Sign-in. All users sign in through single sign-on with your identity provider (Okta, Microsoft Entra ID, Google Workspace and any SAML or OIDC provider). 20xwork stores no passwords. Multi-factor authentication is enforced by your provider's policy.
Provisioning. Enterprise customers can provision and deprovision seats automatically through SCIM. Removing a user in your directory removes their seat and starts the 30-day deletion of their data. Team customers manage seats in Organisation settings or by CSV.
Roles. Three roles inside the product: member (sees their own profile and cards), manager (sees their team's standing at the step level), admin (organisation settings, connections, exports, audit log). Roles can be mapped from directory groups.
Sessions. Sessions expire after 12 hours of inactivity and can be revoked by an admin at any time.