RBAC, SSO, and Separation of Duties in Enterprise iPaaS

Access control built for enterprise iPaaS

Role-based access control, SSO, MFA, scoped permissions, environment-level controls, and audit logs that help teams secure integration environments and support separation of duties.

Why it matters

Secure the users, roles, and environments behind your integrations

Integration platforms sit at the center of sensitive business processes. They connect applications, move data, manage credentials, trigger workflows, and handle exceptions across the business.

Celigo helps enterprise teams secure integration access with controls that support access provisioning, separation of duty, and regulatory compliance — including the option to enforce SSO across your entire account, not just for individually selected users.

Roles and access levels

Access control across every layer of integration work

Give users the right level of access based on what they need to do. Celigo supports account owner, admin, and user roles. Users can be assigned Manage all, Monitor all, or Custom access depending on their responsibilities.

Manage all

For builders who need to create, edit, and manage integrations and resources across the account.

Monitor all

For operators who need to view integrations and perform selected runtime actions, such as running flows, assigning errors, and retrying or resolving errors, without modifying flow design or account settings.

Custom access

For teams that need to scope manage or monitor permissions to selected integrations.

Automated provisioning with SCIM

User and group changes in your identity provider stay in sync automatically. When someone joins, changes teams, or leaves, their Celigo access updates or revokes without an admin having to do it by hand.

Scoped permissions

Limit access without blocking work

Custom access lets admins scope permissions to specific integrations, so users can work where they need to without receiving broad account-wide access. Admins can also enable specific exceptions only when needed, such as allowing certain monitor users to edit retry data or create an integration workspace.

Use it to support:

Least privileged access
Integration-specific access
Builder and operator separation
Safer delegated administration
More controlled production access

Separation of duties

Support separation of duties without slowing delivery

Give builders the access they need

Builders can receive Manage access where they need to create, edit, and maintain integrations. Access can be scoped so builders work on the integrations and environments they are responsible for, rather than receiving unnecessary account-wide control.

Let operators resolve issues without changing design

Operators can receive Monitor access where they need to run flows, review operational status, assign errors, and retry or resolve issues. They can help keep integrations running without receiving permission to modify flow design, account settings, connections, or API tokens.

Keep administration separate

Admins manage users, environments, and account-level configuration, keeping platform administration separate from day-to-day integration building and runtime operations. Delegated invitations stay bounded, too: a Manage-level user can invite others, but only up to their own permission level — no accidental privilege escalation as administration gets shared across a team.

Give reviewers the evidence they need

Reviewers can use audit logs to see what changed, when it changed, who changed it, and where the change came from, giving security, compliance, and operations teams a clearer way to review access and configuration changes.

Scope access by job, integration, and environment

Celigo supports separation of duties as an operating model. The right users get the right level of control for the work they are responsible for, without every role needing broad access across the integration environment.

Enterprise integration teams need to move fast without giving every user broad access. Celigo helps teams separate responsibilities across builders, operators, admins, and reviewers using scoped roles, custom permissions, environment-level access controls, and audit logs.

Governance at every stage

Control the full lifecycle, and prove every change

Environments

Environment-level access controls

Control access across the full integration lifecycle, not just production. Celigo accounts support a single Production environment alongside one or more non-production environments.

Teams can invite users to specific environments, edit access by environment, or remove it entirely — so a user can hold Manage access in dev and Monitor access in production, giving builders room to develop and test safely while keeping production risk contained.

Audit logs

Audit logs for access and change review

Celigo audit logs record configuration activity across integrations, flows, exports, imports, connections, lookup caches, file definitions, revisions, scripts, users, SSO clients, and API tokens — including changed fields, change type, responsible user, source, and old and new values where available, with side-by-side diffs for certain changes.

Use it to answer compliance and operational questions instantly: who changed this integration, what changed, and when.

Built on a verified compliance foundation

Access controls only matter if they hold up to outside scrutiny.

Celigo maintains SOC 2 Type II certification, ISO 27001 certification, and adherence to the Data Privacy Framework. Combined with the audit trail, role-based access controls, and separation of duties covered above, this gives compliance and security teams a verifiable foundation to point to, not just a set of controls to take on faith.

Access control doesn’t stop at roles. Environment-level controls decide where each user can act across dev and production, and audit logs record what changed, who changed it, and when.

FAQs

Access control questions, answered