Skip to main content
Identity & Access

Account security is foundational to AI workforce management.

An AI workforce reaches your repositories, your production systems, and your credentials. The first control worth asking about is the oldest one, which is who your organization lets through the door and how hard that door is to force.

Account Security

Every account gets passkeys, session control, and audit records.

Passkeys and security keys

Hardware-backed sign-in where the account and provider support it, with authenticator apps available when a rollout policy calls for them.

Session visibility and revocation

Personal Settings lists the sessions on an account and ends any one of them, or every other one, without ending the session doing the review.

Security notifications

New logins, completed password resets, email changes, session revocations, recovery reviews, and account deletion each raise a notification.

Verified email and reset paths

Email verification, password reset, and signed-out access recovery are part of every account, and passkey-backed accounts keep their stronger posture instead of dropping to an email reset.

Auth audit records

Sign-in and account events are written as records an organization admin can review beside the rest of the security activity.

Roles that scope access

Organization roles and project access levels decide who administers security settings and who can see a given project at all.

Enterprise Identity

Your team signs in with the identity provider it already uses.

SSO with SAML or OIDC

Codespeed connects to the identity provider your organization already runs, so sign-in follows the policy your security team set there.

Verified-domain routing

Once your domain is verified and mapped to the organization, sign-in for that domain routes through your provider and can be enforced there.

Enterprise session policy

Organization access can carry session controls set for higher assurance rather than the defaults a single account would use.

Guided setup handoff

Configuration passes to your IT owner through a handoff that requires organization admin permission and a recent high-assurance sign-in. Codespeed records the handoff as organization activity and never stores, copies, or emails the setup link.

Step-Up Assurance

Sensitive changes ask for a stronger sign-in.

The check is another sign-in

Recent password reauthentication satisfies sensitive actions on an email and password account, and a recent passkey-backed sign-in satisfies the higher bar. Plain SSO clears it once your organization runs a verified enterprise identity policy.

A blocked change stays unapplied

When a session cannot complete the stronger step, the page keeps a visible Sign In Again action instead of a warning that leads nowhere. The change waits until the sign-in finishes and then returns to the page that asked for it.

Account Recovery

Account recovery takes two admins and a waiting period.

01

The request is made in the open

An account that has lost every strong sign-in method starts a recovery request rather than falling back to a weaker path. Codespeed provides no silent alternate login.

02

A second admin reviews it

Organization owners and admins review recovery requests for their organization, and a different owner or admin has to review the request before the manual identity action completes.

03

A waiting period runs

Assisted recovery can hold a waiting period and raise security notifications while it runs, so an account takeover attempt has to survive time and attention rather than a single decision.

04

The decision becomes a record

The review lands as an organization-visible security record without exposing factor secrets or recovery material.

Before Rollout

Three decisions to settle with your IT owner.

Who owns the member lifecycle

Provisioning and deprovisioning run through your identity provider and your own joiner and leaver process. Settle the removed-member path with Codespeed before the first rollout.

Which identity events your review needs

Identity and security records are reviewable in the app. Delivery into a SIEM is agreed as contracted scope, so name the events your security review depends on early.

How your organization recovers

Codespeed keeps no bypass route around your provider, so making SSO the only sign-in path calls for a recovery plan written for your organization.

Secure the accounts before you scale the workforce.