Skip to main content
Last reviewed: March 5, 2026 Owner: Security + Engineering Review cadence: Quarterly Status: Implemented This page explains how users and integrations authenticate, how Tero scopes access, and how Tero protects, rotates, and revokes credentials.

Reviewer focus

  • Which identity types are used for users and integrations
  • How least-privilege authorization is enforced
  • How credentials are stored, rotated, and revoked

Implementation status (March 5, 2026)

Tero supports SSO and OIDC-capable authentication with tenant and workspace scoped authorization. Tero scopes integration credentials to required operations and supports rotation and revocation.

Authentication and token flow

Authentication model

Authorization and least privilege

Credential lifecycle controls

Hosted vs self-hosted boundary

Evidence you can request

Exceptions and governance

Any identity or access exception requires documented approval, scoped compensating controls, and a target remediation date. Evidence requests: