For enterprise
Access control that fails closed, not open.
Permission-based RBAC, TOTP MFA, and audit logging of admin actions — built so a misconfiguration denies access by default instead of quietly granting it.
Security posture as the pitch, not the afterthought
Enterprise buyers ask harder questions: what happens when a permission is misconfigured, who can see what an admin changed, and whether a session can be revoked the moment someone leaves. Oidot is built to answer all three by default.
Role-based access control is permission-based rather than a fixed list of role names, and it fails closed: an unrecognized or missing permission denies access — it doesn't silently allow it.
Features
Fail-closed RBAC
Permission-based roles rather than hardcoded role names — a missing permission denies access by default.
Multi-factor authentication
TOTP-based MFA, recovery codes, and step-up re-authentication for sensitive actions.
Audit logging
Admin actions are logged, so access changes are reviewable after the fact, not just at the time they happen.
Session management
See and revoke active sessions and devices individually or all at once — useful the moment someone leaves.
Talk through your requirements
We're happy to walk through the security model in detail before you commit to anything.