Security and data isolation
Organisations are isolated, and permissions apply to actions rather than sections. In the on-premise delivery the database, attachments and AI model stay inside your network.
Organisations are isolated
An organisation is a separate data space. Projects, cases, runs and members belong to it and are invisible outside it.
Data belongs to an organisation
Every record belongs to its organisation. A request into another organisation fails the access check rather than merely hiding rows in the interface.
Several organisations per person
An agency or contractor keeps clients apart and switches between them without mixing anything.
Entry by invitation only
A member appears through an internal invitation or an invitation link issued by an organisation admin.
Roles and rights
60+ permissions per action, not per section. Preset roles can be extended with your own.
- System roles
- Administrator, Member and Viewer. Only Administrator and Member are paid; viewers and guests are free.
- 60+ permissions
- View, create, edit and delete separately for cases, plans, runs, dashboards, environments, configurations, roles, import and export.
- Custom roles
- An organisation administrator builds a role for the team's process: for example, a reviewer who cannot delete cases. Available on Pro and On-Premise.
- Access per project
- Project membership is granted separately: working in one project does not open the neighbouring ones.
Sign-in, tokens and reports going out
Authentication is delegated to Keycloak, and anything that leaves the system is switched on by an explicit action.
SSO through Keycloak
Sign-in runs on OAuth2 and OpenID Connect. In your perimeter Keycloak connects to your directory over LDAP or SSO.
API tokens
Automation gets its own token. It is listed and can be revoked without touching the person's account.
Report by link
A test run report can be opened by link without access to the system. Private or public is decided by the report author.
Where the data sits
Data is split between two places: a relational database and object storage. In your perimeter both of them are yours.
PostgreSQL
Cases, runs, results and change history are stored in the relational database.
S3 or MinIO
Attachments on run results, screenshots and logs sit in object storage, separate from the database.
Your own perimeter
With an on-premise install the database, the storage and the AI model all stay inside your network.
Access log and change history
Who changed what can be reconstructed without contacting support.
- Access log
- Role creation and edits, permission changes, user activation and deactivation. Author, time, old value and new value are recorded.
- Step revisions
- Case steps are stored as revisions: a run points at the version of the steps it was executed against.
- Case review
- Field changes are visible line by line, together with comments and reviewer statuses.
- Test data history
- A test data record keeps an event history and shows which cases use it.
Let us go through your access model
We show how your roles and projects map onto the system and answer your security team's questions. If data must not leave the perimeter, we cover delivery into your infrastructure.
30 minutes online with a CommIT expert: we walk you through the product and answer questions about your process