centilio
Centilio

Explore the products

A business OS.
Room to grow.

Start with one tool. Explore the wider suite as your needs grow.

Explore Centilio One ↗Product availability follows the catalogue.
CENTILIO ACCOUNT / PLATFORM · PEARL

Trust the sign-in.
Check the access.

A secure identity workflow needs more than a login screen: enrolment, policy, recovery and evidence that the intended rule took effect.

The Account app is available. Demonstrations here use fictional data; Directory prices remain proposed.
ACCOUNT / SAMPLE IDENTITY
MK
Mira Kumar

Operations · Northfold Studio

OrganisationNorthfold Studio
Sign-in methodPasskey registered
Access comes fromRole + assignment
SignMEMBER
DriveMEMBER
VaultNOT ASSIGNED
ONE PERSON. INTENTIONAL ACCESS.
SINGLE SIGN-ON / EXPLAINED

One identity provider.
Separate app decisions.

SSO lets a compatible application rely on an identity provider. App roles, provisioning and session lifetime still need configuration.

WHO IS THIS?

Start with the person.

  • OrganisationConfirm the right business context.
  • AuthenticationCheck the supported sign-in method.
  • RecoveryKeep a tested route back in.
Celia prepares.
A person reviews the change.

Illustrative access model · not an account session

WHAT MAY THEY DO?

Assignment is a separate decision.

  • App accessWhich applications should be available?
  • RoleWhat can they do inside each one?
  • InheritanceWhich groups or rules contribute access?
Celia prepares.
A person reviews the change.

Illustrative access model · not an account session

WHAT ACTUALLY HAPPENED?

Inspect the result.

  • RecordWho requested and reviewed the change?
  • Target appDid the intended permission take effect?
  • SessionIs an older session still usable?
Celia prepares.
A person reviews the change.

Illustrative access model · not an account session

PASSKEYS / RECOVERY MATTERS

Less to type.
More to understand.

Passkeys use public-key authentication and are designed to resist phishing. Recovery and device security still matter.

01

Synced or device-bound?

Some passkeys sync through a credential provider; others are bound to a device or security key. Do not assume every private key stays on one physical device.
02

Keep a tested recovery path.

Understand the credential provider’s recovery process, maintain an appropriate backup and review lost devices from a trusted session.
03

MFA is not one universal method.

Check which methods the organisation permits and how user verification is enforced. A stored passkey label is not proof that a policy is enforced.

Technical background: FIDO Alliance passkeys guidance ↗

POLICY / WITH A SAFE ROLLOUT

Test the exception.
Before the whole team.

A mistaken identity policy can lock out the people who need to recover it.

0 of 3 reviewed

Personal checklist only. Resets on reload; no approval or request is submitted.

ASK FOR THE EVIDENCE

A badge is not
an assurance package.

Confirm security commitments in the current product and agreement.

01 / DATA

Location and retention.

Ask for current hosting, encryption, retention, deletion and data-residency documentation.

02 / ASSURANCE

Scope and date.

Request the actual certification or assessment scope. No compliance badge or uptime promise is asserted here.

03 / ACCESS

Revocation and recovery.

Test Account sessions and connected application sessions separately. Preserve a recovery owner.

QUESTIONS / ANSWERED

The details.
Without the ambiguity.

Open a question before you decide.

01

Can I use Account today?

The current Centilio Account application is available separately from this marketing preview. The inventory here follows the product handoff; confirm organisation-specific capabilities in the application before rollout.
02

Is this demo changing real access?

No. Every person and assignment in the demonstration is fictional. Nothing is saved, sent or changed in a real account.
03

Are Directory prices final?

No. Both dollar and rupee Directory figures are proposals, not purchasable offers. Confirm scope, currency, taxes, billing and support before committing.
04

Does SSO also provision and remove every account?

No. Sign-in, provisioning, app roles and session revocation are separate capabilities. Check each connection; SCIM remains on the inherited roadmap.
05

Does Account replace device management?

Device trust and session controls are not full fleet management, patching or MDM. Evaluate those requirements separately.
YOUR NEXT STEP

A clearer view.
A deliberate decision.

Explore the workflow, then confirm it against the current product.

01 / CONTINUE

Directory

Follow the next part of Account.

Explore ↗
02 / THE BUSINESS SYSTEM

Celia at the centre.

See how business context and human review fit together.

Meet Celia ↗
03 / YOUR REQUIREMENTS

Bring the access question.

Discuss the apps, people and policies your rollout needs.

Contact Centilio ↗