Domain security

How do we protect access to your domains?

A RUMvision account can contain one or more domains, and different users may need access to different parts of your organisation.

RUMvision therefore combines domain verification, role-based access and domain-specific permissions to help prevent unauthorised access.

How do roles and permissions work?

RUMvision uses role-based access controls to determine what users can see and do.

Depending on the role assigned, users may receive permissions for activities such as:

  • managing domains and configuration
  • viewing monitoring data
  • managing users and permissions
  • accessing financial or subscription information
  • using API or MCP functionality where enabled

Roles can be assigned according to the responsibilities of each user, so not every user needs administrative access.

Can access be limited per domain?

Yes. Access can be granted for specific domains rather than automatically giving a user access to every domain in an organisation.

This is useful for organisations with multiple websites, teams, agencies or business units that should only access the data relevant to them.

Where appropriate, users can also be granted access across all domains.

Can two-factor authentication be enforced?

Yes. Users with the appropriate permissions can require two-factor authentication for access to a domain.

This allows organisations to enforce a stronger authentication standard for users who work with their RUMvision data and settings.

What should I consider when adding users?

Only give users the permissions they need for their role.

As your organisation changes, you should also review access and remove users or permissions that are no longer required.

We recommend:

  • using individual user accounts rather than shared logins
  • assigning the least privileged role that still allows the user to do their work
  • limiting access to the domains the user actually needs
  • enforcing two-factor authentication where appropriate
  • reviewing users and permissions periodically

Can I see who changed something?

RUMvision records relevant user activity so authorised users can review who performed actions within the application.

This helps organisations investigate changes, understand account activity and maintain internal accountability.

Read about audit logs and user activity

How is the underlying platform protected?

Domain permissions are one layer of the security model. RUMvision also applies technical and organisational measures to protect the platform and stored customer data.

Read about platform security