Single Sign-On SCIM Provisioning MFA IP Allowlisting Access Control Audit Logging Reliability & Scale Packaging

This page describes the identity, access, and audit controls that larger organizations require for rollout and security review, how each works, and the standards it is built on. Available today: single sign-on over SAML 2.0 and OIDC, SCIM user provisioning and deprovisioning, organization-wide MFA enforcement, IP address allowlisting, role-based access control, and audit logging with SIEM export, all included at every tier with no security add-on fee. Torgix runs on enterprise Microsoft Azure infrastructure with a 99.5% uptime commitment and compute and storage that scale on demand, covered under Platform Reliability & Scale. For Torgix's company-wide security posture (infrastructure, encryption, monitoring, and compliance), see the Security overview.

Single Sign-On & SCIM
SAML 2.0 and OIDC sign-on, with automated user provisioning and deprovisioning from your identity provider.
Multi-Factor Authentication
Authenticator-app MFA with backup codes, plus organization-wide enforcement an administrator can require for the whole team.
Role-Based Access Control
Custom roles with granular, per-module permissions and access scoped by team, location, or territory.
Audit Logging
A searchable, exportable record of security-relevant activity, with a configurable retention period.
Reliability & Scale
Runs on enterprise Microsoft Azure with a 99.5% uptime commitment and compute and storage that scale on demand as your operation grows.
⚙️
Configured by you, not by a consultant

Users, roles, and what each role can see, set in plain English. Workflows you build by describing them, reviewed before anything applies, and every run undoable.

Read the transcript

01 · The best admin panel is the one the office manager can run.

02 · Users, roles, and what each role can see, set in plain English. Categories, custom fields, and hover help you write yourself.

03 · And workflows. Automations you build by describing them, reviewed before anything applies, and every run undoable. No IT department required.

04 · Configured by you, not by a consultant. Torgix.

Real product screens. Figures shown are illustrative demo data.

🔑
Single Sign-On (SSO)

Browser-based single sign-on so users authenticate through your identity provider instead of a separate Torgix password.

CapabilityWhat it does
ProtocolsSign-on over SAML 2.0 and OpenID Connect (OIDC, which runs on OAuth 2.0), so Torgix works with standards-compliant identity providers.
Identity providersCompatible with major providers including Okta, Microsoft Entra ID (Azure AD), and Google Workspace, plus any standards-compliant SAML or OIDC provider.
Per-company configurationEach organization configures and tests its own SSO connection in admin settings before turning it on for users.
Just-in-time provisioningA Torgix account is created on a user's first successful sign-on, using attributes passed from the identity provider.
Default role for new usersAccounts provisioned through SSO are assigned a configurable default role set by your administrator. Fine-grained group-to-role mapping is on the roadmap.
Break-glass accessA local administrator path is always preserved, so a misconfigured SSO connection cannot lock an organization out.
🔄
SCIM Provisioning

Automated user lifecycle through the SCIM 2.0 standard, so directory changes flow into Torgix without manual steps.

CapabilityWhat it does
ProvisioningUsers added in your identity provider are created in Torgix automatically, over SCIM 2.0.
Attribute syncProfile changes such as name, email, group, and status sync from the identity provider to Torgix.
DeprovisioningWhen a user is disabled or removed in your identity provider, their Torgix account is deactivated and any active session is ended within about a minute, so access is revoked promptly rather than at their next sign-in.
Role assignmentNew users are provisioned at a configurable default role; group-driven role mapping is on the roadmap.
📱
Multi-Factor Authentication (MFA)

Multi-factor authentication for accounts that sign in directly, available to every user, and an administrator can require it organization-wide.

CapabilityWhat it does
Authenticator appTime-based one-time passcodes from standard authenticator apps, using the TOTP standard.
Recovery codesOne-time backup codes for sign-in when an authenticator device is unavailable.
Organization-wide enforcementAn administrator can require MFA for every user in the organization; anyone not yet enrolled is prompted to set it up before they can continue.
Single sign-on accountsFor users who sign in through SSO, MFA is typically enforced by your identity provider. This policy covers accounts that sign in directly to Torgix.
🌐
IP Address Allowlisting

Restrict where your team can sign in from, so Torgix web access is limited to your organization's approved networks.

CapabilityWhat it does
Approved networksAn administrator sets the IP addresses and CIDR ranges allowed to sign in. Sign-in from any other network is blocked.
Applies to user sign-inEnforced on user web sessions. Token-authenticated integrations, including SSO, SCIM, and the REST API, are not affected, so identity-provider and SIEM connections keep working.
Lock-out protectionAn administrator cannot save a list that excludes their own current address, so an organization cannot accidentally lock itself out.
👥
Role-Based Access Control (RBAC)

Control over who can see and do what, enforced in the data layer and applied the same way across the app and the API.

CapabilityWhat it does
Custom rolesDefine roles beyond the standard set, each with its own permission set.
Per-module permissionsGrant view, create, edit, delete, and export rights per module, including assets, work orders, maintenance, inspections, parts, and rentals.
Record scopingLimit access by team, location, or territory, so users see only the records for their part of the organization.
Server-side enforcementPermission checks run in the data and API layer rather than only hiding items in the interface, and apply identically in the Torgix app and the REST API.
🧾
Audit Logging

A record of security-relevant activity that an administrator can search, export, and retain for as long as policy requires.

CapabilityWhat it does
Events capturedAuthentication events, data changes, permission and role changes, configuration changes, exports, and administrative actions.
Entry detailEach entry records the actor, the action, the affected record, before and after values where applicable, the IP address, a request ID, and a timestamp in UTC.
Search and filterAdministrators can search and filter the log inside Torgix.
Export and SIEMLog entries can be exported on demand in CSV or JSON, and pulled programmatically into a SIEM such as Splunk over the REST API.
RetentionThe retention period for the audit log is configurable.
📈
Platform Reliability & Scale

The foundation an IT team asks about after identity: where it runs, how it scales, and what happens when something fails. For the full infrastructure, encryption, and compliance detail, see the Security overview.

CapabilityWhat it does
Enterprise cloud foundationRuns on Microsoft Azure, which holds SOC 2 Type II, ISO 27001, and PCI DSS certification at the platform level.
Uptime commitmentA 99.5% monthly availability commitment, with a formal SLA available on enterprise agreements.
Scales on demandManaged Azure App Service and Azure SQL Database scale compute and storage as an account grows, with no re-platforming or data migration.
Data residencyCustomer data is processed and stored in US-based Azure regions.
Backups and recoveryDaily database snapshots retained for 30 days and encrypted with AES-256, with disaster-recovery targets of under 4 hours to restore and under 24 hours of data loss.
Tenant isolationEach organization's data is logically isolated, and cross-tenant access is prevented in the data layer.
📦
Packaging & Administration

How these controls are licensed and administered.

CapabilityWhat it does
Included at every tierAdvanced security is included in every Torgix plan. There is no separate security add-on or per-seat security fee. See Pricing.
Multi-tenant isolationEach organization's identity connections, roles, and audit data are isolated from other tenants.
Administered in-appOwners and administrators configure roles, MFA, SSO, SCIM, IP allowlisting, and audit settings in the company's admin section.
Consistent across app and APIThe same role and permission model governs both the Torgix interface and the REST API add-on.

📩 For security teams

If you are evaluating Torgix and need documentation or have questions about Torgix security, contact security@torgix.ai.

For company-wide controls, encryption, and compliance, see the Security overview.

Last reviewed: August 2026 • Torgix, Inc. • Security overviewPricing
Start Free Trial →