Skip to content

Security and data isolation

Organisations are isolated, and permissions apply to actions rather than sections. In the on-premise delivery the database, attachments and AI model stay inside your network.

Organisations are isolated

An organisation is a separate data space. Projects, cases, runs and members belong to it and are invisible outside it.

  • Data belongs to an organisation

    Every record belongs to its organisation. A request into another organisation fails the access check rather than merely hiding rows in the interface.

  • Several organisations per person

    An agency or contractor keeps clients apart and switches between them without mixing anything.

  • Entry by invitation only

    A member appears through an internal invitation or an invitation link issued by an organisation admin.

Roles and rights

60+ permissions per action, not per section. Preset roles can be extended with your own.

System roles
Administrator, Member and Viewer. Only Administrator and Member are paid; viewers and guests are free.
60+ permissions
View, create, edit and delete separately for cases, plans, runs, dashboards, environments, configurations, roles, import and export.
Custom roles
An organisation administrator builds a role for the team's process: for example, a reviewer who cannot delete cases. Available on Pro and On-Premise.
Access per project
Project membership is granted separately: working in one project does not open the neighbouring ones.

Sign-in, tokens and reports going out

Authentication is delegated to Keycloak, and anything that leaves the system is switched on by an explicit action.

  • SSO through Keycloak

    Sign-in runs on OAuth2 and OpenID Connect. In your perimeter Keycloak connects to your directory over LDAP or SSO.

  • API tokens

    Automation gets its own token. It is listed and can be revoked without touching the person's account.

  • Report by link

    A test run report can be opened by link without access to the system. Private or public is decided by the report author.

Where the data sits

Data is split between two places: a relational database and object storage. In your perimeter both of them are yours.

  • PostgreSQL

    Cases, runs, results and change history are stored in the relational database.

  • S3 or MinIO

    Attachments on run results, screenshots and logs sit in object storage, separate from the database.

  • Your own perimeter

    With an on-premise install the database, the storage and the AI model all stay inside your network.

Access log and change history

Who changed what can be reconstructed without contacting support.

Access log
Role creation and edits, permission changes, user activation and deactivation. Author, time, old value and new value are recorded.
Step revisions
Case steps are stored as revisions: a run points at the version of the steps it was executed against.
Case review
Field changes are visible line by line, together with comments and reviewer statuses.
Test data history
A test data record keeps an event history and shows which cases use it.

Let us go through your access model

We show how your roles and projects map onto the system and answer your security team's questions. If data must not leave the perimeter, we cover delivery into your infrastructure.

Start for free

Book a demo

30 minutes online with a CommIT expert: we walk you through the product and answer questions about your process

30 minutes online with a CommIT expert: we walk you through the product and answer questions about your process