Enterprise access controls: SAML SSO, SCIM, audit log export, read-only role
Three renewals and one new-business deal in the last 30 days were blocked by the same four gaps in access control and auditability. This epic closes the set so security review stops being a deal stage.
Northwind Labs sells into platform teams inside regulated enterprises, but the product only supports per-user email login, full-member permissions, and 30 days of audit history in the UI. Security questionnaires consistently fail on SAML SSO, SCIM deprovisioning, exportable 12-month audit logs, and a role that lets contractors read incidents without mutating them. Feedback is concentrated in escalation channels rather than public reviews, so it does not show up in volume-ranked lists — but it carries the highest revenue weight of any theme this month.
- Ship SAML 2.0 SSO with IdP-initiated and SP-initiated flows, verified against Okta and Entra ID.
- Add SCIM 2.0 user and group provisioning, with deprovisioning revoking sessions within 5 minutes.
- Extend audit log retention to 12 months and add an async CSV export scoped to an admin-selected range.
- Introduce a read-only workspace role that can view incidents, dashboards, and audit history but cannot acknowledge, edit, or invite.
- SSO enforcement is per-workspace and can coexist with break-glass email login for one designated owner.
- SCIM deprovisioning is idempotent and emits an audit event on every apply.
- Audit export runs asynchronously and emails a signed, expiring download link.
- Read-only role is enforced server-side; UI hiding alone is not sufficient.
- Every new admin action appears in the audit log with actor, target, and IP.
Meridian's security review needs SAML SSO plus SCIM deprovisioning before they'll sign the renewal in November.
Lost the security questionnaire round on audit logs — they need 12 months exportable.
The only option is full member access for contractors, which our security team blocked.