[Home](/en-us)›[Product](/en-us/product)›Security & Access Control

Extend & govern

# Security & Access Control

Enterprise-grade security built in from the start: authentication, authorization, 2FA, SSO, and a full audit trail.

[Start Free](https://portal.otms.transportial.com/auth/register)[Request a Demo](/en-us/contact)

JWTTOTPRBACSAML 2.0Argon2Rate limitingSentry

550+

Named permissions

TOTP

2FA built-in

SAML

2.0 SSO

Argon2

Password hashing

Integration · Authentication

![Integration configuration showing an authentication section with basic auth, username and password fields, add attribute and add header buttons](/assets/screens/integration-preset-config.webp)

Credentials are stored per integration, redacted in logs and never echoed back.
1. Authentication method per connection
2. Custom headers and attributes
3. On/off switch without deleting configuration

Security is not an afterthought at Transportial. JWT-based authentication with short-lived tokens, two-factor authentication, 550+ named permissions, SAML 2.0 SSO, Argon2 password hashing, and per-API-key rate limiting are all standard, not add-ons.

## What it does

A code-level inventory of what Security & Access Control covers, in the terms you will find inside the product.

### Authentication

* Sessions and tokens  
JWT sessions, login-attempt tracking, and login levels from not logged in through needs two-factor to full access.
* Two-factor  
TOTP with QR enrollment and recovery codes, managed under the user's security settings with active-session control.
* SAML 2.0 single sign-on  
Per platform, with SP and IdP metadata, downloadable SP metadata and an exchange log.
* Domains and access  
Allowed e-mail domains per platform, access requests approved by an admin, and account types default, customer, supplier, planning and financial.

### Authorization

* Roles and levels  
Roles with a numeric level (300 planner, 800 admin, above 1000 super admin) and a list of permissions.
* Hundreds of permissions  
Roughly 556 verb-resource permissions such as create transport order, approve invoice, confirm trip or convert tachograph, each with read, write and delete and a scope of public, private or owner.
* Property level  
Fields can carry their own permission, and platforms hide fields per entity type.
* Teams  
Team-scoped visibility, for instance invoices only for the user's team, and order auto-assignment to teams.

### Integration and API security

* Keys and tokens  
API integrations, app tokens and user sessions are distinct auth types; API keys per consumer; 500 requests per minute.
* Secrets  
Credentials per integration with redaction in request logs, retention limits, and logging modes all, errors or off.
* Public surfaces  
Share links with per-link tokens and visibility toggles; widgets with hostname and IP allow-lists; tenant-checked socket subscriptions.
* Webhooks  
Signed inbound webhooks for payment providers and partners.

### Auditability

* Revision history  
Every entity is audited with previous values, user and timestamp.
* Activity logs  
Financial documents log sent, reminded, approved, paid and integration events; integrations log tasks and requests.
* Notifications  
A password-changed security notice is part of the automation catalog.

## How it works

1. ### Define roles  
Create roles with a level and the permissions each needs; assign fields their own permissions where necessary.
2. ### Enforce sign-in policy  
Require two-factor, connect SAML for enterprise users, restrict e-mail domains.
3. ### Scope external access  
Customers get portal accounts; partners get API keys or app tokens; public pages get tokens and allow-lists.
4. ### Audit  
Use revision history and activity logs when something needs explaining.

Widgets · Allowed hostnames

![Widget form with an allowed hostname field](/assets/screens/widget-embed.webp)

Public surfaces are allow-listed by hostname and IP.

## Permissions that match how a transportation company works

A planner confirms trips but does not approve invoices; a finance user sees invoices but not driving hours; a customer sees their own orders and nothing else. Transportial expresses this with a large, verb-based permission set on top of role levels, scopes of public, private or owner, and team boundaries, so access mirrors the organization instead of forcing everyone into admin.

## Concepts & terminology

The words this module uses, with links to the full glossary where a term has its own page.

[Open the glossary](/en-us/glossary)

Role level

A numeric rank on a role; above 1000 is super admin.

Permission

A verb-resource pair with read, write and delete flags and a scope of public, private or owner.

TOTP

Time-based one-time passwords for two-factor authentication, enrolled by QR code with recovery codes.

SAML 2.0

The single-sign-on standard supported per platform with SP and IdP metadata.

Share token

The per-link secret that protects a public order, trip, quote or invoice page.

## Works with

Connectors that feed or consume this module out of the box.

[Microsoft 365](/en-us/integration/microsoft-365)[All integrations →](/en-us/integration)

## Built for

Where this module carries the most weight, plus the free tools on the same topic.

[logistics-service-providers](/en-us/solutions/logistics-service-providers)[shippers](/en-us/solutions/shippers)

Technical details

JWT sessions with login levels, TOTP two-factor and SAML 2.0 single sign-on per platform. Every route declares its verb-resource permission, properties can carry their own permission, and tenant scoping is enforced in the API and the live push channel.

## Frequently asked questions

### Is two-factor authentication available?

Yes. TOTP with QR enrollment and recovery codes, managed in the user's security settings.

### Which identity providers work for SSO?

Any SAML 2.0 identity provider, configured per platform with SP and IdP metadata.

### How fine-grained are permissions?

About 556 verb-resource permissions with read, write and delete and scopes public, private or owner, on top of role levels, team scoping and field-level permissions.

### Are integration credentials protected?

Yes. Credentials are stored per integration, redacted in request logs and subject to retention limits.

### Is there an audit trail?

Yes. Every entity has revision history, and financial documents and integrations have activity and request logs.

## Related features

[View all features](/en-us/product)

[Multi-Tenancy & White-LabelRun your own branded logistics platform, fully isolated, fully customizable, on your own domain.](/en-us/product/white-label)[Integration FrameworkConnect Transportial to any external system (ERPs, telematics, ordering platforms, and more) with a full REST API and App Store.](/en-us/product/integration-framework)[Reporting & InsightsTurn operational data into decisions with configurable dashboards, TQL-powered queries, and a complete audit trail.](/en-us/product/reporting)

View all features

[Transport Order Management](/en-us/product/transport-orders)[Interactive Plan Board](/en-us/product/plan-board)[AI-Powered Trip Optimization](/en-us/product/trip-optimisation)[Fleet & Resource Management](/en-us/product/fleet-management)[3D Load Planning](/en-us/product/load-planning)[OpenMove Driver App](/en-us/product/driver-app)[Real-Time Vehicle Tracking](/en-us/product/vehicle-tracking)[Multi-Modal Routing](/en-us/product/routing)[Pricing Engine](/en-us/product/pricing-engine)[Invoicing & Financial Management](/en-us/product/invoicing)[Message Automations](/en-us/product/message-automations)[Document Management & Generation](/en-us/product/documents)[Integrated Email Inbox](/en-us/product/email-inbox)[In-App Chat](/en-us/product/chat)[Customer & Business Portal](/en-us/product/customer-portal)[Integration Framework](/en-us/product/integration-framework)[Reporting & Insights](/en-us/product/reporting)[Multi-Tenancy & White-Label](/en-us/product/white-label)[Security & Access Control](/en-us/product/security)

## Ready to put this to work?

Start free with full platform access, or talk to our team about your specific operation.

[Start Free](https://portal.otms.transportial.com/auth/register)[Book a Demo](/en-us/contact)

---
Canonical page: https://transportial.com/en-us/product/security
