Users & Roles Management
Centralized identity governance, access provisioning, and role-based access control (RBAC) for all Aevum Zenth divisions and subsidiaries.
IAM Overview
Aevum Zenth operates a unified identity fabric across 400 subsidiaries. All users are provisioned through centralized SSO, enforced with mandatory MFA, and governed by least-privilege principles.
Single Sign-On
Enterprise SAML 2.0 & OIDC integration across all internal systems, cloud platforms, and legacy infrastructure.
Zero Trust Access
Continuous verification, device posture checks, and contextual risk scoring for every authentication attempt.
Audit & Compliance
Immutable access logs, quarterly access reviews, and automated certification workflows for all privileged roles.
Role Hierarchy Matrix
Standardized role definitions mapped to business functions, approval tiers, and system access scopes.
Active Role Definitions
| Role Name | Level | Access Scope | Approval Tier | Status |
|---|---|---|---|---|
| 👑 Executive | L4 | Full Enterprise | Board / CEO | Active |
| 📊 Division Director | L3 | Division + Cross-Functional | VP / C-Suite | Active |
| 📂 Department Head | L3 | Department + Subsidiary | Division Director | Active |
| ⚙️ Operations Manager | L2 | Team + Operational Systems | Department Head | Active |
| 🔍 Analyst / Specialist | L1 | Assigned Projects / Read-Write | Manager Approval | Active |
| 💻 Engineering Lead | L2 | DevOps / Prod + Staging | CTO / VP Eng | Active |
| 🛠️ Developer / Engineer | L1 | Dev/Staging Environments | Engineering Lead | Active |
| 🌐 External Contractor | L0 | Restricted / Time-Bound | IAM + Legal | Restricted |
| 🤖 Service Account | System | API / Automation Only | Auto-Provisioned | System |
Permission Tiers
Granular access controls enforced across all Aevum Zenth platforms and data repositories.
Access Policies & Governance
Mandatory compliance standards enforced across all user accounts and service identities.
Password & MFA
16+ character complexity, 90-day rotation, and hardware/FIDO2 or TOTP MFA required for all L1+ roles.
Session Management
Idle timeout: 15 min. Concurrent sessions: 1 per user. Automatic re-auth for privileged actions.
Offboarding Protocol
Immediate access revocation upon HR sync trigger. 30-day archive retention for audit compliance.
Quick Actions & Support
Self-service tools and IAM team escalation paths for access requests and account management.