Skip to content
Help Center

Security and support access

How Vigilis support access to your data is time-boxed, scope-bounded, and audited, plus the org MFA and SSO enforcement toggles on the Authentication tab.

This article covers two sides of security you control as an org admin: how Vigilis support staff can reach your data, and how you raise the sign-in bar for your own members. The tools for the second part live on the Authentication tab in organization settings.

How Vigilis support access is controlled

When you need hands-on help, Vigilis support staff can access your organization’s data, but only under tight controls:

  • Explicit and authorized. Access is granted through your provider. It is never open-ended or standing.
  • Time-boxed. A grant defaults to 4 hours and lasts at most 24 hours, then expires automatically.
  • Scope-bounded. Access is limited to the scope of the grant, not your whole account by default.
  • Audited. Every access is logged.

There is no self-serve screen inside your own organization to view or revoke these grants. Your provider holds that control. If you want a grant changed, shortened, or ended, ask your provider. Because there is no in-app audit screen for this in your org, do not expect to pull the access log yourself; your provider can speak to it.

Requiring MFA for your members

On the Authentication tab you can turn on Require MFA for all members. Once it is on, everyone in your organization must have a second factor and cannot turn their own two-factor authentication off.

Plan the rollout: ask members to enrol an authenticator app or a passkey before you flip the toggle, so no one is locked out mid-session. If someone needs to replace their authenticator while MFA is required, they should add a passkey first. The full member-side flow is in Two-factor and passkeys.

Requiring SSO

The Authentication tab is also where you add and edit your own SAML or OIDC SSO providers and turn SSO on. To make it mandatory, enable Require SSO only so members sign in through your identity provider rather than a password or magic link.

At least one sign-in method must stay enabled at all times, so confirm your SSO provider is working and can sign people in before you require it. If you lock everyone out, contact your provider.

Common questions

Can Vigilis support staff see my organization's data?
Only under an explicit, time-limited grant authorized through your provider. Access is bounded by scope, expires automatically, and every access is logged. The default window is 4 hours and the maximum is 24.
Where can I view or revoke Vigilis support access to my org?
There is no self-serve screen in your own organization to view or revoke it. Your provider holds that control, so ask your provider to change or end a grant.
How do I require MFA for everyone in my organization?
Turn on Require MFA for all members on the Authentication tab in organization settings. After that, members cannot turn off their own two-factor authentication.
How do I make everyone sign in with SSO?
Add your SAML or OIDC provider on the Authentication tab, turn SSO on, then enable Require SSO only. At least one sign-in method must always stay enabled.

Still stuck?

If your Vigilis account is managed by an IT or telecom provider, they can resolve account and plan questions fastest. You can also reach us directly.

Contact support