2026-05-13: CE - Custom Scopes

Overview

We are pleased to announce the introduction of a streamlined, tenant-specific authorization model that empowers you to define and manage your own scopes across IAM, APIs, and custom entities - all from the Management Dashboard.

This gives you fine-grained control over who can access which data and APIs, without the usual role/permission complexity.

New features

Feature
Benefit

Tenant-specific access controls based on scopes

Mirror real business structures (brands, regions, partner types) without redesigning the platform. This reduces admin effort, improves audit clarity, and strengthens enterprise security posture.

Unified scopes in APIs and OAuth2 tokens

Establish clean, predictable contracts for internal teams and partners. This accelerates integration projects and partner onboarding with a secure-by-design, API-first model.

Auto-generated scopes (including "own" access) for custom entities

Extend the data model safely while still enabling fine-grained self-service for customers and partners. This shortens time-to-market for new business concepts while keeping strict data isolation.

Central scope management in Management Dashboard

Use one control center for authorization to reduce complexity, speed up onboarding/offboarding, and provide security and compliance teams with a clear, auditable overview.

Fixes and improvements

None as this is a new feature.

Known problems

No known problems at time of release.

User Guides:

Last updated

Was this helpful?