Enterprise-grade user management, RBAC, team organization, and SSO integration. Secure and compliant configuration for modern engineering teams.

Configuration Features
Secure, compliant, and scalable configuration management for teams of any size.
Granular permissions and roles for users, teams, and services. Control who can create incidents, execute runbooks, and access sensitive data.
Organize users into teams with hierarchies, delegated permissions, and flexible ownership models. Support for matrix and functional structures.
Integration with SAML, OIDC, and OAuth providers. Support for Okta, Azure AD, Google Workspace, and custom identity providers.
Define service ownership with primary and secondary owners. Automatically route incidents based on service ownership and expertise.
Complete audit trail of all configuration changes, user actions, and system events. Essential for compliance and security investigations.
Support for multiple organizations and environments. Isolate data and configuration across prod, staging, and dev with inheritance.
Flexible user and team organization
Organize your engineering organization with teams, roles, and permissions that match your structure.
Create teams with nested sub-teams. Define parent-child relationships for permission inheritance and escalation paths. Support for matrix organizations with users belonging to multiple teams.
Pre-defined roles (Admin, Engineer, Observer) or create custom roles with granular permissions. Control access to incidents, runbooks, analytics, configuration, and billing.
Map services to owning teams with primary and secondary owners. Automatically route incidents to service owners. Track ownership changes over time for accountability.
Manage on-call rotations per team with primary/secondary coverage. Support for follow-the-sun schedules, temporary overrides, and vacation management. Integrate with PagerDuty for unified on-call.
Built for enterprise security requirements
SOC 2 Type II certified with comprehensive security controls and compliance features.
SAML 2.0 and OIDC support for enterprise identity providers. Works with Okta, Azure AD, Google Workspace, OneLogin, and custom providers. Automatic user provisioning and de-provisioning via SCIM.
Enforce MFA for all users or specific roles. Support for TOTP, SMS, and WebAuthn. Admin controls to require MFA for sensitive operations like runbook execution.
Immutable audit trail of all user actions, configuration changes, and system events. Export to SIEM for security monitoring. Retention policies for compliance (HIPAA, SOC 2, GDPR).
Encryption at rest (AES-256) and in transit (TLS 1.3). Customer-managed encryption keys (CMEK) for sensitive data. Field-level encryption for PII and credentials.
Restrict access to specific IP ranges for enhanced security. Configure different allowlists for web UI, API, and SSH access. Support for VPN and corporate network requirements.
Configurable session timeouts and idle timeouts. Concurrent session limits per user. Admin ability to revoke sessions globally or per user. Support for single-logout (SLO).
Multiple environments with data isolation
Separate production, staging, and development environments with isolated data and configuration.
Create separate environments (prod, staging, dev) with complete data isolation. Test configuration changes in staging before promoting to production.
Define global settings that apply to all environments with per-environment overrides. Promote configuration changes across environments with approval workflows.
Test runbooks in staging before executing in production. Validate escalation policies and notification channels without impacting production on-call.
See how Sentinel AI provides enterprise-grade access control and user management.