Skip to main content
For IT, ops, and admins

Provision, audit, revoke — without a ticket queue.

SCIM provisioning, custom RBAC, SSO/SAML, BYOK encryption, and an immutable audit log. MCP access is scoped by the same roles as the UI, so an AI agent can never call a tool the user behind it couldn't. Every change a user makes — and every change you make to a user — is queryable and exportable.

Illustrative outcomes — design targets written by Pact, not measurements.

↓ 4 days

audit evidence gathering time

↓ 0

shadow accounts after IdP deprovisioning

↑ 12pts

MFA adoption (passkeys + SSO defaults)

↓ 78%

permission-change tickets to the help desk

What you get on day one

Six things you stop juggling.

SCIM provisioning that actually works

Okta, Azure AD, Google Workspace — provision users into Pact roles automatically. When IT removes someone from the IdP group, their Pact access disappears in the same sync cycle.

Custom roles, sane defaults

RBAC has 12+ built-in roles for the common shapes (SDR, AE, CSM, Marketing Ops, Auditor) and a UI to compose new ones from primitives. No YAML, no engineering ticket.

Audit log, immutable + exportable

Every mutation produces an event with actor, IP, before/after, and a correlation id. Export it as CSV, JSONL or XLSX for your SIEM; retention is configurable per tenant. SOC 2 evidence can be collected against this log on demand, and a HIPAA BAA is generated in-product.

BYOK + key rotation, your timeline

Bring your own data-encryption keys via KMS. Rotate without downtime; the system re-wraps data keys in the background. Key lineage is visible in the admin UI.

Session control, in real time

List every active session per user. Revoke individually or in bulk. Force a re-auth across the org from one screen — useful the day after the breach you weren't expecting.

Scoped keys for humans and agents

Scoped API keys (read-only, segment-write, audit-only) and webhook subscriptions with HMAC signing and a delivery dashboard. The same scoping governs MCP tool access, so what an AI agent can do is bounded by the role it inherits.

Explore the modules

The shipped product surfaces this role lives in.

When the auditor asked for evidence of access reviews, I exported the audit log to NDJSON and emailed it. Forty minutes from question to answer. That used to be a four-day project.

IT Director · Regulated B2B fintech · illustrative scenario

More Operations roles

See what Pact costs for your team.

Transparent plans — the Free plan stays free under the limits, and Pro and Team open with a 14-day trial, full features, no card. Compare them side by side.

Last reviewed: 2026-07-10

American English · claims grounded against shipped functionality

Closes DP-014 + DP-015