Enterprise Readiness
Status as of March 28, 2026.
Short Answer
ButtrBase has a solid foundation for organizations, teams, billing, entitlements, and role-based permissions. It is not yet accurate to position the platform as fully enterprise-ready across identity, compliance, and tenant governance.
If enterprise customers are a target segment, these capabilities should be added deliberately and marketed according to their real status.
Capability Matrix
| Capability | Status | What Exists Now | What Is Missing | | --- | --- | --- | --- | | SSO | Partial | Google login, Microsoft login, Apple login via Apple-tagged OIDC connections, OTP, magic-link flows, org-level OIDC connection management, live org-aware OIDC login, allowed-domain checks, and optional JIT provisioning | No SAML, no SCIM, no IdP group sync, and no enforced MFA challenge flow | | Audit Logs | Partial | Generic activity logs plus structured admin audit events for org security and SSO changes, including CSV and JSON export | No retention controls, no legal hold, and no full coverage across every admin action yet | | Retention | Missing for compliance | Product retention analytics for usage trends | No retention policies for audit data, no legal hold, no admin retention controls | | RBAC | Partial | Roles, permissions, entitlement checks, and role-permission management | Incomplete enforcement across legacy routes, no delegated admin model, no resource-level policy layer | | Granular Sharing | Partial | Organizations, teams, memberships, and invite flows | No resource-level sharing, no guest governance, no external collaborator policies, no team-to-resource mapping | | Admin Controls | Partial | Product admin, org/team admin, pricing controls, org security settings, and OIDC configuration | No session inventory, no revoke-all, no IP allowlists, and no fully enforced tenant security policy center yet |
What Is Available Today
- Organization, team, and user management
- Custom roles, permissions, and entitlement checks
- Passwordless OTP and magic-link login
- Google, Microsoft, and Apple social sign-in
- Activity logs and invitation workflows
- Org security settings for MFA policy, session TTL, and allowed auth methods
- Org-level OIDC connection management for enterprise setup workflows
- Live org-aware OIDC sign-in with allowed-domain checks
- Optional JIT provisioning for OIDC connections
- Structured org admin audit events for security and SSO changes
- CSV and JSON export for org audit events
- Billing, pricing, wallet, and admin product controls
- SAML-based SSO
- SCIM provisioning
- Enforced MFA policies
- Audit retention controls and legal hold
- Legal hold
- Resource-level sharing and guest governance
- Session inventory, revoke-all, and IP allowlists
org_security_settingsfor MFA policy, session TTL, and allowed auth methodssso_connectionsfor audited OIDC tenant configuration- Live OIDC login options, authorize, and callback flows with allowed-domain checks
- Optional JIT provisioning for OIDC sign-in
audit_eventsfor structured org admin actions- CSV and JSON export for org audit events
- React admin pages for Security, SSO, and Audit Events
- SAML SSO per organization
- Enforced MFA challenge and recovery flows
- SCIM user and group sync
- IdP group-to-role and group-to-team mapping
- Broader runtime enforcement of org auth policy across legacy login paths
- Expand audit event coverage across more admin, session, and agent actions
- Retention policy controls
- Legal hold support
- Export scheduling or log-drain support
- Enforce permission middleware on all write routes
- Add team-scoped admin and delegated admin
- Add resource-level permissions for sensitive objects
- Add explain tooling for access decisions
- Guest and external collaborator policies
- Team-to-resource mapping
- Session inventory and revoke-all
- IP allowlists
- Install permissions, rollout rings, and disable or rollback controls
- Available now
- Partially available
- Planned / enterprise roadmap
What Is Not Ready To Market As Generally Available Yet
Phase 1 Status
The first enterprise admin foundation pass is now in place, including the first runtime closeouts:
This is still not full enterprise identity or compliance. It stores policy, makes configuration visible, enables OIDC tenant sign-in, and audits changes, but not every auth and session control is fully enforced at runtime.
Recommended Build Order
Next In Identity And Security Admin
Phase 2: Audit And Retention
Phase 3: Authorization Hardening
Phase 4: Sharing And Governance
Website Positioning
The public site should keep three states separate:
That keeps docs, pricing, and sales conversations aligned with the actual product surface.