Security & Access Control

Security and access control for internal project steering

Evoltir PM Cockpit is designed for controlled internal use inside industrial companies and PMOs. EU-hosted, role-based, GDPR-oriented, and built around an enterprise SSO roadmap.

01 / Access Model

Internal company access model

Evoltir PM Cockpit is built for internal project steering. Users belong to controlled workspaces with role-based access and clear ownership.

Access can be structured around PMO leaders, project owners, project members, department leads, finance users, and management viewers, so the right people see the right information without exposing sensitive project, cost, or supplier data more broadly than needed.

Workspace isolation
Role-based permissions
Owner / Editor / Viewer
MFA enabled
02 / Identity & SSO

Identity and SSO direction

Enterprise customers expect project steering systems to work with their identity provider. Evoltir PM Cockpit is designed to support Microsoft Entra ID / SAML SSO for internal company users, with strict SSO enforcement and controlled emergency access.

Roadmap

Microsoft Entra ID SAML SSO

Enterprise customers can authenticate through their corporate identity provider with full SSO enforcement.

Roadmap

JIT provisioning

Just-in-time user provisioning on first SSO login, mapped to the right workspace and role.

Roadmap

Strict SSO enforcement

Once configured, SSO becomes the only login path for the workspace. Direct password login is disabled.

Roadmap

Break-glass owner account

Controlled emergency access for the workspace owner, separate from SSO, for incident recovery.

Roadmap

SCIM provisioning

Automated user lifecycle management from the identity provider, onboarding, role changes, offboarding.

Today

Workspace-level access control

Each company / PMO operates in its own isolated workspace. No cross-workspace data exposure.

03 / Data Protection

Data protection

Project steering data includes sensitive project, cost, supplier, and resource information. Evoltir PM Cockpit is built with controlled access and data protection in mind.

EU hosting (Frankfurt)
GDPR-oriented architecture
TLS 1.2+ in transit
AES-256 at rest
Row-level security
MFA (TOTP)
Audit-style activity history
GDPR data export
04 / Auditability

Auditability

Project steering requires traceability. Evoltir PM Cockpit records key actions and status changes so teams can see what changed, when, and by whom.

Change request status changes
Resource approval decisions
Gate decisions
Project status updates
Member and role changes
Activity history
05 / AI & data governance

EvoltirAI operates inside the same security boundaries as your project data.

The full capability story lives on the Intelligence page. Here only one thing matters: control, isolation and governance.

Workspace-isolated

Separated customer environments

EvoltirAI operates inside the respective customer workspace. Project knowledge is not mixed across customer environments.

Permission-checked

The AI sees only what the user sees

The AI can only use information the respective user is allowed to access inside Evoltir.

Source-backed

Answers with provenance

Answers can be traced back to the underlying project information.

Confirmation before writes

No unnoticed changes

EvoltirAI does not change project data unnoticed. Write actions are confirmed before execution.

No cross-training

Your data trains no external models

Customer data is not used to train models across customers.

Controllable operation

Kill switch and cost limits

Workspace-wide controls, a kill switch and cost limits create operational control over AI functions.

For Your IT Team

Need security details for IT review?

We can provide the security and access-control overview for your IT team during the evaluation process, including the SSO roadmap, EU hosting details, and GDPR posture.

See Evoltir live Discuss the 90-day pilot
Free walkthrough See Evoltir live