Skip to content

Security and administration overview

Perslace includes settings for user access, two-factor authentication, Enterprise SSO, Action Lock, dual-admin access control, audit history, and notifications. Some setup workflows remain unverified.

For: Primary Admins, Admins, and Security or IT owners

Area What was observed Documentation status
User roles Employee, Manager, Admin, and Primary Admin concepts Manager scope and Primary Admin transfer or recovery require verification
Two-factor authentication TOTP option in settings Enrolment and recovery were not tested
Enterprise SSO SAML availability; settings mention Okta, Entra, and domain routing Provider setup and fallback require Enterprise testing
Action Lock Email verification for groups of high-impact actions Code delivery, expiry, and audit effects require testing
Access Control Description of second-admin approval The detailed route rendered blank; configuration instructions are blocked
Audit Log Search, date and module filters, actor, role, action, object, time, and changed-field count Verified for review; retention, export, and immutability are unknown
Notifications In-app activity plus configurable email events Counter semantics require clarification
  1. Assign the least-privileged role that supports each person’s work.
  2. Keep a separate employee record, login account, and role decision for each person.
  3. Require an approved test and recovery plan before enabling SSO, two-factor authentication, Action Lock, or dual-admin approvals.
  4. Review audit history after high-impact changes to plans, assignments, data, or payout cycles.
  5. Review user access periodically and remove unnecessary access through an approved lifecycle process.
  6. Keep credentials and sensitive financial data out of documentation, screenshots, and support messages.

Your organisation has a named Security owner, clear role decisions, an approval route for high-impact controls, and an evidence-preservation process.

This Help Centre does not make claims about encryption, data residency, certifications, retention, disaster recovery, or subprocessors. Use only Security and Legal-approved Perslace assurance material for those topics.

Last updated: August 2026