Overview
Enterprise Governance extends Bifrost’s core governance capabilities with advanced security, compliance, and user management features designed for large-scale enterprise deployments. This module provides comprehensive identity management, regulatory compliance, and detailed audit capabilities. Enterprise Extensions:- Identity & Access Management - OpenID Connect integration with Okta and Microsoft Entra
- User-Level Governance - Individual user authentication and budget allocation
- Role-Based Access Control - Fine-grained permissions with custom roles and resource-level controls
- Team Synchronization - Automatic team membership based on identity provider groups
- Compliance Framework - SOC 2 Type II, GDPR, ISO 27001, and HIPAA compliance
- Advanced Auditing - Comprehensive audit reports and compliance dashboards
- All standard Virtual Keys, Teams, and Customers functionality
- Hierarchical budget management and rate limiting
- Model and provider access controls
- Usage tracking and cost management
Identity Provider Integration
Bifrost Enterprise supports OpenID Connect (OIDC) integration with popular identity providers for single sign-on (SSO) authentication. Users are automatically provisioned on first login, with roles and team memberships synchronized from your identity provider. Supported Identity Providers:- Okta - Full OIDC integration with custom roles and group sync
- Microsoft Entra ID - Azure AD integration with app roles and group claims
- Automatic User Provisioning - Users are created on first SSO login
- Role Synchronization - Admin, Developer, and Viewer roles mapped from identity provider
- Team Membership - Groups from your identity provider automatically create and sync teams
- Secure Token Handling - JWT validation with automatic token refresh
Role Hierarchy
Bifrost uses a three-tier role hierarchy that maps to your identity provider roles:| Role | Privilege Level | Description |
|---|---|---|
| Admin | Highest | Full access to all Bifrost features and settings |
| Developer | Medium | Access to development features, API keys, and logs |
| Viewer | Lowest | Read-only access to dashboards and reports |
Configuration
Identity provider configuration is done through the Bifrost UI:- Navigate to Workspace → SCIM in the Bifrost dashboard
- Select your identity provider (Okta or Microsoft Entra)
- Enter the required credentials from your identity provider
- Enable the provider and save
User-Level Authentication & Budgeting
Enterprise Governance extends the hierarchical governance model to include individual user-level controls, providing granular access management and personalized budget allocation.User Management
Enhanced Hierarchy:- Individual Authentication - SSO-based login credentials
- Personal Budgets - User-specific cost allocation
- Access Controls - Per-user model and provider restrictions
- Usage Tracking - Individual consumption monitoring
- Audit Trails - User-specific activity logging
User Authentication Flow
SSO Authentication:Compliance Framework
Enterprise Governance includes built-in compliance capabilities for major regulatory frameworks including SOC 2 Type II, GDPR, ISO 27001, and HIPAA compliance. These features provide automated compliance monitoring, policy enforcement, and audit trail generation to meet enterprise security and regulatory requirements.Audit Reports & Compliance Dashboards
Enterprise Governance provides comprehensive audit reporting and compliance dashboards for regulatory requirements and internal governance.Audit Report Types
1. Access Audit Reports- User login/logout activities
- Failed authentication attempts
- Privilege escalation events
- Unusual access patterns
- API request tracking
- Model and provider usage
- Budget consumption patterns
- Rate limit violations
- Data access and modification
- Data export activities
- Data deletion requests
- Consent management tracking
- SOC 2 Type II control evidence
- GDPR compliance status
- ISO 27001 risk assessments
- HIPAA safeguard compliance
Report Generation
- Web UI
- API
-
Navigate to Audit Reports
- Go to Enterprise → Audit & Compliance
- Select Generate Report
- Report Configuration
- Access Report: Authentication and authorization events
- Usage Report: API consumption and cost analysis
- Compliance Report: Regulatory compliance status
- Security Report: Security events and incidents
- Last 24 Hours: Recent activity
- Last 7 Days: Weekly summary
- Last 30 Days: Monthly analysis
- Custom Range: Specific date range
- Users: Specific users or all users
- Teams: Specific teams or all teams
- Customers: Specific customers or all customers
- Event Types: Filter by event categories
- PDF: Formatted compliance report
- CSV: Raw data for analysis
- JSON: Structured data export
Compliance Dashboards
Real-Time Monitoring:- Security Posture: Current security status and alerts
- Compliance Status: Regulatory compliance health check
- Risk Assessment: Identified risks and mitigation status
- Audit Trail: Recent audit events and activities
Automated Compliance Monitoring
Continuous Monitoring:Error Responses
Enterprise Governance extends standard governance errors with additional authentication and compliance-related responses: Authentication Errors:Next Steps
- Role-Based Access Control - Manage roles and fine-grained permissions
- Setting up Okta - Configure Okta as your identity provider
- Setting up Microsoft Entra - Configure Microsoft Entra ID as your identity provider
- Core Governance - Understand base governance concepts
- Clustering - Deploy enterprise governance across multiple nodes
- Vault Support - Secure credential management
- Custom Plugins - Extend enterprise governance capabilities

