This page describes the identity, access, and audit controls that larger organizations require for rollout and security review, how each works, and the standards it is built on. Available today: single sign-on over SAML 2.0 and OIDC, SCIM user provisioning and deprovisioning, organization-wide MFA enforcement, IP address allowlisting, role-based access control, and audit logging with SIEM export, all included at every tier with no security add-on fee. Torgix runs on enterprise Microsoft Azure infrastructure with a 99.5% uptime commitment and compute and storage that scale on demand, covered under Platform Reliability & Scale. For Torgix's company-wide security posture (infrastructure, encryption, monitoring, and compliance), see the Security overview.
Users, roles, and what each role can see, set in plain English. Workflows you build by describing them, reviewed before anything applies, and every run undoable.
Read the transcript
01 · The best admin panel is the one the office manager can run.
02 · Users, roles, and what each role can see, set in plain English. Categories, custom fields, and hover help you write yourself.
03 · And workflows. Automations you build by describing them, reviewed before anything applies, and every run undoable. No IT department required.
04 · Configured by you, not by a consultant. Torgix.
Real product screens. Figures shown are illustrative demo data.
Browser-based single sign-on so users authenticate through your identity provider instead of a separate Torgix password.
| Capability | What it does |
|---|---|
| Protocols | Sign-on over SAML 2.0 and OpenID Connect (OIDC, which runs on OAuth 2.0), so Torgix works with standards-compliant identity providers. |
| Identity providers | Compatible with major providers including Okta, Microsoft Entra ID (Azure AD), and Google Workspace, plus any standards-compliant SAML or OIDC provider. |
| Per-company configuration | Each organization configures and tests its own SSO connection in admin settings before turning it on for users. |
| Just-in-time provisioning | A Torgix account is created on a user's first successful sign-on, using attributes passed from the identity provider. |
| Default role for new users | Accounts provisioned through SSO are assigned a configurable default role set by your administrator. Fine-grained group-to-role mapping is on the roadmap. |
| Break-glass access | A local administrator path is always preserved, so a misconfigured SSO connection cannot lock an organization out. |
Automated user lifecycle through the SCIM 2.0 standard, so directory changes flow into Torgix without manual steps.
| Capability | What it does |
|---|---|
| Provisioning | Users added in your identity provider are created in Torgix automatically, over SCIM 2.0. |
| Attribute sync | Profile changes such as name, email, group, and status sync from the identity provider to Torgix. |
| Deprovisioning | When a user is disabled or removed in your identity provider, their Torgix account is deactivated and any active session is ended within about a minute, so access is revoked promptly rather than at their next sign-in. |
| Role assignment | New users are provisioned at a configurable default role; group-driven role mapping is on the roadmap. |
Multi-factor authentication for accounts that sign in directly, available to every user, and an administrator can require it organization-wide.
| Capability | What it does |
|---|---|
| Authenticator app | Time-based one-time passcodes from standard authenticator apps, using the TOTP standard. |
| Recovery codes | One-time backup codes for sign-in when an authenticator device is unavailable. |
| Organization-wide enforcement | An administrator can require MFA for every user in the organization; anyone not yet enrolled is prompted to set it up before they can continue. |
| Single sign-on accounts | For users who sign in through SSO, MFA is typically enforced by your identity provider. This policy covers accounts that sign in directly to Torgix. |
Restrict where your team can sign in from, so Torgix web access is limited to your organization's approved networks.
| Capability | What it does |
|---|---|
| Approved networks | An administrator sets the IP addresses and CIDR ranges allowed to sign in. Sign-in from any other network is blocked. |
| Applies to user sign-in | Enforced on user web sessions. Token-authenticated integrations, including SSO, SCIM, and the REST API, are not affected, so identity-provider and SIEM connections keep working. |
| Lock-out protection | An administrator cannot save a list that excludes their own current address, so an organization cannot accidentally lock itself out. |
Control over who can see and do what, enforced in the data layer and applied the same way across the app and the API.
| Capability | What it does |
|---|---|
| Custom roles | Define roles beyond the standard set, each with its own permission set. |
| Per-module permissions | Grant view, create, edit, delete, and export rights per module, including assets, work orders, maintenance, inspections, parts, and rentals. |
| Record scoping | Limit access by team, location, or territory, so users see only the records for their part of the organization. |
| Server-side enforcement | Permission checks run in the data and API layer rather than only hiding items in the interface, and apply identically in the Torgix app and the REST API. |
A record of security-relevant activity that an administrator can search, export, and retain for as long as policy requires.
| Capability | What it does |
|---|---|
| Events captured | Authentication events, data changes, permission and role changes, configuration changes, exports, and administrative actions. |
| Entry detail | Each entry records the actor, the action, the affected record, before and after values where applicable, the IP address, a request ID, and a timestamp in UTC. |
| Search and filter | Administrators can search and filter the log inside Torgix. |
| Export and SIEM | Log entries can be exported on demand in CSV or JSON, and pulled programmatically into a SIEM such as Splunk over the REST API. |
| Retention | The retention period for the audit log is configurable. |
The foundation an IT team asks about after identity: where it runs, how it scales, and what happens when something fails. For the full infrastructure, encryption, and compliance detail, see the Security overview.
| Capability | What it does |
|---|---|
| Enterprise cloud foundation | Runs on Microsoft Azure, which holds SOC 2 Type II, ISO 27001, and PCI DSS certification at the platform level. |
| Uptime commitment | A 99.5% monthly availability commitment, with a formal SLA available on enterprise agreements. |
| Scales on demand | Managed Azure App Service and Azure SQL Database scale compute and storage as an account grows, with no re-platforming or data migration. |
| Data residency | Customer data is processed and stored in US-based Azure regions. |
| Backups and recovery | Daily database snapshots retained for 30 days and encrypted with AES-256, with disaster-recovery targets of under 4 hours to restore and under 24 hours of data loss. |
| Tenant isolation | Each organization's data is logically isolated, and cross-tenant access is prevented in the data layer. |
How these controls are licensed and administered.
| Capability | What it does |
|---|---|
| Included at every tier | Advanced security is included in every Torgix plan. There is no separate security add-on or per-seat security fee. See Pricing. |
| Multi-tenant isolation | Each organization's identity connections, roles, and audit data are isolated from other tenants. |
| Administered in-app | Owners and administrators configure roles, MFA, SSO, SCIM, IP allowlisting, and audit settings in the company's admin section. |
| Consistent across app and API | The same role and permission model governs both the Torgix interface and the REST API add-on. |
📩 For security teams
If you are evaluating Torgix and need documentation or have questions about Torgix security, contact security@torgix.ai.
For company-wide controls, encryption, and compliance, see the Security overview.