Skip to content

Access and governance

Access and governance explain why each user sees the records, fields, actions, and history they are allowed to use. Moltaro combines broad roles with Security Statements, record-specific responsibility, field access, and audit history.

Use this section when you need to understand the difference between being able to do something in general and being responsible for one specific record.

For central authentication without centralizing workspace authorization, read External identity and SSO.

An Owner or Admin creates local users under Administration > Users. A new Workspace user receives an initial password in the same create workflow, so the account can sign in immediately after its roles are assigned. The password must contain at least six characters and at least one digit.

Service accounts do not use passwords; administrators issue API keys for them. External-identity provisioning is also different: it may create a passwordless local profile and then explicitly link that profile to the selected provider identity. Moltaro never copies an external password into the workspace.