All platform features
Access control & audit
Granular role-based permissions and an audit log that records configuration changes and operator writes.

Permissions are defined per API surface and per resource, not as a single admin flag. Every configuration change and every operator write is recorded with the actor, the action and the client address.
SSO is on the roadmap; today authentication is username and password with role-based authorisation on top.
What you get
- Role-based access control with per-resource permissions
- Audit log of configuration changes and writes
- Client IP recorded against each action
- External journal option for the audit trail