Security and administration overview
Perslace includes settings for user access, two-factor authentication, Enterprise SSO, Action Lock, dual-admin access control, audit history, and notifications. Some setup workflows remain unverified.
For: Primary Admins, Admins, and Security or IT owners
Available control areas
Section titled “Available control areas”| Area | What was observed | Documentation status |
|---|---|---|
| User roles | Employee, Manager, Admin, and Primary Admin concepts | Manager scope and Primary Admin transfer or recovery require verification |
| Two-factor authentication | TOTP option in settings | Enrolment and recovery were not tested |
| Enterprise SSO | SAML availability; settings mention Okta, Entra, and domain routing | Provider setup and fallback require Enterprise testing |
| Action Lock | Email verification for groups of high-impact actions | Code delivery, expiry, and audit effects require testing |
| Access Control | Description of second-admin approval | The detailed route rendered blank; configuration instructions are blocked |
| Audit Log | Search, date and module filters, actor, role, action, object, time, and changed-field count | Verified for review; retention, export, and immutability are unknown |
| Notifications | In-app activity plus configurable email events | Counter semantics require clarification |
Recommended administrative baseline
Section titled “Recommended administrative baseline”- Assign the least-privileged role that supports each person’s work.
- Keep a separate employee record, login account, and role decision for each person.
- Require an approved test and recovery plan before enabling SSO, two-factor authentication, Action Lock, or dual-admin approvals.
- Review audit history after high-impact changes to plans, assignments, data, or payout cycles.
- Review user access periodically and remove unnecessary access through an approved lifecycle process.
- Keep credentials and sensitive financial data out of documentation, screenshots, and support messages.
Expected result
Section titled “Expected result”Your organisation has a named Security owner, clear role decisions, an approval route for high-impact controls, and an evidence-preservation process.
Important notes
Section titled “Important notes”This Help Centre does not make claims about encryption, data residency, certifications, retention, disaster recovery, or subprocessors. Use only Security and Legal-approved Perslace assurance material for those topics.
Related articles
Section titled “Related articles”Last updated: August 2026