Most inventory data is lost through a shared login rather than an attack. Eze IT is built so nobody needs one.
Permission in Eze IT is a role plus a scope. The role decides what a person can do, from read only through technician and manager to full administration. The scope decides where they can do it: one site, a region, a department, or the whole organization. A technician responsible for two buildings sees those two buildings, and nothing about cost centers, purchase prices or headcount elsewhere.
Custom roles go further and control visibility field by field. Purchase price, supplier terms and depreciation class can be hidden from the people who move equipment around while remaining visible to finance, on the same asset record, without duplicating data into a second system.
Read only viewers are free and unlimited on every plan, which removes the last practical reason to share an account. Auditors and contractors can be granted read only access with an expiry date set at the point of invitation, so the access closes itself when the engagement ends rather than waiting for someone to remember.
Single sign on is available with any SAML 2.0 or OpenID Connect provider, including Microsoft Entra ID, Okta, Google Workspace and JumpCloud. With SCIM provisioning enabled, accounts are created, updated and deactivated from your directory, so somebody who leaves your organization on Friday cannot sign in on Monday. Where single sign on is not used, multi factor authentication can be enforced for every administrator, and API tokens are scoped, individually named and revocable without affecting anyone else.