Identity and access
- OIDC sign-in with PKCE, session refresh and provider sign-out (Construction Twin)
- SCIM 2.0 user provisioning and de-provisioning (Construction OS)
- TOTP two-factor enrollment to RFC 6238, compatible with standard authenticator apps
- Role-based access control scoped to tenant, organization, project and record type
- AI agents inherit — and cannot exceed — the permissions of their principal