Skip to main content

Documentation Index

Fetch the complete documentation index at: https://docs.eraneos.com/llms.txt

Use this file to discover all available pages before exploring further.

Authentication

BusinessGPT implements robust authentication mechanisms to ensure that only authorized users can access the platform:

Single Sign-On (SSO)

BusinessGPT integrates seamlessly with Azure Active Directory, allowing organizations to:
  • Leverage existing corporate identities
  • Apply consistent access policies
  • Enforce password complexity requirements
  • Implement conditional access policies
All users must use multi-factor authentication, which provides:
  • An additional layer of security beyond passwords
  • Protection against credential theft and phishing attacks
  • Compliance with security best practices and regulations
  • Support for various authentication methods (authenticator apps, SMS, etc.)

Authorization

BusinessGPT uses a comprehensive role-based access control (RBAC) system to ensure that users can only access the resources and perform the actions they are authorized for:

Role-Based Access Control

Owner

Full control over resources, including user management and deletion

Editor

Can create, modify, and collaborate on content

Viewer

Read-only access to specific resources

Permission Levels

Access control is implemented at multiple levels:
  1. Organization Level
    • Controls who can access the organization’s BusinessGPT instance
    • Manages organization-wide settings and policies
  2. Knowledge Base, Assistant, and Prompt Level
    • Determines who can access specific knowledge bases, assistants, and prompts
    • Controls specific settings and configurations for these resources
  3. Resource Level
    • Governs access to individual chats, documents, and other resources
    • Enables detailed sharing and collaboration

User Management

BusinessGPT provides comprehensive user management features:

User Provisioning

  • Automated user provisioning via Azure AD
  • Invitation-based user registration
  • Self-service account creation (if enabled)
  • Initial role assignment
  • Immediate access revocation
  • Data transfer options for user content
  • Audit trail of user activities
  • Compliance with data retention policies

User Administration

Administrators have access to user management tools:
  • User activity monitoring and reporting
  • Role and permission management
  • Access policy enforcement