Administration & access

Profiles, permissions, SSO, entities, billing and organisation settings — everything an administrator needs to know.

iComply manages sensitive compliance data, so the access model is deliberately granular. This page covers the configuration that an administrator sets up once and reviews periodically.

User profiles

Five profiles cover the vast majority of cases. Always apply the principle of least privilege: start with the most restrictive profile and move up if necessary.

  • Administrator — organisation settings, users, entities, authentication, billing and all domains. Keep the number to a minimum (ideally two, so you don’t lose access).
  • Domain Manager — full control over assigned domains: controls, risks, evidence, audits and reports. No access to billing or users.
  • Contributor — carries out assigned tasks and maintains records for the controls for which they are responsible. They do not alter the control framework.
  • Auditor — reviewing controls, evidence, findings and reports within the defined scope. They may record findings if the audit is assigned to them.
  • Reading — for reference only, typically for management or stakeholders.

Âmbito de acesso

A profile determines the ‘what’; the scope determines the ‘where’. Each user may be restricted by:

  • Domain — e.g. Privacy and Ethics only.
  • Legal entity — e.g. only the Portuguese subsidiary.
  • Organisational unit — e.g. IT only.
  • Validity period — access with an expiry date, useful for consultants and external auditors.

This arrangement makes it possible, for example, to assign an external consultant the role of Security Domain Manager within a single organisation for a period of three months.

Invite and deactivate users

In Administração → Utilizadores, send an invitation by email. The invitation expires if it is not used. When an employee leaves, deactivate their account rather than deleting it: deactivation blocks access but preserves the activity log, which serves as audit evidence. Permanent deletion should only be used in response to a request for erasure under the GDPR.

Authentication and MFA

In Administração → Autenticação, you can:

  • Enforce MFA for all users or only for privileged accounts. We recommend it for everyone.
  • Set session policy — duration and time-out on inactivity.
  • Restrict by IP — list of authorised ranges, on plans that support this feature.

SSO & SCIM

On Enterprise plans, you can connect your identity provider via SAML 2.0 or OIDC, and automatically provision users via SCIM. With SCIM enabled, user join and leave events within the organisation are automatically reflected on the platform without the need for manual intervention — which in itself resolves one of the most common non-compliances identified in access audits.

Typical configuration: map the directory groups to the iComply profiles, and define one group per governance domain.

Organisations and structure

In Administração → Entidades, the group is modelled as follows: legal entities, countries and units. This determines:

  • How the scope of domains is applied.
  • Whether the reports are consolidated or by entity.
  • What regulatory obligations apply to each party (NIS2, CSRD and Pay Transparency thresholds vary by size and sector)?

Platform audit logs

All relevant actions are recorded in an immutable log: who, what, when and from where. This includes authentication, changes to controls, the uploading and replacement of evidence, changes to permissions and data exports.

This log is evidence in itself — it fulfils the logging and monitoring requirements of ISO 27001 and the equivalent requirements of NIS2 and DORA. It can be exported in Administração → Registos.

Notifications

In Administração → Notificações, configure what is sent and to whom: assigned tasks, records due to expire, controls under review, new findings, CAPA with an imminent deadline, and periodic summaries for senior management. A common mistake is to notify everyone of everything — the result is that nobody reads it. Start by keeping it limited.

Billing and subscription

Under Administração → Subscrição, you can view the active plan, the domains included, the users currently using the service, and the add-ons you have subscribed to. You can:

  • Add domains or users via self-service, with immediate effect.
  • Switch between monthly and annual billing.
  • View and download invoices.
  • Set the billing details and financial contact details.

Changes are prorated over the current billing cycle. See Pricing for details of plans and add-ons.

Data, export and retention

  • Hosting — data is hosted within the EU. For Enterprise plans, a specific region can be specified.
  • Export — you can export controls, records, risks and reports at any time; the data belongs to you.
  • Retention — set retention policies in line with your legal obligations.
  • Backups — daily, with retention and tested recovery. See the Trust Center.

Regular review of access points

Schedule a review of access to the platform itself — quarterly is a good frequency. Check that:

  • There are no active users who have left the organisation.
  • No temporary access has extended beyond the scheduled date.
  • The number of directors remains very low.
  • The profiles correspond to current roles, not previous ones.

This review is, in itself, an audit that you can record in iComply — with the audit report generated by the platform serving as the supporting evidence.

On this page

Do you need SSO or multi-organisation support?

We set up SSO, SCIM and the group structure with your IT team.