Skip to main content

Security Overview

Security and governance for connected IT operations

A practical view of the controls Stack-Ops uses around access, auditability, tenant isolation, protected credentials, and identity.

Access Control

Stack-Ops uses role and permission checks to control access to operational and administrative areas.

Built-in Admin, Technician, and End User roles
Permission-gated API and module actions
Plan-based custom roles and permission controls
Controlled administrative access for workspace settings and billing

Auditability

Operational records are designed to keep important actions traceable for review and follow-up.

Audit logs for significant platform actions
Activity history across tickets, assets, task cases, and subscriptions
Actor and timestamp context on important changes
Audit log retention controlled by plan

Data Protection

Security controls are built around tenant-scoped data access and protected integration secrets.

HTTPS and TLS for browser and API traffic
Tenant-scoped records and query filters for logical isolation
Encrypted storage for cloud connector credential secrets
Soft-delete and retention behavior for operational records where implemented

Identity & Authentication

Authentication controls support both local account security and external identity options.

Multi-factor authentication support
Microsoft Entra ID and Google sign-in paths
SSO and LDAP options on eligible plans
Session and login activity tracking

Built into the operating model

Stack-Ops does not treat governance as a disconnected settings page. Controls are tied to the records IT teams manage: tickets, assets, employees, vendors, contracts, software, cloud resources, and task cases.

1

User signs in

Authentication, tenant membership, and role context are evaluated.

2

Technician opens a record

Permissions control which operational data is visible and editable.

3

Admin changes access

Role or configuration changes become part of audit history.

4

Integration connects

API and webhook usage follows platform-level access controls.