Access Control and Audit
The access and accountability layer a regulated programme needs: role-based access, optional 2FA, single sign-on, and an append-only audit log that records every action for the auditor.
Last reviewed September 2026
The gap access and audit control closes
Regulated buyers cannot adopt a tool that cannot answer who did what and when, or that cannot fit their identity and least-privilege requirements. Access control and an immutable trail are treated as table stakes here.
How Penaxtra governs AI access
Penaxtra enforces role-based access (owner, admin, editor, viewer), offers optional TOTP 2FA and magic-link sign-in, and records every auth and data event in an append-only audit log mirrored for tamper-evidence. Single sign-on is available per tenant as SAML 2.0 or OIDC, SP-initiated, with just-in-time provisioning. Every record is tenant-scoped under row-level security.
Access and audit capabilities
Optional TOTP 2FA and magic-link sign-in (user opt-in)
SSO: per-tenant SAML 2.0 and OIDC, SP-initiated, with JIT provisioning
Append-only, tamper-evident audit log of every action
Tenant isolation enforced by row-level security
CSV export of the audit trail
Access and audit compliance mapping
Supports ISO/IEC 42001 access and accountability controls, EU AI Act Article 12 (record-keeping), and NIST AI 600-1 GOVERN actions.