RBAC, SSO, and Separation of Duties in Enterprise iPaaS
Access control built for enterprise iPaaS
Role-based access control, SSO, MFA, scoped permissions, environment-level controls, and audit logs that help teams secure integration environments and support separation of duties.
Secure the users, roles, and environments behind your integrations
Integration platforms sit at the center of sensitive business processes. They connect applications, move data, manage credentials, trigger workflows, and handle exceptions across the business.
Celigo helps enterprise teams secure integration access with controls that support access provisioning, separation of duty, and regulatory compliance — including the option to enforce SSO across your entire account, not just for individually selected users.
Roles and access levels
Access control across every layer of integration work
Give users the right level of access based on what they need to do. Celigo supports account owner, admin, and user roles. Users can be assigned Manage all, Monitor all, or Custom access depending on their responsibilities.
Manage all
For builders who need to create, edit, and manage integrations and resources across the account.
Monitor all
For operators who need to view integrations and perform selected runtime actions, such as running flows, assigning errors, and retrying or resolving errors, without modifying flow design or account settings.
Custom access
For teams that need to scope manage or monitor permissions to selected integrations.
Automated provisioning with SCIM
User and group changes in your identity provider stay in sync automatically. When someone joins, changes teams, or leaves, their Celigo access updates or revokes without an admin having to do it by hand.
Limit access without blocking work
Custom access lets admins scope permissions to specific integrations, so users can work where they need to without receiving broad account-wide access. Admins can also enable specific exceptions only when needed, such as allowing certain monitor users to edit retry data or create an integration workspace.
Use it to support:
Separation of duties
Support separation of duties without slowing delivery
Give builders the access they need
Builders can receive Manage access where they need to create, edit, and maintain integrations. Access can be scoped so builders work on the integrations and environments they are responsible for, rather than receiving unnecessary account-wide control.
Let operators resolve issues without changing design
Operators can receive Monitor access where they need to run flows, review operational status, assign errors, and retry or resolve issues. They can help keep integrations running without receiving permission to modify flow design, account settings, connections, or API tokens.
Keep administration separate
Admins manage users, environments, and account-level configuration, keeping platform administration separate from day-to-day integration building and runtime operations. Delegated invitations stay bounded, too: a Manage-level user can invite others, but only up to their own permission level — no accidental privilege escalation as administration gets shared across a team.
Give reviewers the evidence they need
Reviewers can use audit logs to see what changed, when it changed, who changed it, and where the change came from, giving security, compliance, and operations teams a clearer way to review access and configuration changes.
Scope access by job, integration, and environment
Celigo supports separation of duties as an operating model. The right users get the right level of control for the work they are responsible for, without every role needing broad access across the integration environment.
Enterprise integration teams need to move fast without giving every user broad access. Celigo helps teams separate responsibilities across builders, operators, admins, and reviewers using scoped roles, custom permissions, environment-level access controls, and audit logs.
Governance at every stage
Control the full lifecycle, and prove every change
Environments
Environment-level access controls
Control access across the full integration lifecycle, not just production. Celigo accounts support a single Production environment alongside one or more non-production environments.
Teams can invite users to specific environments, edit access by environment, or remove it entirely — so a user can hold Manage access in dev and Monitor access in production, giving builders room to develop and test safely while keeping production risk contained.
Audit logs
Audit logs for access and change review
Celigo audit logs record configuration activity across integrations, flows, exports, imports, connections, lookup caches, file definitions, revisions, scripts, users, SSO clients, and API tokens — including changed fields, change type, responsible user, source, and old and new values where available, with side-by-side diffs for certain changes.
Use it to answer compliance and operational questions instantly: who changed this integration, what changed, and when.
Built on a verified compliance foundation
Access controls only matter if they hold up to outside scrutiny.
Celigo maintains SOC 2 Type II certification, ISO 27001 certification, and adherence to the Data Privacy Framework. Combined with the audit trail, role-based access controls, and separation of duties covered above, this gives compliance and security teams a verifiable foundation to point to, not just a set of controls to take on faith.
Access control doesn’t stop at roles. Environment-level controls decide where each user can act across dev and production, and audit logs record what changed, who changed it, and when.