Appearance
Identity & Access Model
OrviQ integrates identity authentication with granular Role-Based Access Control (RBAC).
Authentication & Session Management
- Authentication: Native username/password authentication with configurable password complexity policies.
- Session Tokens: Authenticated sessions utilize secure, encrypted HTTP tokens with configurable idle timeouts.
- Role Scoping: Functional entitlements are derived from assigned roles (Compliance Manager, Risk Manager, Control Owner, Auditor, Read Only, Tenant Admin).
- Segregation of Duties: Workflow actions enforce maker-checker separation, ensuring that creators cannot approve their own submissions.