These controls are in the product today. Enterprise plans add negotiated channel counts and AI credits.
Sign-in
Single sign-on with Microsoft Entra ID
Verify your email domain, and new users from your tenant join with the role and accounts you choose.
Sign-in
Two-step verification, always on
Every password sign-in needs a second step: an authenticator app with recovery codes, or an emailed code. Users can trust a device for 30 days, and sessions end after 12 hours.
Access
Roles scoped to accounts
Owners and admins run the workspace. Members see only the accounts they're given, and AMC, cost edits and listing changes each need their own permission.
Integrations
Expiring credentials, OAuth for AI clients
API keys are stored only as a hash, read-only by default, and expire after a year. MCP clients connect with OAuth 2.1, so no one pastes a key into a chat tool.
Data
S3 or Snowflake push, on request
We push your 1stPage data into your own S3 bucket or Snowflake account on a schedule you pick. Ask us when you set up your workspace.
Logging
Security events kept at least a year
Sign-ins, failed sign-ins, role changes, SSO changes and API key changes are logged with IP address and kept for at least 12 months.