← Back to V20
05 — Control

Enterprise-grade governance and trust

SSO, SCIM, audit logs, 9-role RBAC, customer-managed keys, data residency, AI evaluation dashboards, and a nonprofit tier that stays free.

9 roles, org + workspace

Owner, admin, billing, researcher, enumerator, analyst, respondent-manager, auditor, viewer. Least-privilege by default.
  • Org-level + workspace-level scopes
  • Role matrix exportable for audit
  • Session + MFA policies per role
  • Service accounts with rotating keys

Credit pools across country offices

Central budget, delegated spend. Each country office draws from a shared pool with caps, alerts, and monthly true-up.
  • Central pool + per-office cap
  • Alerts at 50 / 80 / 95%
  • Roll-over policy configurable
  • Nonprofit tier · 200 free credits / month

Security + compliance

SOC 2 Type II in progress, EU AI Act conformity, GDPR + HIPAA options, customer-managed keys on enterprise tier.
  • SSO (SAML + OIDC) + SCIM provisioning
  • Audit log streaming to SIEM
  • Data residency: EU, US, ME
  • BYOK via customer Key Vault

AI evaluation dashboard

Every AI call is logged, sampled, and scored. Drift alerts, cost per workspace, and human-rating queues.
  • Gold-set scoring nightly
  • Cost per org / workspace / feature
  • Rater queues + calibration
  • Exportable eval reports