Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

The User Manual has moved! For the most up-to-date information, please visit our new site at docs.antavo.com.
We're committed to providing you with the best resources, and our new site offers an enhanced experience with the latest documentation. Thank you for your understanding and continued support.

Table of Contents

Antavo security basics

...

  • Register only with individual accounts – do not use a generic account, e.g. info@yourcompany.com

  • Do not share your password information with anyone

  • Multi-factor authentication (MFA) is highly recommended for signing in to the platform for increased security

    • Administrator users with elevated rights can enforce the use of MFA.

...

Users can change their passwords by clicking the profile icon and at the bottom of the main sidebar, opening the Manage profile page, and navigating to the Change password tab.

...

The new password has to be re-entered in the ‘Confirm password' field to make sure no unintentional change is made.

Single sign-on

Single sign-on (SSO) lets users access all authorized network resources with one login. Usernames and passwords are validated against your corporate user database or other client apps rather than Antavo managing separate passwords for each resource. Some of Antavo’s integrations use SSO authentication through the Auth0 identity management platform.

...

There are a few security measures that you need to take under the Settings menu of the Antavo Backoffice.

Data backup

Antavo creates a backup of all customer data . This customer service ensures a 90-day retention period and 1-hour snapshotsbased on its data backup policy . Backups are located in the same stack as production instances. Please reach out to the Antavo Service Desk in case you have further questions or requests.

...

Security logs can be accessed by opening the Security logs tab of the Settings menu. This page lists all login and password reset information that occurs in the specific brand.
Read more about the details that can be accessed here.

Workflow logs

Workflow logs can be accessed both from the point of a specific workflow or from a specific customer. A new item is added to the logs every time a workflow is triggered by an event or a date. The lists give information on the date (the exact date and time), time (duration), type, trigger, and output (success or failure) of workflow execution.

...

Webhook logs

The Log page of the Webhook, Webhook Webhooks (betalegacy), Webhooks, and Incoming Webhook modules shows the list of triggered messages.

  • The Webhook and Webhook Webhooks (betalegacy) and Webhooks log page lists the time, action, customer, response status with code, as well as a detailed breakdown for every webhook, which includes the header and messages.
    Third-party tools PostBin can be used to display outbound webhook messages.
    The webhook log also has the possibility of resending a webhook event, in case there was an error.

  • The Incoming Webhook log page lists the date and time of the registration of the webhook message, the detailed request with the endpoint it was sent to, the processing time, and the response status with code.

Info

Find information about the retention time of logs here.

Access management

User role permissions

Antavo enables the creation of new Backoffice users with distinct roles, each with configurable access levels to the platform. In some cases, users may need access (see, edit, and delete the value) to a particular object but need restrictions on individual fields.

User groups

The User groups module allows the controlling of record-level access of Backoffice users. Setting up user groups simplifies the process of aligning users, organizational structures, and roles.

Customer mapping

Creating customer mapping rules allows to batch-update various attributes of customers, based on their previously set grouping. This helps in organizing the customers to separate compartments in the Backoffice without importing.