01
Multi-tenant identity
Organizations and workspaces with full tenant isolation. Every user, every membership, every permission scoped to the right level.
- ✓ Organizations with multiple workspaces
- ✓ Per-tenant data isolation
- ✓ Single sign-on across the platform
- ✓ Identity events streamed to the audit log
02
Partner-managed onboarding
White-labeled invite flows. Partners onboard their own clients with their own branding, their own email templates, their own terms.
- ✓ Partner-scoped admin console
- ✓ Custom invite emails per partner
- ✓ Bulk CSV invitations
- ✓ Initial-owner provisioning flows
03
Role-based access controls
Owner / Admin / Member / Guest at every level. Permissions cascade from partner to organization to workspace. Every grant is auditable.
- ✓ Four standard roles, per level
- ✓ Permission cascading
- ✓ Per-membership overrides
- ✓ Suspend / reactivate without losing state
04
Audit & compliance
Every authentication, every membership change, every permission grant — written to an append-only audit log. Queryable, exportable, SOC-2-friendly.
- ✓ Append-only audit events
- ✓ Per-org and per-partner event scopes
- ✓ Filtered queries by actor, target, time
- ✓ Export to CSV or JSONL