IAM Overview

Aevum Zenth operates a unified identity fabric across 400 subsidiaries. All users are provisioned through centralized SSO, enforced with mandatory MFA, and governed by least-privilege principles.

🔐

Single Sign-On

Enterprise SAML 2.0 & OIDC integration across all internal systems, cloud platforms, and legacy infrastructure.

🛡️

Zero Trust Access

Continuous verification, device posture checks, and contextual risk scoring for every authentication attempt.

📊

Audit & Compliance

Immutable access logs, quarterly access reviews, and automated certification workflows for all privileged roles.

Role Hierarchy Matrix

Standardized role definitions mapped to business functions, approval tiers, and system access scopes.

Active Role Definitions

Role Name Level Access Scope Approval Tier Status
👑 ExecutiveL4Full EnterpriseBoard / CEOActive
📊 Division DirectorL3Division + Cross-FunctionalVP / C-SuiteActive
📂 Department HeadL3Department + SubsidiaryDivision DirectorActive
⚙️ Operations ManagerL2Team + Operational SystemsDepartment HeadActive
🔍 Analyst / SpecialistL1Assigned Projects / Read-WriteManager ApprovalActive
💻 Engineering LeadL2DevOps / Prod + StagingCTO / VP EngActive
🛠️ Developer / EngineerL1Dev/Staging EnvironmentsEngineering LeadActive
🌐 External ContractorL0Restricted / Time-BoundIAM + LegalRestricted
🤖 Service AccountSystemAPI / Automation OnlyAuto-ProvisionedSystem

Permission Tiers

Granular access controls enforced across all Aevum Zenth platforms and data repositories.

Read
View-only access to dashboards, reports, and public documentation.
Write
Create and update records, submit requests, and modify assigned projects.
Edit
Modify configurations, approve workflows, and manage team-level settings.
Admin
Full system management, user provisioning, and policy enforcement within scope.
Super Admin
Global IAM control, audit override, and cross-divisional access governance.

Access Policies & Governance

Mandatory compliance standards enforced across all user accounts and service identities.

Password & MFA

16+ character complexity, 90-day rotation, and hardware/FIDO2 or TOTP MFA required for all L1+ roles.

Session Management

Idle timeout: 15 min. Concurrent sessions: 1 per user. Automatic re-auth for privileged actions.

Offboarding Protocol

Immediate access revocation upon HR sync trigger. 30-day archive retention for audit compliance.

Quick Actions & Support

Self-service tools and IAM team escalation paths for access requests and account management.