Help
ConceptFreeGrowthScale

Access controls and permissions

Workspace roles control access on your side. Two-factor authentication is available per member, and an audit log can be exported.

Access control in Vyera has two sides: who in your team can see and do what, and who at Vyera can reach your data at all.

On your side

Access to a workspace is controlled by workspace roles. Owners can manage billing, plan changes and membership; members can use the workspace day to day. See Role permissions explained for the current breakdown, and Manage team members for removing access.

A removed member loses access to the workspace immediately.

Signing in

You can sign in with a Google or Microsoft account, or with an email address and password.

Signing in with Google or Microsoft is account sign-in rather than enterprise single sign-on. It uses your existing account to authenticate, but it does not connect Vyera to an identity provider, and it does not provision or deprovision members automatically. Workspace membership is managed in Vyera.

Two-factor authentication

Two-factor authentication is available and can be turned on per member in Settings.

It is not enforced across a workspace, so turning it on is each member's own choice. If your organisation requires it, ask your team to enable it individually and confirm they have.

Where a member signs in with Google or Microsoft, any two-factor requirement on that account is enforced by Google or Microsoft rather than by Vyera.

Sessions

Sessions last 7 days, after which you sign in again. This is fixed and cannot currently be changed per workspace.

Audit log

An audit log records activity in your workspace and can be exported.

On our side

Access to production systems is granted on a least-privilege basis, using role-based permissions and named individual accounts rather than shared logins. Multi-factor authentication is required for administrative and infrastructure access. Production and non-production environments are held in separate cloud accounts. Administrative actions are logged, and access is reviewed and revoked when someone changes role or leaves.

Anyone at Vyera authorised to process your data is bound by written or statutory confidentiality obligations.

What is not available

Vyera does not currently support enterprise single sign-on through an identity provider such as Okta, Entra ID or Google Workspace SAML, does not support SCIM provisioning, does not enforce two-factor authentication across a workspace, and does not allow session length to be configured.

If your organisation requires any of these, contact info@vyera.ai before you sign up rather than after.

What it does not do

Workspace roles do not partition data within a workspace. Anyone with access to a workspace can see the competitors and data in it; roles govern what someone can change, not what they can see.

They also do not control access to connected third-party accounts. Disconnecting a Vyera workspace member does not change their access to your Slack, Search Console or Google Analytics accounts, which is managed in those tools.

Last verified 3 August 2026

Was this useful?

Related articles

  • Role permissions explained

    Owners can manage billing and members; members can use the workspace day to day.

  • Manage team members

    Review who has access to your workspace and remove members who no longer need it.

  • How we secure your data

    Your data is encrypted in transit and at rest, and access is restricted on a least-privilege basis. Vyera holds no independent security certification.

  • Our data processing agreement

    Vyera's DPA is published at vyera.ai/dpa and is incorporated into the Terms automatically, so there is nothing to sign.

Still stuck?

Send this to the team and we will pick it up.