Administrative roles
Super Admin and Company Admin responsibilities are separated. Company access is scoped and permission checks protect management actions.
Security documentation
Controls for administering company identity while keeping claims within the platform’s implemented security and verification boundaries.
Review what the current SAML configuration foundation does—and does not—activate.
Controls remain subject to role, permission, plan and tenant context.
Super Admin and Company Admin responsibilities are separated. Company access is scoped and permission checks protect management actions.
Support Operators use explicitly allowed, tenant-scoped support workflows. They are not Company Admins and the support model does not provide employee impersonation.
Password/session controls, login activity, session revocation and administrator TOTP MFA foundations are implemented.
Identity audit records and security alerts support authorized review; availability can depend on plan and configuration.
DNS TXT domain verification and Trusted Domains provide scoped ownership and email-domain signals. They do not prove government identity.
Employee deactivation and company lifecycle states can stop an identity from being presented as active.
A company state applies at workspace level; employee status applies to one professional identity.
Operational lifecycle controls include active, suspended, frozen and archived handling where applied. Suspended or frozen workspaces restrict normal company operations and active identity presentation.
An employee can be activated, reviewed, frozen where supported, or deactivated independently within an operating company.
Evaluate CardIQ controls alongside your own policies and hosting arrangement.
This documentation does not claim ISO, SOC 2, PCI, NCA or other CardIQ certification.
Verification signals help recipients assess a company-controlled identity; CardIQ does not guarantee authenticity in every case or prevent all fraud.
Explore the CardIQ platform or review the workflow from verification through identity deactivation.
See how CardIQ works View pricing