User Management & Identity Governance
Identity governance in Colrows comes down to one thing: every person and agent runs under an identity whose access is enforced deterministically, at compile time. Bring your enterprise identity provider for sign-in; inside Colrows, users belong to groups and are assigned a persona whose access and redaction policies shape every query before a single row is read.
| Capability | Standard SaaS User Management | Colrows Enterprise Identity |
|---|---|---|
| Authentication | Basic. Password-based or simple OAuth. | SAML 2.0 and OIDC single sign-on, plus native email/password. |
| Access model | Manual. Static roles assigned per user. | Personas and user groups drive compile-time RBAC and ABAC access and redaction policies. |
| Governance | Reactive. Enforced after data access. | Compile-time. Authorized before SQL executes. |
| Auditability | Limited. Basic access logs. | Full. Verifiable traceability with per-request audit trail. |
Why identity is upstream of governance
In most stacks, identity and data access live in separate silos: a user exists in your IdP, their tool identity exists somewhere else, and a role change only takes effect at the next manual sync. Colrows closes that gap by making identity the thing that governs. A user authenticates, runs under an assigned persona, and that persona's access and redaction policies are compiled into every query - so authorization happens before a single row is read, not after.
Identity is the first perimeter of your data strategy. Secure it. Govern it. Determinize it. Fix the Context, Not the Model.
Identity model
- User - a principal who signs in through your IdP or with native credentials. Belongs to zero or more user groups and is assigned a persona. Each user carries a role: Developer, Curator, or Admin.
- User group - a collection of users you manage in Colrows. Access and redaction policies bind to individual users and to groups.
- Persona - a named identity that carries scope and policy context. An administrator assigns a persona to a user; queries, agents, and monitors run under it, which is what keeps scheduled and automated work reproducible.
- Session - an authenticated context that carries the resolved persona, audit identifiers, and a request-scoped trace.
Authentication options
Native email & password
Sign in with an email and password managed in Colrows. Passwords can be reset, and an administrator can deactivate a user to revoke access immediately. Native accounts suit evaluation and break-glass administrators; bring your identity provider for everyday production access.
SAML 2.0 single sign-on
Colrows acts as the SAML Service Provider. Configure your IdP's sign-on URL and signing certificate in organization settings; Colrows publishes its SP metadata and validates the assertion at its ACS endpoint. Just-in-time provisioning is supported - a user signing in for the first time is created automatically. A configurable group claim carries the user's IdP groups into the session.
| Purpose | Endpoint |
|---|---|
| Start SAML sign-in | POST /api/user/login/saml |
| Service-provider metadata | GET /api/user/login/saml/metadata |
| Assertion consumer (ACS) | POST /api/user/login/saml/response |
OIDC
Colrows also authenticates users against an OIDC identity provider, reading a configurable group claim so group membership travels with the sign-in. Works with mainstream providers such as Okta, Microsoft Entra ID (Azure AD), Google Workspace, Auth0, and Keycloak.
Managing users, groups & personas
Administrators manage users, user groups, and persona assignments from Administration and on the platform API. Personas and groups are how identity connects to governance: policies bind to users and groups, and every request compiles under the requester's persona.
| Operation | Endpoint |
|---|---|
| List / get users | GET /api/user/list · GET /api/user/get/{userId} |
| Create a user (admin) | POST /api/user/create |
| Assign a persona | PUT /api/user/update/persona/{personaId} |
| Deactivate a user (admin) | DELETE /api/user/deactivate/{userId} |
| List / create / update groups | GET /api/usergroup/list · POST /api/usergroup/create · PUT /api/usergroup/update |
| Deactivate a group (admin) | DELETE /api/usergroup/deactivate/{groupId} |
To see how a persona's grants become row- and column-level control, read Data Access Control and Redaction Policies. For the full architectural picture, see SaaS Architecture.
Session & audit
- Every session is bound to the resolved persona; a persona change takes effect on the next session. Sessions can be refreshed with
POST /api/user/token/refresh. - Session lifetime is a configurable timeout, applied org-wide (default 2 hours).
- Every API call is recorded server-side - request URL, HTTP method, response code, organization, user, and timestamp. See Audit & Traces for what is captured and how to retrieve it.
Use SAML or OIDC single sign-on for production, and reserve native accounts for break-glass administrators. Keep personas focused so a user's effective access stays easy to reason about.
Ready to integrate Colrows with your enterprise identity stack?
Book a technical architecture review