Security and data protection

Access hygiene, and the data-protection paperwork a German company cannot avoid.

Two jobs sit here. One is keeping your team's access tight: second factors, sessions, and removing people the day they leave. The other is DSGVO: you are the controller for the personal data in your shop, and that comes with documents and deadlines regardless of what the software does.

Both are quarterly work at most. Both are unpleasant to start once an incident or an access request has already arrived.

Cockpit screens: partly planned. Multi-factor authentication, the session list and the activity log are shipped. Not yet on your tenant: an export of the activity log for auditors, a session policy or IP allowlist for your own team, managing individual passkeys inside the Cockpit, and any data-residency setting. What you can already use today: Settings › Profile › Security for your factors, Settings › Team › Sessions for everyone's sign-ins, and the Access register on every installed app for your processing record.
  • Security and data protection — multi-factor authentication, sessions, what the activity log is and is not, DSGVO obligations, and where your data lives.