Security and access

How do users sign in, and how are seats provisioned?

In short

Single sign-on through your identity provider, multi-factor enforced by your provider, SCIM provisioning on Enterprise, and role-based access inside the product.

Last updated September 27, 2026

Sign-in. All users sign in through single sign-on with your identity provider (Okta, Microsoft Entra ID, Google Workspace and any SAML or OIDC provider). 20xwork stores no passwords. Multi-factor authentication is enforced by your provider's policy.

Provisioning. Enterprise customers can provision and deprovision seats automatically through SCIM. Removing a user in your directory removes their seat and starts the 30-day deletion of their data. Team customers manage seats in Organisation settings or by CSV.

Roles. Three roles inside the product: member (sees their own profile and cards), manager (sees their team's standing at the step level), admin (organisation settings, connections, exports, audit log). Roles can be mapped from directory groups.

Sessions. Sessions expire after 12 hours of inactivity and can be revoked by an admin at any time.

Have a questionnaire to fill in?

Send us your SIG, CAIQ or your own template and we will return it completed, with our penetration test summary and policies under NDA.

Email adharsh@20xwork.ai
Last updated September 27, 2026.The commitments on these pages are incorporated into our commercial agreements and Data Processing Addendum.