//Enterprise Readiness

Enterprise Readiness

Status as of March 28, 2026.

Short Answer

ButtrBase has a solid foundation for organizations, teams, billing, entitlements, and role-based permissions. It is not yet accurate to position the platform as fully enterprise-ready across identity, compliance, and tenant governance.

If enterprise customers are a target segment, these capabilities should be added deliberately and marketed according to their real status.

Capability Matrix

| Capability | Status | What Exists Now | What Is Missing | | --- | --- | --- | --- | | SSO | Partial | Google login, Microsoft login, Apple login via Apple-tagged OIDC connections, OTP, magic-link flows, org-level OIDC connection management, live org-aware OIDC login, allowed-domain checks, and optional JIT provisioning | No SAML, no SCIM, no IdP group sync, and no enforced MFA challenge flow | | Audit Logs | Partial | Generic activity logs plus structured admin audit events for org security and SSO changes, including CSV and JSON export | No retention controls, no legal hold, and no full coverage across every admin action yet | | Retention | Missing for compliance | Product retention analytics for usage trends | No retention policies for audit data, no legal hold, no admin retention controls | | RBAC | Partial | Roles, permissions, entitlement checks, and role-permission management | Incomplete enforcement across legacy routes, no delegated admin model, no resource-level policy layer | | Granular Sharing | Partial | Organizations, teams, memberships, and invite flows | No resource-level sharing, no guest governance, no external collaborator policies, no team-to-resource mapping | | Admin Controls | Partial | Product admin, org/team admin, pricing controls, org security settings, and OIDC configuration | No session inventory, no revoke-all, no IP allowlists, and no fully enforced tenant security policy center yet |

What Is Available Today

  • Organization, team, and user management
  • Custom roles, permissions, and entitlement checks
  • Passwordless OTP and magic-link login
  • Google, Microsoft, and Apple social sign-in
  • Activity logs and invitation workflows
  • Org security settings for MFA policy, session TTL, and allowed auth methods
  • Org-level OIDC connection management for enterprise setup workflows
  • Live org-aware OIDC sign-in with allowed-domain checks
  • Optional JIT provisioning for OIDC connections
  • Structured org admin audit events for security and SSO changes
  • CSV and JSON export for org audit events
  • Billing, pricing, wallet, and admin product controls
  • What Is Not Ready To Market As Generally Available Yet

  • SAML-based SSO
  • SCIM provisioning
  • Enforced MFA policies
  • Audit retention controls and legal hold
  • Legal hold
  • Resource-level sharing and guest governance
  • Session inventory, revoke-all, and IP allowlists
  • Phase 1 Status

    The first enterprise admin foundation pass is now in place, including the first runtime closeouts:

  • org_security_settings for MFA policy, session TTL, and allowed auth methods
  • sso_connections for audited OIDC tenant configuration
  • Live OIDC login options, authorize, and callback flows with allowed-domain checks
  • Optional JIT provisioning for OIDC sign-in
  • audit_events for structured org admin actions
  • CSV and JSON export for org audit events
  • React admin pages for Security, SSO, and Audit Events
  • This is still not full enterprise identity or compliance. It stores policy, makes configuration visible, enables OIDC tenant sign-in, and audits changes, but not every auth and session control is fully enforced at runtime.

    Recommended Build Order

    Next In Identity And Security Admin

  • SAML SSO per organization
  • Enforced MFA challenge and recovery flows
  • SCIM user and group sync
  • IdP group-to-role and group-to-team mapping
  • Broader runtime enforcement of org auth policy across legacy login paths
  • Phase 2: Audit And Retention

  • Expand audit event coverage across more admin, session, and agent actions
  • Retention policy controls
  • Legal hold support
  • Export scheduling or log-drain support
  • Phase 3: Authorization Hardening

  • Enforce permission middleware on all write routes
  • Add team-scoped admin and delegated admin
  • Add resource-level permissions for sensitive objects
  • Add explain tooling for access decisions
  • Phase 4: Sharing And Governance

  • Guest and external collaborator policies
  • Team-to-resource mapping
  • Session inventory and revoke-all
  • IP allowlists
  • Install permissions, rollout rings, and disable or rollback controls
  • Website Positioning

    The public site should keep three states separate:

  • Available now
  • Partially available
  • Planned / enterprise roadmap

That keeps docs, pricing, and sales conversations aligned with the actual product surface.