API Access & Security

Connect DocBoss to your existing systems via API

Move equipment, model, and tag data directly from your ERP into DocBoss, or pull live completion metrics back into your ERP dashboards.

  • SAML 2.0 single sign-on and SCIM 2.0 user provisioning with Microsoft Entra ID, Okta and Ping.
  • Multi-factor authentication for your users and, optionally, for the customers downloading your submittals.
  • API access to projects, equipment, document codes, documents and the library, included rather than sold separately.

5 safeguards for total data and access control

Align user authentication with enterprise standards, restrict permissions down to specific roles, and maintain clear security boundaries across every division.

01

Identity

Users are managed where you already manage them. Joiners and leavers follow your existing process rather than depending on a document control administrator remembering.

02

Divisions

Separate business units, joint ventures and regional operations run as separate affiliates on one system, with their own outputs and their own user access.

03

Precision

Four role types plus per-user permissions, so an engineer who reviews drawings cannot reconfigure a project.

04

Integration

Projects created from your order system, equipment lists and document codes loaded from your ERP, library files kept in step. Data is entered where it already lives.

05

Answers

Security questionnaires are answered directly by 
people who know the system rather than deflected 
to a trust page.

Integrate DocBoss directly into your identity stack and order system

Schedule a 15-minute walkthrough to see how DocBoss plugs directly into your existing ecosystem.

HOW IT WORKS

Connects with your stack.
Scales across your enterprise.

Manage multi-affiliate setups, automate data flow via open APIs, and onboard teams through SCIM user provisioning without disruption.

Single sign-on and user provisioning

Authenticate users through your identity provider using SAML 2.0 with SCIM 2.0 provisioning for Microsoft Entra ID, Okta, or Ping. Account creation, updates, and deactivation automatically follow your standard identity lifecycle.

Confidential projects

Mark sensitive projects as confidential to restrict visibility strictly to explicitly granted users. Confidential status flags directly in the project list so data protection is clearly indicated rather than assumed.

The API

Automate project creation from your order system, load equipment lists from ERPs, and sync library files via documented API endpoints. API access is included as part of the core product without separate licensing fees.

Support access on your terms

DocBoss support cannot enter your system unless access is deliberately granted. Support permissions expire automatically and can be instantly revoked by an administrator at any point.

Roles and permissions

Assign four primary role types—view, review, full, and admin—to match team responsibilities. Individual user permissions can be scoped to specific projects to ensure appropriate access boundaries.

Affiliates for separate divisions

Run separate divisions, joint ventures, or regional entities on one system with isolated document codes, templates, and email addresses. Users access only assigned affiliates, while standard manuals can be shared across divisions.

Multi-factor authentication

Enforce MFA instance-wide or target specific roles, including external portal contacts and sub-suppliers. Separately require submittal recipients to confirm their identity before downloading files.

Hosting, backup and data handling

Hosted on AWS with versioning enabled to prevent accidental file deletion. System volumes are snapshotted hourly, retained for two weeks, encrypted, and regularly tested for restore validity.

FAQs about our API Access & Security

Get answers to questions about Access & Security

Still have questions?

Do we have to maintain a separate user list for DocBoss?

No. With provisioning enabled, users are created, updated and deactivated from your identity provider over SCIM, and they sign in with the credentials they already use.

Which identity providers and protocols do you support?

SAML 2.0 for single sign-on and SCIM 2.0 for provisioning, with Microsoft Entra ID, Okta and Ping. Configuration is done with DocBoss support rather than left to you to work out.

We have several divisions with different customers and different document requirements. Can they share one system without seeing each other’s work?

Yes. Each division runs as its own affiliate with its own document codes, templates, project settings and outbound email, and users reach only the projects belonging to the affiliates they are assigned to. Shared reference documents can still be made available across all of them.

FAQs about our API Access & Security

Get answers to questions about Access & Security

Do we have to maintain a separate user list for DocBoss?

No. With provisioning enabled, users are created, updated and deactivated from your identity provider over SCIM, and they sign in with the credentials they already use.

Which identity providers and protocols do you support?

SAML 2.0 for single sign-on and SCIM 2.0 for provisioning, with Microsoft Entra ID, Okta and Ping. Configuration is done with DocBoss support rather than left to you to work out.

We have several divisions with different customers and different document requirements. Can they share one system without seeing each other’s work?

Yes. Each division runs as its own affiliate with its own document codes, templates, project settings and outbound email, and users reach only the projects belonging to the affiliates they are assigned to. Shared reference documents can still be made available across all of them.

Still have questions?

Measurable results across every project

Learn how teams just like yours transformed complex customer formatting, cover sheet rules, and databook assembly into a push-button workflow.