Skip to main content

Access control

Revizo uses a multi-layer approach to access control. All authentication is handled by Clerk, a dedicated identity platform that is SOC 2 Type II certified. No user passwords or session data are stored in Revizo.


Authentication​

Login​

Revizo supports the following login methods via Clerk:

MethodDescription
Email and passwordTraditional login with email verification
Google SSOLogin with a Google account
Microsoft SSOLogin with a Microsoft account

Two-factor authentication (MFA)​

Two-factor authentication can be enabled by each user individually via user settings. MFA supports:

  • Authenticator apps (TOTP) — Google Authenticator, Microsoft Authenticator, Authy, etc.
  • SMS codes — As an alternative factor

We strongly recommend that all users enable MFA, especially administrators.

Sessions​

  • Sessions are handled by Clerk with short-lived session tokens
  • Tokens are rotated automatically
  • Inactive sessions expire automatically
  • Users can view and end active sessions from account settings

Organisations and multi-tenancy​

Revizo is built with multi-tenancy as a foundational principle. Each customer (accounting firm) creates an organisation in Revizo. The organisation is the fundamental unit for access and data isolation:

  • All data belongs to one specific organisation
  • Users are invited to organisations by administrators
  • A user can have access to several organisations (e.g. an accounting firm and a client)
  • Data is never shared between organisations

Data isolation​

Organisation ID is always taken from the authenticated session — never from the URL or user input. This prevents a user from manipulating requests to see another organisation’s data.

Isolation is enforced in three independent layers:

  1. Session-based — All API requests use the organisation ID from the Clerk session
  2. Application-based — All database queries automatically filter on organisation ID
  3. Database-based — Row Level Security (RLS) provides an independent safety net

Role-based access control (RBAC)​

Revizo has three roles with different access levels:

RoleRead dataCreate and editDelete and configureManage users
ViewerYesNoNoNo
MemberYesYesNoNo
AdministratorYesYesYesYes

What can each role do?​

Viewer (org:viewer)

  • View all data in the organisation (companies, clients, transactions, reports)
  • Export data and reports

The Viewer role cannot use Revizo AI chat, because the chat can perform actions. See Revizo AI → Security controls.

Member (org:member)

  • Everything a Viewer can do, plus:
  • Import files and data
  • Create and edit clients, companies, and contacts
  • Run reconciliations and Smart Match
  • Create and assign tasks

Administrator (org:admin)

  • Everything a Member can do, plus:
  • Invite and remove users
  • Change user roles
  • Configure integrations (Tripletex, Visma NXT)
  • Change organisation settings
  • Delete clients, companies, and data
  • Schedule deletion of the organisation
  • Export all organisation data (GDPR)

Role enforcement​

Roles are enforced server-side on all API endpoints. Even if a user were to try to bypass the user interface, the server rejects requests that require a higher access level.


Invitations and user administration​

  • Invitations are sent by email to new users. Only administrators can invite.
  • Role assignment is set at invitation and can later be changed by administrators.
  • User removal — Administrators can remove users from the organisation. The user immediately loses access to all of the organisation’s data.

API access control​

All API requests go through the following security pipeline:

  1. Session verification — Clerk verifies that the user is authenticated
  2. Organisation validation — Confirms that the user belongs to an active organisation
  3. Role check — Verifies that the user’s role has sufficient rights
  4. Input validation — All data is validated with structured schemas (Zod)
  5. Rate limiting — Prevents abuse and brute force
  6. Tenant filtering — Database queries are automatically limited to the organisation
  7. Logging — All actions are logged with user ID, organisation ID, and timestamp

Audit log​

All material actions in Revizo are logged in an audit log with the following information:

FieldDescription
TimestampWhen the action was performed
UserWho performed the action
ActionWhat was done (created, changed, deleted, imported, etc.)
ResourceWhich resource was affected
DetailsAdditional context where relevant

The audit log is available to administrators and is included in the GDPR data export.


Last updated: March 2026