Profiles, permissions, SSO, entities, billing and organisation settings — everything an administrator needs to know.
iComply manages sensitive compliance data, so the access model is deliberately granular. This page covers the configuration that an administrator sets up once and reviews periodically.
Five profiles cover the vast majority of cases. Always apply the principle of least privilege: start with the most restrictive profile and move up if necessary.
A profile determines the ‘what’; the scope determines the ‘where’. Each user may be restricted by:
This arrangement makes it possible, for example, to assign an external consultant the role of Security Domain Manager within a single organisation for a period of three months.
In Administração → Utilizadores, send an invitation by email. The invitation expires if it is not used. When an employee leaves, deactivate their account rather than deleting it: deactivation blocks access but preserves the activity log, which serves as audit evidence. Permanent deletion should only be used in response to a request for erasure under the GDPR.
In Administração → Autenticação, you can:
On Enterprise plans, you can connect your identity provider via SAML 2.0 or OIDC, and automatically provision users via SCIM. With SCIM enabled, user join and leave events within the organisation are automatically reflected on the platform without the need for manual intervention — which in itself resolves one of the most common non-compliances identified in access audits.
Typical configuration: map the directory groups to the iComply profiles, and define one group per governance domain.
In Administração → Entidades, the group is modelled as follows: legal entities, countries and units. This determines:
All relevant actions are recorded in an immutable log: who, what, when and from where. This includes authentication, changes to controls, the uploading and replacement of evidence, changes to permissions and data exports.
This log is evidence in itself — it fulfils the logging and monitoring requirements of ISO 27001 and the equivalent requirements of NIS2 and DORA. It can be exported in Administração → Registos.
In Administração → Notificações, configure what is sent and to whom: assigned tasks, records due to expire, controls under review, new findings, CAPA with an imminent deadline, and periodic summaries for senior management. A common mistake is to notify everyone of everything — the result is that nobody reads it. Start by keeping it limited.
Under Administração → Subscrição, you can view the active plan, the domains included, the users currently using the service, and the add-ons you have subscribed to. You can:
Changes are prorated over the current billing cycle. See Pricing for details of plans and add-ons.
Schedule a review of access to the platform itself — quarterly is a good frequency. Check that:
This review is, in itself, an audit that you can record in iComply — with the audit report generated by the platform serving as the supporting evidence.
We set up SSO, SCIM and the group structure with your IT team.
Utilizamos cookies para melhorar a sua experiência no nosso site. Ao utilizar o nosso site, está a consentir a utilização de cookies.
Defina as suas preferências relativas aos cookies abaixo:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are needed for adding comments on this website.
Pode encontrar mais informações na nossa Política de Cookies e na nossa Privacy Policy.