Sign in →
1 min read

Governance — Overview

Privacy, audit, identity, integrations, settings. Eleven pages covering everything a security or compliance reviewer needs to sign off, plus the operator surface for managing it.

Updated 2026-07-29Suggest edits

Governance is the section a security reviewer asks for and an audit signs off on. It covers personal-data handling, the audit trail, organization and access management, gateway orchestration, third-party integrations, workspace settings, billing entities, SCIM provisioning, multi-workspace identity, and rate-limit policy. Eleven pages — read what your role asks of you.

What Governance covers#

Three logical groups: privacy + compliance (Privacy Operations, Audit & Compliance), identity + access (Organization, Access Control, SCIM Provisioning, Workspaces), and plumbing + policy (Gateway Orchestration, Integrations, Settings, Billing Entities, Rate Limit Policies). They live in one sidebar group because the same operator usually owns all of them, even if they read on different days.

Pages in this section#

Privacy & compliance

Privacy Operations
DSR queue (Articles 15–22, 30-day SLA) and breach incidents (Articles 33 + 34, 72-hour SLA). Operator surface for the two time-critical GDPR workflows.
Open

Identity & access

Organization
The parent company that groups your workspaces — org members, org-level roles, and org SSO.
Open
Access Control
Read-only view of who holds which role across the workspace, backed by the audit trail.
Open

Plumbing & policy

Pick by role#

Different roles read different pages here. Use this table to jump straight to what your seat needs:

RolePages to read
Security reviewerAudit & Compliance, Privacy Operations, Access Control, SCIM Provisioning
Compliance / DPOPrivacy Operations, Audit & Compliance
Finance leadBilling Entities, Audit & Compliance
Platform engineerGateway Orchestration, Integrations, Rate Limit Policies, Settings
IT admin (identity)Organization, Access Control, SCIM Provisioning, Workspaces, Settings
Owner / Admin (everyone above)All of the above. Settings is the gate; SCIM + Workspaces is most often the access ticket.

What is internal vs. external#

Some pages here drive what an end-customer sees on the storefront; others are purely operator-facing. Knowing which is which prevents accidents:

PageAffects end-customer experience?
Privacy OperationsYes — DSR responses + breach notifications reach the customer.
Audit & ComplianceNo — internal log only.
OrganizationNo — operator org + membership management.
Access ControlNo — read-only operator role review.
Gateway OrchestrationNo — internal plumbing.
IntegrationsIndirect — ERP integration affects invoice delivery cadence.
SettingsSome toggles change storefront behaviour (locale, currency defaults).
Billing EntitiesYes — appears on the invoice the customer receives.
SCIM ProvisioningYes — affects who can log into your storefront portal.
WorkspacesNo — operator UX only.
Rate Limit PoliciesYes — the gateway rejects over-limit customer requests.
WARNING
Changes in Settings and Billing Entities can land on a live customer instantly. Stage them in sandbox first when the change is non-trivial, and read the relevant page's "destructive actions" section before flipping a switch in production.
  • Intelligence → COGS & Margins — margin observability and the Margin Guard enforcement that lives alongside it.
  • Operations — what to watch when policy changes (alerts, event log, metering health).
  • Workspace Admin — member invites + API key management (operator account management lives there).