Octofi runs your people's schedules, status, and hours, so we treat that data carefully. Sign-in runs through your identity provider, every team is its own data boundary, and every change is logged.
Connect Microsoft Entra ID or Google Workspace once for your whole organization.
Mobile app access can be enabled or disabled depending on your company policy.
Disable an account to block sign-in and keep its history, or delete it to anonymize the name and email and purge the rest.
Every team in Octofi is its own data boundary, with its own schedules, time off, and dashboards. Role groups define which permissions exist, and each person gets a role on each team they belong to.
The audit log captures every change made in Octofi across every team: who made it, when, what it touched, and the request details behind it. Search it, sort it, and export it to CSV for your own reviews.
Status history adds a second trail, with every activity status change timestamped, including who set it and why.
Our SOC 2 Type II audit is underway. Ask us for the current status and timeline.
We build our security program around these frameworks. We follow them; we don't claim certification to them.
We complete security questionnaires and share supporting documentation under NDA as part of your review.
Need your data kept in a specific region or separated from other environments? Enterprise plans add regional deployment and data siloing.
Our SOC 2 Type II audit is in progress. We follow ISO 27001, NIST CSF, and PCI DSS as frameworks, and we're happy to walk your team through our controls.
Microsoft Entra ID and Google Workspace on every plan, set up once by your admin for the whole organization. Any SAML identity provider on Enterprise, set up with our team.
Yes. Admins can let the iOS and Android apps use the same SSO sign-in as the web app, with a separate setting for mobile.
Yes. Each team is its own data boundary, and roles decide what each person can view or change on each team. You can use built-in roles or create your own.
Yes. Global admins can see every change made across the organization, including who made it, when, and the request details, and export it to CSV.
Disabling an account blocks sign-in and keeps its history. Deleting an account anonymizes the name and email and purges the rest.
Yes. We complete security questionnaires and share supporting documentation under NDA.
We'll walk through sign-on, roles, and the audit log live, and answer your review questions.
Live in two weeks. Configured by our team.