Skip to content
Modica Group website banner-1

Identity & Access Management

Identity and Access Management (IAM) is a security framework and set of processes that manage digital identities and control user access to resources. It ensures that only authorised individuals can access the right resources at the right time, preventing unauthorised access and data breaches.

IAM can best be separated into two sides - Authentication and Authorisation. Authentication checks who you are (this happens when you sign into our CPaaS Platform) and Authorisation checks what you are allowed to do once you’re in there. Think of it like going to a concert: authentication is showing your ticket at the entrance to prove you've purchased entry (confirming who you are), while authorisation determines whether you have general admission or VIP backstage access (what you're allowed to do once inside).

Authentication

Authentication

There are currently three different ways a customer can sign into our CPaas Platform:
1
Basic Authentication (username and password)
The easiest and most commonly used. We have strict password controls like 16 character minimums and checks for leaked passwords that ensure this is still a secure way to access our platform.
2
Multi-factor Authentication
Adds another layer of security - not only do you need to know the password but you also need to have the device which receives the SMS code - a great additional layer of security for our customers to add.
3
Federated Identity
Even more secure - it outsources the authentication to specialised Identity Providers (idPs) like Jumpcloud or Okta who have built very secure and very reliable systems for performing these authentication checks. This is a popular method for large organisations as they generally already use an IDP and will want to plug that into our CPaaS Platform for secure sign-ins.

SCIM Overview

System for Cross-domain Identity Management (SCIM)

SCIM enables seamless user provisioning directly from your identity provider. When you create, remove, or update user access in platforms like Entra ID, JumpCloud, or Okta, these changes automatically synchronise with our CPaaS Platform, removing duplicate administration.

To enforce access, our CPaaS Platform uses industry-standard Role-Based Access Control (RBAC). This ensures users only see the functions they need, while simplifying permission management for administrators. Permissions govern access to messaging features, reports, and settings. For easier management, administrators can group permissions into roles and assign them to users, with the option to add specific permissions individually when required.

scim-modica

NOTE: An Identity Provider (IdP) is a system that centrally manages user identities and shares authentication information with other applications and services. Examples are: Entra (by Microsoft - most popular), Jumpcloud, Okta and others.



Key Benefits

Streamlined User Management Automatically provisions and de-provisions user accounts, drastically reducing administrative overhead and saving valuable IT time.  
Enhanced Security Ensures immediate access revocation when employees leave, eliminating dormant accounts and reducing the risk of unauthorised access.  
Reduced Human Error Automates identity synchronisation across platforms, minimising manual data entry errors and maintaining consistent user information throughout your systems.  

Contact us today to learn more about
our Intelligent Messaging solutions