Feature documentation

Security & Audit

Multi-tenant isolation, real RBAC, and a log that does not forget.

Desk Portal is self-hosted and multi-tenant by construction: tenant isolation is enforced in the data layer on every query, authentication is delegated to your own identity provider, permissions are enforced server-side, and every administrative and access-relevant action lands in an append-only audit log.

Isolation in depth

Tenant scoping is applied by a global query filter at the database context — endpoints cannot forget it — with write guards on top. Client-company scoping narrows further within a tenant. Requests without an established scope fail closed to zero rows.

Identity and sessions

Sign-in runs through Keycloak with OIDC and PKCE; the browser holds tokens in httpOnly cookies behind a backend-for-frontend proxy, and permissions are resolved from the database on every request — access changes take effect without waiting for tokens to expire.

Audit log

User management, role and permission changes, connection changes, control-panel actions and ticket-affecting operations are recorded append-only with actor, entity and timestamp — and with secrets redacted before anything is written.

Your infrastructure, your data

The platform, its PostgreSQL database and its encrypted secret store run on servers you control. PSA credentials never appear in configuration files, API responses or logs.

Keep your PSA. Upgrade your client experience.

Desk Portal gives your clients a modern support experience while your team continues working in the PSA they already know.