Access control
Revizo uses a multi-layer approach to access control. All authentication is handled by Clerk, a dedicated identity platform that is SOC 2 Type II certified. No user passwords or session data are stored in Revizo.
Authentication
Login
Revizo supports the following login methods via Clerk:
| Method | Description |
|---|---|
| Email and password | Traditional login with email verification |
| Google SSO | Login with a Google account |
| Microsoft SSO | Login with a Microsoft account |
Two-factor authentication (MFA)
Two-factor authentication can be enabled by each user individually via user settings. MFA supports:
- Authenticator apps (TOTP) — Google Authenticator, Microsoft Authenticator, Authy, etc.
- SMS codes — As an alternative factor
We strongly recommend that all users enable MFA, especially administrators.
Sessions
- Sessions are handled by Clerk with short-lived session tokens
- Tokens are rotated automatically
- Inactive sessions expire automatically
- Users can view and end active sessions from account settings
Organisations and multi-tenancy
Revizo is built with multi-tenancy as a foundational principle. Each customer (accounting firm) creates an organisation in Revizo. The organisation is the fundamental unit for access and data isolation:
- All data belongs to one specific organisation
- Users are invited to organisations by administrators
- A user can have access to several organisations (e.g. an accounting firm and a client)
- Data is never shared between organisations
Data isolation
Organisation ID is always taken from the authenticated session — never from the URL or user input. This prevents a user from manipulating requests to see another organisation’s data.
Isolation is enforced in three independent layers:
- Session-based — All API requests use the organisation ID from the Clerk session
- Application-based — All database queries automatically filter on organisation ID
- Database-based — Row Level Security (RLS) provides an independent safety net
Role-based access control (RBAC)
Revizo has three roles with different access levels:
| Role | Read data | Create and edit | Delete and configure | Manage users |
|---|---|---|---|---|
| Viewer | Yes | No | No | No |
| Member | Yes | Yes | No | No |
| Administrator | Yes | Yes | Yes | Yes |
What can each role do?
Viewer (org:viewer)
- View all data in the organisation (companies, clients, transactions, reports)
- Export data and reports
The Viewer role cannot use Revizo AI chat, because the chat can perform actions. See Revizo AI → Security controls.
Member (org:member)
- Everything a Viewer can do, plus:
- Import files and data
- Create and edit clients, companies, and contacts
- Run reconciliations and Smart Match
- Create and assign tasks
Administrator (org:admin)
- Everything a Member can do, plus:
- Invite and remove users
- Change user roles
- Configure integrations (Tripletex, Visma NXT)
- Change organisation settings
- Delete clients, companies, and data
- Schedule deletion of the organisation
- Export all organisation data (GDPR)
Role enforcement
Roles are enforced server-side on all API endpoints. Even if a user were to try to bypass the user interface, the server rejects requests that require a higher access level.
Invitations and user administration
- Invitations are sent by email to new users. Only administrators can invite.
- Role assignment is set at invitation and can later be changed by administrators.
- User removal — Administrators can remove users from the organisation. The user immediately loses access to all of the organisation’s data.
API access control
All API requests go through the following security pipeline:
- Session verification — Clerk verifies that the user is authenticated
- Organisation validation — Confirms that the user belongs to an active organisation
- Role check — Verifies that the user’s role has sufficient rights
- Input validation — All data is validated with structured schemas (Zod)
- Rate limiting — Prevents abuse and brute force
- Tenant filtering — Database queries are automatically limited to the organisation
- Logging — All actions are logged with user ID, organisation ID, and timestamp
Audit log
All material actions in Revizo are logged in an audit log with the following information:
| Field | Description |
|---|---|
| Timestamp | When the action was performed |
| User | Who performed the action |
| Action | What was done (created, changed, deleted, imported, etc.) |
| Resource | Which resource was affected |
| Details | Additional context where relevant |
The audit log is available to administrators and is included in the GDPR data export.
Last updated: March 2026