Account and billing

Security controls

Sign-in options including SAML SSO and two-factor authentication, audit logging, support access, PII redaction and the controls that govern Agent spending.

This page covers the controls an administrator sets. The published detail of how Collabre runs, including subprocessors and data handling, is on the security page.

How people sign in

Collabre supports password sign-in, Google sign-in, magic links sent by email, and SAML single sign-on for organizations with an identity provider.

With SAML configured, you can force single sign-on so that password sign-in is no longer accepted for your Workspace, which puts account lifecycle back where your identity team already manages it.

Two-factor authentication

Two-factor authentication uses a time-based code from an authenticator app, with backup codes issued at setup for the day a phone is lost. An administrator can require it across the Workspace rather than leaving it to each person.

Login activity

The login activity log records the method used, the location it came from, and the failures. Read it when someone reports an account they do not recognize, or as part of a periodic review.

Audit logging

There are two records, and they answer different questions.

Per entity change history sits on the record itself and shows what changed, with the values before and after. The Workspace audit log is searchable across everything that happened, which is the one to export when a reviewer asks for evidence.

Agent actions are written to the audit log alongside human ones, with the reasoning the Agent recorded at the time.

Support access

Collabre support cannot enter your Workspace unless an Owner grants access. That access is time boxed, read only, and fully recorded. While it is active, a banner shows for the whole session, so nobody is ever inside your Workspace invisibly.

Personal data in AI work

PII redaction is on by default. Personal data is scrubbed from logs and from the inputs Agents receive, so a prompt or a trace does not become an unmanaged copy of customer data.

Agent memory is scoped, retained for a set period, and opt-in at the Workspace scope. There is deliberately no memory shared between Workspaces.

Controlling what Agents may do

The same governance controls that keep AI work predictable are security controls:

  • Spending caps per Agent run, per Agent per day, and per Workspace per month.
  • Kill switches that halt one Agent or all of them immediately.
  • Tool approval rules that allow, deny or require human confirmation, with confirmation as the default.
  • A destructive action registry classifying actions as automatic, human in the loop, or denied.
  • Domain allow lists for any tool that calls outward.
  • Role based control over who may edit an Agent's prompt, tools or caps.

The governance dashboard gathers permissions, spend, tool rules and destructive actions in one screen. See The AI workforce.

White-label and custom domains

Workspaces can run under a custom domain with their own CSS, a branded sign-in page and branded report headers, which matters for agencies handing reports to clients.

Reviewing security before you buy

For a security review, a completed questionnaire, or the data processing agreement, start at the security page and the data processing agreement, then write to us with what your team still needs.

Last updated . Questions this page does not answer go to /contact.

See it on your campaigns

Collabre is in private beta. Request a demo and we will walk through your workflow with you.