Administration
Security & identity
Session management, step-up re-authentication, SSO and SCIM, and support-access consent.
Sessions
Settings → Sessions lists your active sign-ins — device, location hint, last activity — and revokes any of them individually. Revoke anything you don't recognize, then change your credentials with your identity provider. Administrators can revoke all sessions for a member from the user page.
Step-up re-authentication
Sensitive operations can demand a fresh sign-in even inside a valid session — you're bounced through authentication and returned to complete the action. That's by design: possession of an open browser tab isn't proof enough for the most dangerous buttons.
SSO and SCIM
Settings → Enterprise identity (Business plans) connects your identity provider: SSO brings sign-in under your IdP's control (MFA policies included), and SCIM provisions and deprovisions members from your directory — an offboarded employee loses Itemra access when they lose their directory account, not when someone remembers. Configuration runs through a guided admin portal; directory-managed memberships then show as such in the user list, and manual changes to them are restricted accordingly.
Support access
Itemra staff can never browse your organization by default. Settings → Support access is your consent switch: grant it when support needs to see what you see, and revoke it when the case closes. While active, a banner shows the support view to everyone, support actions are attributed and logged, and the whole visit lands in the audit log.