Our engineers set up and run your first AI security scan. Get in touch

Access Control and Audit

The access and accountability layer a regulated programme needs: role-based access, optional 2FA, single sign-on, and an append-only audit log that records every action for the auditor.

Last reviewed September 2026

The gap access and audit control closes

Regulated buyers cannot adopt a tool that cannot answer who did what and when, or that cannot fit their identity and least-privilege requirements. Access control and an immutable trail are treated as table stakes here.

How Penaxtra governs AI access

Penaxtra enforces role-based access (owner, admin, editor, viewer), offers optional TOTP 2FA and magic-link sign-in, and records every auth and data event in an append-only audit log mirrored for tamper-evidence. Single sign-on is available per tenant as SAML 2.0 or OIDC, SP-initiated, with just-in-time provisioning. Every record is tenant-scoped under row-level security.

Access and audit capabilities

Role-based access: owner, admin, editor, viewer

Optional TOTP 2FA and magic-link sign-in (user opt-in)

SSO: per-tenant SAML 2.0 and OIDC, SP-initiated, with JIT provisioning

Append-only, tamper-evident audit log of every action

Tenant isolation enforced by row-level security

CSV export of the audit trail

Access and audit compliance mapping

Supports ISO/IEC 42001 access and accountability controls, EU AI Act Article 12 (record-keeping), and NIST AI 600-1 GOVERN actions.