Enterprise
IAM
A centralised solution for authentication, authorisation and user identity management. IAM provides a single mechanism for user sign-in, access control and enforcement of security policies across the entire organisational infrastructure. The solution is designed as a ready-to-use platform that can be deployed immediately without extensive custom development.
Benefits
One place for identities,
access and security policies
Centralised identity and access management
Support for modern security standards
OAuth 2.0, OpenID Connect (OIDC), issuing and validation of JWT tokens, and single sign-on (SSO).
Ready-to-use administration interface
A web interface for complete IAM management — there is no need to develop your own administration portal.
Flexible API-based integration
REST API with OpenAPI / Swagger documentation and full automation options via API.
Enterprise readiness and scalability
The solution is ready for large organisations, with support for on-premise, cloud and hybrid deployment.
Minimal custom development required
A ready-to-use platform that can be deployed immediately without extensive custom development..
Support for standard data exchange formats
Data exchange in JSON and XML formats.
On-premise, cloud and hybrid deployment
The platform can be deployed in your own infrastructure, in the cloud or in a hybrid model, according to the technical and security requirements of the organisation.
Complete IAM management
without your own portal
A web interface for managing users, groups, roles and permissions — with full automation options via API.
Web interface
Web interface for comprehensive IAM management.
Management in one place
Management of users, groups, roles, and permissions.
No custom portal needed
No need to develop a custom administrative portal.
Full automation
Full automation capabilities via API.
Ready to connect
to your infrastructure
Enterprise IAM is ready to be connected to the existing application infrastructure of the organisation through standardised API interfaces.
Technical interfaces
Integrations are handled through standardised API interfaces and documented so the system can easily be connected to internal applications, enterprise systems and external services.
Integration models
Permissions can be managed in the SSO system or directly within IAM.
Supported SSO solutions and applications
The solution supports integration with web and mobile applications, microservice architectures, ERP, CRM and agenda systems.
Monitoring, audit and security
Visibility into access
and control over it
Tracking of sign-ins and API calls, detection of anomalous behaviour, security controls and log exports.
Monitoring
Tracking of user sign-ins, API calls and network access.
Threat detection
Identification of anomalous behaviour.
Security controls
Audit permissions, access blocking, enforcement of geographic restrictions.
Reporting
Exporting logs to CSV or Excel formats.
From the user account
to access control
Identity management, authentication and authorisation, roles and permissions, user groups and access on behalf of another entity.
User and identity management
The complete lifecycle of user accounts and profiles.
- Creating, editing and deactivating user accounts
- User profile management
- Identity management through a web administration interface
- REST API (documented with Swagger/OpenAPI)
Authentication and authorisation
Centralised access control for frontend applications and backend APIs.
- Support for OAuth 2.0 and OpenID Connect (OIDC) standards
- Issuing and validation of JWT tokens
- Centralised access control for frontend and backend
- Support for single sign-on (SSO)
Roles and permissions
Dynamic permission changes without modifications at application level.
- Definition of custom roles
- Assignment of roles at individual user or group level
- Dynamic permission changes without application modifications
- Centralised storage of authorisation rules
User groups
Simplified administration for large organisations.
- Creating and managing groups with large numbers of users
- Bulk group operations: role assignment, notifications, permission changes
Delegation and “On-Behalf-Of” access
Support for authentication on behalf of another entity.
- Option to sign in as another user
- Sign-in on behalf of an organisation
- Suitable for delegation scenarios, service accounts and approval workflows
Enterprise operations
and open interfaces
Enterprise deployment
IAM is designed for enterprise deployment in demanding operational environments.
INCLUDES:
- On-premise, cloud and hybrid deployment
- Failover configuration option
- Data backup and recovery without service interruption
Modular and extensible
The solution is modular, extensible and scales according to the needs of the organisation.
INCLUDES:
- Modular and extensible architecture
- Scaling according to the needs of the organisation
- Operation with a high number of users without performance degradation
Database platforms
The solution supports common enterprise database platforms.
INCLUDES:
- PostgreSQL
- MariaDB
- Microsoft SQL Server
- Oracle Database
REST API with OpenAPI / Swagger
A documented interface for connecting internal applications and external services.
JWT validation
Validation of JWT tokens for external systems.
JSON and XML data exchange
Data exchange in JSON and XML formats.
Perpetual licence
The licence is perpetual, with a clearly defined licence type and licensing model.
Production and pre-production
Valid for productive as well as testing/pre-production environments.
No limitations
No limit on the number of processed documents, volume of stored data, internal and external users, and no geographic restriction on deployment in the contracting authority’s environment.
References – selected projects
Trusted by companies
and institutions
EMPIRE THE KNOW-HOW INSTITUTE
A Slovak and Czech language school and certified educational institution specialising in corporate and individual language courses.
- A system unifying activities, access and overviews
- Unified agenda, more efficient processes
- Access to important overviews and study reports
- A comprehensive, unified system that makes work easier for all administrators
Unified agenda and access
The software for the EMPIRE language institute unifies agenda, access and overviews into one clear system.
Reports without waiting
It enables fast access to study reports without waiting for administration.
Support for every role
It makes work easier for administrators, lecturers, methodologists and clients.
What does Enterprise IAM provide?
IAM (Identity and Access Management) provides a single mechanism for user sign-in, access control and enforcement of security policies across the entire organisational infrastructure.
Is custom development required?
The solution is designed as a ready-to-use platform that can be deployed immediately without extensive custom development. It also includes a web administration interface, so there is no need to develop your own administration portal.
Which security standards are supported?
Support for OAuth 2.0 and OpenID Connect (OIDC) standards, issuing and validation of JWT tokens, and support for single sign-on (SSO).
Which SSO solutions can be used?
Microsoft Entra ID (Microsoft 365), Active Directory and identity providers compatible with OAuth 2.0 / OIDC.
How are permissions managed?
Through two models: external permission management, where permissions are defined directly in the SSO system (e.g. Microsoft Entra ID), or internal permission management, where SSO handles authentication only and authorisation with roles is managed within IAM.
Where can the solution be deployed?
The platform can be deployed in your own infrastructure, in the cloud or in a hybrid model, according to the technical and security requirements of the organisation.
Which database platforms are supported?
PostgreSQL, MariaDB, Microsoft SQL Server and Oracle Database.
How does licensing work?
The licence is perpetual, with a clearly defined licence type and licensing model, valid for productive as well as testing/pre-production environments, with no limit on the number of processed documents, volume of stored data, internal and external users, and no geographic restriction on deployment in the contracting authority’s environment.
Still have questions?
Book a consultation with us — we will gladly advise you on identity management design and deployment.
Unify identities
across your organisation
Book a consultation with us — we will prepare an identity management and integration proposal tailored to your environment.
Related solutions
Other modules
from the Enterprise ecosystem
Enterprise Web Signer
Signing · On-premise
Enterprise Archive
Local archiving of documents with issued certificates, integrable with any DMS.
Archive
Enterprise RemoteHSM
On-site HSM virtualization for Portal, PKI API, and Archive with a secure connection.
Infrastructure