ZyncoAI

Security

RBAC, audit trails, secrets, and enterprise controls.

Role-based access control

Every user has a role that determines what they can view, run, or change. A support rep and an admin looking at the same workflow see different actions available to them — enforced server-side, not just hidden in the UI.

Immutable audit logs

Every run, tool call, and configuration change is recorded with who did it and when. Logs aren't editable after the fact, and can be exported to a SIEM for teams that need automation activity in their existing security tooling.

Secrets management

API keys and credentials used by a connector are stored encrypted, never exposed in workflow definitions or logs, and scoped to the workflows that actually need them rather than shared globally.

SSO & SCIM

SAML/OIDC single sign-on and SCIM-based provisioning mean access follows whatever your identity provider already says about an employee — deprovision them there, and their ZyncoAI access goes with it.

Security controls and governance policy are related but different things — access and audit logging live here, while approval rules and change tracking for what a workflow is allowed to do live under Governance. For the full compliance picture — data residency, retention policies, and SIEM export — see Enterprise.