Operations · Identity

A security tool should be the last place your access controls get weaker.

Mobexa connects to the identity provider your organisation already trusts over SAML 2.0 and OIDC, enforces role-based access so people see only what their job requires, and isolates every tenant on the server - so the platform that holds your most sensitive findings is governed as tightly as the apps it tests.

SAML 2.0OIDCRole-based accessTenant isolation
Identity & access

Governed the way the rest of your stack already is

Single sign-on, your provider

SAML 2.0 and OIDC mean no separate password to manage, no orphaned accounts, and access that ends the moment someone leaves your directory.

Role-based access

Run, triage, read and administer are distinct rights. People get the access their role needs and nothing beyond it - least privilege without a spreadsheet.

Tenant isolation, enforced server-side

Every request is scoped to the owning organisation on the server. Cross-tenant data is not hidden in the UI - it is never returned.

Auditable by design

Sensitive actions are logged with actor, target and time, so access can be reviewed and reconstructed when it matters.


Roles at a glance

Who can do what, by default

A sensible separation of duties out of the box, adjustable to how your team is structured.

CapabilityAdminAnalystViewer
Run & manage scansYesYesNo
Triage & transition findingsYesYesNo
Read evidence & reportsYesYesYes
Manage members & SSOYesNoNo
Change platform settings & keysYesNoNo

The most sensitive surfaces are gated

Integration credentials, API keys and configuration sit behind administrator access on purpose. A security platform that leaked its own keys to every viewer would be the vulnerability - so it does not.


Questions teams ask

SSO & access control, answered plainly

Which single sign-on protocols do you support?

SAML 2.0 and OpenID Connect, so Mobexa connects to the identity provider your organisation already runs. Access to the platform follows your existing joiner-mover-leaver process; when someone leaves your directory, they lose access here too.

How granular is access control?

Access is role-based. Different roles see different parts of the platform - who can run scans, who can triage findings, who can read evidence, who can change settings - so least privilege is the default rather than an afterthought. Sensitive surfaces are gated to administrators.

How do you keep one customer's data away from another's?

Tenant isolation is enforced on the server for every request, not just hidden in the interface. Findings, scans, reports and evidence are scoped to the owning organisation, and where one person is not entitled to another's data, the platform shows nothing rather than leaking an identity or a record.

Is access auditable?

Yes. Sensitive actions are recorded with the actor, the target and the time, so an administrator or auditor can reconstruct who did what. Access control without an audit trail is a promise; with one it is evidence.

Fit your identity stack

Bring your own identity provider and your own access policy.

Tell us how your organisation manages access and we will show you how Mobexa slots into it - SSO, roles and isolation included.