User Management & Identity Governance

Identity governance in Colrows comes down to one thing: every person and agent runs under an identity whose access is enforced deterministically, at compile time. Bring your enterprise identity provider for sign-in; inside Colrows, users belong to groups and are assigned a persona whose access and redaction policies shape every query before a single row is read.

Capability Standard SaaS User Management Colrows Enterprise Identity
Authentication Basic. Password-based or simple OAuth. SAML 2.0 and OIDC single sign-on, plus native email/password.
Access model Manual. Static roles assigned per user. Personas and user groups drive compile-time RBAC and ABAC access and redaction policies.
Governance Reactive. Enforced after data access. Compile-time. Authorized before SQL executes.
Auditability Limited. Basic access logs. Full. Verifiable traceability with per-request audit trail.

Why identity is upstream of governance

In most stacks, identity and data access live in separate silos: a user exists in your IdP, their tool identity exists somewhere else, and a role change only takes effect at the next manual sync. Colrows closes that gap by making identity the thing that governs. A user authenticates, runs under an assigned persona, and that persona's access and redaction policies are compiled into every query - so authorization happens before a single row is read, not after.

Identity is the first perimeter of your data strategy. Secure it. Govern it. Determinize it. Fix the Context, Not the Model.

Identity model

  • User - a principal who signs in through your IdP or with native credentials. Belongs to zero or more user groups and is assigned a persona. Each user carries a role: Developer, Curator, or Admin.
  • User group - a collection of users you manage in Colrows. Access and redaction policies bind to individual users and to groups.
  • Persona - a named identity that carries scope and policy context. An administrator assigns a persona to a user; queries, agents, and monitors run under it, which is what keeps scheduled and automated work reproducible.
  • Session - an authenticated context that carries the resolved persona, audit identifiers, and a request-scoped trace.

Authentication options

Native email & password

Sign in with an email and password managed in Colrows. Passwords can be reset, and an administrator can deactivate a user to revoke access immediately. Native accounts suit evaluation and break-glass administrators; bring your identity provider for everyday production access.

SAML 2.0 single sign-on

Colrows acts as the SAML Service Provider. Configure your IdP's sign-on URL and signing certificate in organization settings; Colrows publishes its SP metadata and validates the assertion at its ACS endpoint. Just-in-time provisioning is supported - a user signing in for the first time is created automatically. A configurable group claim carries the user's IdP groups into the session.

PurposeEndpoint
Start SAML sign-inPOST /api/user/login/saml
Service-provider metadataGET /api/user/login/saml/metadata
Assertion consumer (ACS)POST /api/user/login/saml/response

OIDC

Colrows also authenticates users against an OIDC identity provider, reading a configurable group claim so group membership travels with the sign-in. Works with mainstream providers such as Okta, Microsoft Entra ID (Azure AD), Google Workspace, Auth0, and Keycloak.

Managing users, groups & personas

Administrators manage users, user groups, and persona assignments from Administration and on the platform API. Personas and groups are how identity connects to governance: policies bind to users and groups, and every request compiles under the requester's persona.

OperationEndpoint
List / get usersGET /api/user/list · GET /api/user/get/{userId}
Create a user (admin)POST /api/user/create
Assign a personaPUT /api/user/update/persona/{personaId}
Deactivate a user (admin)DELETE /api/user/deactivate/{userId}
List / create / update groupsGET /api/usergroup/list · POST /api/usergroup/create · PUT /api/usergroup/update
Deactivate a group (admin)DELETE /api/usergroup/deactivate/{groupId}

To see how a persona's grants become row- and column-level control, read Data Access Control and Redaction Policies. For the full architectural picture, see SaaS Architecture.

Session & audit

  • Every session is bound to the resolved persona; a persona change takes effect on the next session. Sessions can be refreshed with POST /api/user/token/refresh.
  • Session lifetime is a configurable timeout, applied org-wide (default 2 hours).
  • Every API call is recorded server-side - request URL, HTTP method, response code, organization, user, and timestamp. See Audit & Traces for what is captured and how to retrieve it.
Best practice.

Use SAML or OIDC single sign-on for production, and reserve native accounts for break-glass administrators. Keep personas focused so a user's effective access stays easy to reason about.

Ready to integrate Colrows with your enterprise identity stack?

Book a technical architecture review