Authentication and Authorisation System
Authentication and Authorisation SystemComprehensive identity management, authentication and access control system based on roles and permissions for multi-tenant organizations.
Manages identities, organizations, groups, roles and permissions to access the applications and services of the platform.
A first look at what you can do with this product.
Simplify access with corporate identities and directory groups.
Limit each person's access to authorized resources.
Manage multiple organizations with separate data and configurations.
Connect identity management with other applications and services.
Check activity and access logs to support control.
Maintain an income experience consistent with your organization.
Select a category in the map to explore its features.
Choose a category or search across all product features. Browse the results page by page.
133 features
The search includes all categories.
Comprehensive identity management, authentication and access control system based on roles and permissions for multi-tenant organizations.
Main module for authentication of users using local credentials or integration with LDAP directories.
Authenticates users by name or email and password, validates the organization and issues JWT tokens with configurable expiration.
Logout process that invalidates active JWT tokens and records activity in session tracking audit logs.
Allows you to renew JWT tokens during the session according to authentication settings.
Monitoring and validation system of active sessions with automatic expiration capacity and detection of orphan sessions.
Complete management of the user life cycle including creation, editing, deletion, activation/deactivation and permission management associated with groups and roles.
Creation of new users with uniqueness validation, automatic role and group mapping, and initial credentials configuration.
Modification of user information including personal data, role changes, group assignment and permission update.
Process of logical and physical removal of users with clean relationships, active sessions and associated audit records.
User Status Control to enable or disable temporary access without deleting the account, including cleaning active sessions.
Password recovery system using security questions, recovery keys and automatic expiration email notifications.
Administration of multi-tenant organizations with specific parameter configuration, LDAP integration and associated application management.
Registration of new organizations with configuration of security parameters, color palette, logos and authentication settings.
Organizational parameters management including session expiration time, active session limit and authentication settings.
Configuration and management of LDAP connections for federated authentication, user and group synchronization from corporate directories.
Automatic synchronization process of users and groups from LDAP directories with attribute mapping and permission management.
Administration of user groups for hierarchical organization and massive allocation of permissions and roles within the organization.
Creation of groups with automatic assignment of permissions by role, configuration of service groups and administrative groups.
Linking and untying users to groups with automatic allocation of permissions and corresponding roles.
Administration of service groups, administrative groups and LDAP groups with special management and elimination rules.
Predefined role system with hierarchical permission levels from global administrator to basic user with granular access control.
It includes predefined hierarchical roles for global administration, organizations, groups and users.
Assignment of roles to users and groups with permission validation and hierarchical inheritance control of permits.
Access control list system for specific resources with granular display and editing permissions by group and object type.
Definition of access control lists for resources such as dashboards, panels, data sources and files with specific permissions.
Allocation and modification of visualization and editing permissions for specific groups on ACL protected resources.
Configuration of available object types for ACL including dashboards, panels, search engines, data sources and files.
Administration of applications integrated into the authentication system with group access control and authentication propagation.
Creation of applications with URL configuration, application types and integration parameters with the authentication system.
Manage supported and restricted groups for each application with configurable authentication propagation.
Distinguish application types to configure your accesses and integration with the identity system.
Management of backend services with certificate authentication, IP access control and service token management.
Creation of services with IP configuration, subnet, service type and generation of secure authentication tokens.
Service authentication system using client certificates, IP validation and expiration token management.
Manage supported and restricted groups for services with IP validation and granular access control.
System of actions or policies that define specific operations that users can perform with group access control.
Creation of actions with description, required permissions and visibility settings for specific groups.
Management of supported and restricted groups for specific actions with validation of permits at run time.
Permission verification system for specific actions with validation of user roles and groups.
Configurable captcha implementation for protection against automated attacks with visual and security parameters customization.
Captcha parameters management including length, characters, colors, image formatting and expiration time.
Dynamic creation of captchas with customizable configuration and validation of attempts with configurable limit.
Captcha response validation system with failed attempt control and automatic expiration.
Complete registration of system activities for audit, traceability and security analysis with advanced filters.
Automatic capture of all actions performed by users including creation, editing, deletion and access to resources.
Log query system with filters per user, group, application, object type, date and status of operation.
Log analysis tools with facets, statistics and reports for audit and detection of anomalies.
Asynchronous task system for long-term operations such as LDAP synchronization and data cleaning with status tracking.
Generation of asynchronous tasks for complex operations with assignment of unique identifiers and execution parameters.
Status monitoring and progress of asynchronous tasks with query and notification capability.
Automatic cleaning process of completed tasks and obsolete data for system performance optimization.
Customizable web authenticator system with configurable elements, customizable styles and post-login redirection.
Management of visual elements of the authenticator such as logos, text, side images and footer with configurable positioning.
Customization of visual styles including colors, fonts, spacing and responsive design of the authentication interface.
Management of post-authentication redirect URLs with source validation and configuration by organization.
User service system for client applications with certificate authentication and container management.
Creation of user services with validation of client certificates, container IP and generation of access tokens.
Heartbeat system for monitoring active user services with automatic detection of inactive services.
Automatic cleaning process of inactive user services and expired tokens for resource optimization.
Secure redirect mechanism for authentication between applications with automatic validation of origin and expiration.
Creation of temporary redirect URLs for authentication between applications with accepted source validation.
Redirection validation system with verification of origin, expiration and unique use for security.
Public API for validation of redirects from external applications without requiring prior authentication.
Set of security measures and functionalities implemented to protect the system, data and communications.
JSON Web Tokens implementation for stateless authentication with configurable expiration and blacklisting of revoked tokens.
Generate JWT tokens with custom attributes, cryptographic signature and configurable expiration.
Verification of JWT tokens including signature, expiration, claims and blacklist of revoked tokens.
Blacklist system for JWT tokens revoked with Redis storage and automatic cleaning.
federated authentication system with corporate LDAP directories for user and group synchronization.
Configuration of LDAP connections with credentials validation, search filter configuration and attribute mapping.
Automatic synchronization process of users and groups from LDAP with attribute mapping and conflict management.
Authentication system that allows users to authenticate with corporate LDAP credentials.
granular permission system based on roles, groups and ACL for precise control of access to resources.
System of hierarchical roles with inherited permissions and validation of access based on the user's role level.
Allocation of specific permits by group with capacity for granular restriction and admission.
Resource-specific access control lists with independent display and editing permissions.
Mechanisms for protection against common attacks such as brute force, automation and unauthorized access.
Customizable captcha system for protection against bots and automated attacks.
Control of failed authentication attempts with temporary blocking and security event notification.
Validate the origin of applications as part of access controls.
Features designed to support growth and high system availability.
It supports several organizations with data separation and organizational configuration.
Separates data by organization and applies access validations.
Configurable parameters by organization including authentication, styles and security policies.
Architecture that allows to scale horizontally adding instances of service according to demand.
Session management system compatible with distributed architectures and load balancers.
Use of JWT for stateless authentication that allows horizontal scalability without shared status.
Token blacklist system distributed using Redis for multi-instance compatibility.
Configurable session parameters including expiration time and active session limit.
Background task system for long-term operations without affecting the user's response.
Task queue system for asynchronous processing of complex operations such as LDAP synchronization.
Monitoring the status and progress of asynchronous tasks with consultation and reporting capacity.
Automatic processes of cleaning obsolete data and completed tasks for performance optimization.
Features for integration with external systems and client applications.
Complete RESTful programming interface for integration with client applications and external systems.
Complete set of REST endpoints for all system operations with detailed documentation.
Authentication system for APIs using JWT tokens with validation of permissions and roles.
Input data validation system with Marshmallow schemas and standardized error management.
Integration system with backend services through certificates and service tokens.
Authentication mechanism for services through client certificates and IP validation.
Generation and management of specific tokens for services with expiration and configured permissions.
Heartbeat system for monitoring active services and detection of inactive services.
Secure redirect system for authentication between integrated applications.
Generation of temporary URLs for redirection between applications with source validation.
Verification of the origin of redirections to prevent attacks and unauthorized access.
Public Endpoint for redirect validation without requiring prior authentication.
Complete monitoring, logging and auditing system for traceability and security analysis.
Complete registration of all activities of the system for security audit and analysis.
Automatic capture of all actions performed by users with full context.
Specific registration of security events such as failed authentication attempts and permission changes.
Registration of system events such as task creation, automatic cleaning and application errors.
Tools for querying and analyzing logs with advanced filters and reports.
Filter system for log queries by user, group, application, date and type of event.
Log analysis tools with facets for identification of patterns and anomalies.
It generates audit reports and records for security analysis.
System resource monitoring system and problem detection services.
Heartbeat system for verification of active services and fault detection.
Follow up on active sessions and detection of orphan or expired sessions.
Automatic processes of cleaning obsolete data and unused resources.
Functions for system customization according to the specific needs of each organization.
Fully customizable web authenticator system with configurable elements.
Configuration of logos, texts, images and visual elements of the authentication interface.
Complete customization of visual styles including colors, fonts and responsive design.
Management of post-authentication URLs specific to organization.
Parameters configurable by organization to adapt the system to specific needs.
Setting session expiration time, limit of attempts and password policies.
Customization of color palette, logos and visual elements of the organization.
Specific authentication parameters including LDAP and captcha integration.
Captcha system fully configurable with visual and safety parameters.
Configuration of length, characters, colors, image format and captcha style.
Expiry time configuration, attempt limit and exclusion of similar characters.
Integration of captcha into authentication flow with organization-specific configuration.
We didn't find features with those terms. Try a different word.
Explore how it relates to other products and shared capabilities.
Consultation · Analysis · Information management
IFINDIT
A platform to work with your organization's information.
Sources of information
A functional view of IFINDIT and its shared capabilities. Each product connects different needs of the organization.
Download SVG diagramTell us what you need to find, analyze or organize. Discover IFINDIT with the Creangel team.