows

Beyond who can log in, the company sets when and from where: the hours and geographic regions each device is allowed to run in. Outside the window, access does not open — and the attempt is logged.

Windows are configured per group, so operations in different time zones live in the same fleet without a manual exception device by device.

Up next

Device lockdown

From blocking a single port to shutting the machine down remotely — and when to use each level.

Keep reading

Klaar om je team te monitoren met precisie?

Begin vandaag gratis. Geen creditcard nodig. Ingericht in minder dan 5 minuten.

7 dagen gratis proberen
Geen creditcard
Altijd opzegbaar
Schermmonitoring in realtimeVergrendeling van USB-poorten en BluetoothDienstcontrole met automatische tijdregistratieSites en programma's toegestaan via beleidLocatie en geografische grenzenVoorzorgsvergrendeling van het apparaatProductiviteitsrapporten van het teamEnd-to-end AES-256-versleutelingSchermmonitoring in realtimeVergrendeling van USB-poorten en BluetoothDienstcontrole met automatische tijdregistratieSites en programma's toegestaan via beleidLocatie en geografische grenzenVoorzorgsvergrendeling van het apparaatProductiviteitsrapporten van het teamEnd-to-end AES-256-versleuteling