Audit and security
Who signed in, what changed, and how to stop a session
clariBI records security-relevant events for your organization, lets you see and end active sessions, and supports two-step sign-in on every plan.
Audit trail on Professional and Enterprise. Export on Enterprise. Two-step sign-in and session control on every plan.
- Two-step sign-in
Authenticator app codes and backup codes, on every plan - Roles and permissions
Five built-in roles; custom roles on Professional and Enterprise - Audit trail
Sign-ins, role changes and sharing, on Professional and Enterprise - Encrypted credentials
API keys and tokens for your tools are encrypted before storage
01 Audit trail
An organization-wide record
- Events such as sign-ins and failed sign-ins, role and permission changes, sharing, data source changes and settings changes are recorded with the user, time and details.
- The trail is searchable and filterable. By default only the Owner role can open it.
- Security alerts are raised for suspicious patterns and can be marked resolved or a false positive.
- Events can be signed, and a trail can be verified later to show it has not been changed.
- Events are kept for seven years by default. The retention period can be changed.
- When clariBI staff sign in as a user to help with a support request, every event records the staff member behind the session.
- On Enterprise, the trail can be exported as JSON or CSV.
02 Sessions
Seeing and ending sessions
| Who | What they can do |
|---|---|
| Every user | List their active sessions, end one or all of them, and set their own session timeout. |
| Owners and administrators | See session statistics for the organization, review sessions flagged as suspicious, and end a member's sessions. |
| Automatic | Expired sessions are cleaned up daily. |
03 Sign-in
Two-step sign-in, social sign-in and single sign-on
- Authenticator app codes (TOTP) with a QR code for setup, backup codes for a lost phone, and trusted devices. Every plan.
- An organization can require two-step sign-in for all members.
- Sign in with Google or Facebook on every plan.
- Single sign-on through your SAML or OIDC identity provider (Okta, Microsoft Entra ID and similar) on Enterprise. People choose Sign in with SSO and enter their work email.
- SMS codes are not offered.
04 Plans
What each plan includes
| Feature | Free, Trial, Lite, Starter | Professional | Enterprise |
|---|---|---|---|
| Two-step sign-in (TOTP) | Yes | Yes | Yes |
| Google and Facebook sign-in | Yes | Yes | Yes |
| Personal activity log | Yes | Yes | Yes |
| Session list and sign-out | Yes | Yes | Yes |
| Organization audit trail | No | Yes | Yes |
| Custom roles | No | Yes | Yes |
| Audit trail export | No | No | Yes |
Try it on your own data
The trial lasts 14 days and needs no credit card. When it ends you move to the Free plan and keep your data and source dashboards.