Skip to content

Identity & Access Model

OrviQ integrates identity authentication with granular Role-Based Access Control (RBAC).


Authentication & Session Management

  • Authentication: Native username/password authentication with configurable password complexity policies.
  • Session Tokens: Authenticated sessions utilize secure, encrypted HTTP tokens with configurable idle timeouts.
  • Role Scoping: Functional entitlements are derived from assigned roles (Compliance Manager, Risk Manager, Control Owner, Auditor, Read Only, Tenant Admin).
  • Segregation of Duties: Workflow actions enforce maker-checker separation, ensuring that creators cannot approve their own submissions.

OrviQ Enterprise Governance, Risk & Compliance Platform