Skip to main content

Guide to the secure configuration and use of Riot

This guide brings together our recommendations for configuring and using Riot securely: shared responsibility, authentication, roles and rights, privileged functions, vulnerabilities, updates and logs.

👍 Good to know: Riot is a SaaS service. Security follows a shared responsibility model: the cloud provider secures the physical infrastructure, Riot secures the platform and the application, and you keep control of your tenant, meaning your users, their access and the data you import. The full matrix is published on our Trust Center.

1️⃣ Shared responsibility

👉 What Riot takes care of

  • Hosting in the European Union, on an architecture designed for high availability.

  • Network: WAF filtering and TLS 1.2 minimum encryption for all traffic with the platform.

  • Data: encryption at rest (AES-256) and logical isolation of each tenant; no customer's data can be accessed by another customer.

  • Application: secure development, code review, vulnerability management, hardening of the runtime and dependencies.

  • Identity and access: application authentication and authorisation, SSO and SCIM, RBAC model.

  • Monitoring: SIEM, alerting and application logs monitored by Riot's security team.

  • Backups on a schedule, with regular restore tests.

  • Incident response on the platform side, and breach notification in line with the DPA.

👉 What you are responsible for

  • Provisioning and deprovisioning your users promptly.

  • Enforcing MFA through your identity provider.

  • Classifying your data before importing it into the platform.

  • Monitoring usage of your tenant.

  • Keeping your devices and browsers up to date (patched).

  • Reporting any suspected security incident to [email protected] without undue delay.

👍 Good to know: Riot is ISO/IEC 27001:2022 certified, with the ISO/IEC 27017 and ISO/IEC 27018 extensions, and holds a SOC 2 Type II report. The certificates are available on the Trust Center. The SOC 2 report and the penetration test report are shared on request, under NDA.

2️⃣ Configuring your workspace securely

👉 Step 1: Connect Riot to your identity provider

This is the recommended setup. Your employees and admins sign in through SSO with their company account, and your authentication policies (MFA, conditional access, session rules) apply to Riot just as they do to your other tools. See Does Riot support multi-factor authentication (MFA)?

👉 Step 2: Sync your employees from your directory

Syncing keeps your user list up to date automatically: when someone leaves your directory, the change is reflected in Riot with no manual action. See Sync my employees and, for Microsoft Entra, How to use the Microsoft Entra SCIM Provisioning Service.

💡 Prerequisite: on Google Workspace, you can run the sync with an account that has restricted directory access, rather than with a super admin account. See Create a Google Workspace account with restricted directory access.

👉 Step 3: Validate your domains

Validation proves that the email domains declared in Riot belong to you, through a DNS record or an IP address allowlist. See Validate a domain.

👉 Step 4: Only enable magic link on the admin platform if you need it

Magic link sign-in is disabled by default on the admin platform. If all your admins sign in through SSO, leave it disabled: access to the admin platform then remains subject to your identity provider's policies.

👉 Step 5: Grant the minimum rights needed

Apply the principle of least privilege: give each admin the most restrictive role that still lets them do their job. Roles and the combinations to watch are detailed in section 4️⃣.

👉 Step 6: Receive integration alerts immediately

Riot notifies admins when an integration (sync, Sonar, compliance) runs into a problem. In your profile, Notifications tab, choose immediate delivery for this type of event rather than the monthly summary.

👉 Step 7: Limit the scope of your API keys

If you use the API, prefer an API key at workspace level rather than at organisation level when your tool only needs data from a single workspace. See How to use the Riot API ?

3️⃣ Authentication mechanisms

👉 SSO

Riot supports SSO through Google, Microsoft, Slack and Okta, as well as OIDC configurations for Entra, Okta, OneLogin and JumpCloud. Authentication is then handled entirely by your identity provider.

👉 Magic link

Passwordless sign-in: the user receives by email a single-use link and a 6-digit code shown only to the person who made the request. The link expires after 15 minutes and only works with the profile's primary email address. It is always available on the employee portal; on the admin platform, it depends on the workspace setting (see section 2️⃣).

👉 API

Every request must include an API key in the x-api-key header. An API key is tied to a single organisation and limited to specific scopes (for example awareness:read or simulation:read).

⚠️ Important: Riot does not provide MFA of its own on its sign-in form. To enforce it, connect Riot to your identity provider: it remains the source of truth for your access policies. An API key is a secret: never share it publicly and, if you think it has been exposed, contact us to revoke it.

4️⃣ Roles and rights

👉 At workspace level

  • Admin or Read-only, with rights that can be adjusted module by module. See Manage my Admins.

  • The super admin, shown with a crown 👑, is the account owner. They cannot be removed directly: a transfer of ownership is requested from support.

  • The developer role, granted by the super admin, lets a person create and manage API keys.

👉 At organisation level

A global admin has access to everything. For each functional area (Users, Awareness, Breaches, Inbox, Settings, Simulation, Sonar), there is an admin role (read and write) and a viewer role (read-only). These roles are granted for the whole organisation or workspace by workspace. See Understanding organization management.

👉 High-risk combinations

Some roles, alone or combined, grant broad access. Keep them to a small number of people and review them regularly:

  • Global admin: full access to every workspace in the organisation.

  • Invitation at organisation level: it grants access to every workspace, including those created later.

  • Developer role combined with an organisation-level API key: programmatic access to the data of every workspace.

  • Super admin: this is the person who grants the developer role; treat this account like a privileged account in your directory.

👉 Separating duties

  • Assign Simulation and Inbox to different people when awareness and security operations are handled by two teams: the split by functional area makes this possible.

  • Give the viewer or Read-only role to people who review results without changing anything (management, auditors).

  • Only grant the developer role to people who actually integrate the API.

  • Review the member list in Settings > Members; at organisation level, you can export it as a CSV.

5️⃣ Functions reserved for specific admins

Function

Who

Where

Invite or deactivate an admin, change their rights

Admin

Settings > Members

Grant the developer role

Super admin 👑

Settings > Members

Create and manage API keys

Developer role

Settings > API

Transfer account ownership

On request to Riot support

Chat, email

Enable magic link on the admin platform

Admin with a write role on "User Management" and "Settings"

Settings > Members

Manage integrations (sync, Albert) and domains

Admin with a write role on "User Management" and "Settings"

Settings > Members

Create a workspace, invite users in bulk

Organisation admin

Organisation

👉 When an admin leaves the company

Remove them in two places: in Settings > Members (See details > Deactivate), then in the Team tab, where they also appear as an employee. If they are the super admin, first request a transfer of ownership from support.

6️⃣ Vulnerabilities and updates

👉 Platform updates

The Riot platform is updated by our teams: you have nothing to install to benefit from patches. If an intervention requires service downtime, you are informed on status.tryriot.com.

👉 Components installed in your environment

Some components are installed on your side: the reporting button in Outlook, the Sonar browser extension, and Albert on Slack, Microsoft Teams or Google Chat. When a change requires action on your part, a dedicated article explains it, such as Update Albert on Teams: From Graph API to Setup Policies.

👉 How Riot handles vulnerabilities

Vulnerabilities are identified through automated scans, penetration tests, our Vulnerability Disclosure Program and monitoring of published security advisories. Each one is classified by severity (critical, high, medium, low) and fixed in order of priority according to that level.

👉 How you are informed

  • For service downtime: status.tryriot.com.

  • For an incident affecting several customers or a major feature: email, a banner in the platform, or your account manager if you have one.

  • For an incident that may affect your data or your service: notification as soon as possible through the contractually agreed channel, regular updates until resolution, then an incident report.

  • In the event of a personal data breach, Riot meets its notification obligations under the GDPR and the DPA.

⚠️ Important: to report a vulnerability, email [email protected] or use our Vulnerability Disclosure Program, whose terms are set out in the security.txt file. We acknowledge every report within 3 working days and give you a resolution timeline.

7️⃣ Error handling and logs

👉 Sign-in error messages

Every failed magic link sign-in displays an explicit message (account not found, link expired or already used, option disabled on the workspace, link opened on another device). What each one means and what to do are detailed in Signing in to Riot with a magic link.

👉 Integration alerts

When an integration fails, admins receive an "integration issue detected" email, sent by Riot from [email protected]. The email is triggered by the incident, once per detected problem. See Why am I receiving an "integration issue detected" email, and how often?

👉 API errors

Rate limits apply per API key; when they are exceeded, the API returns a 429 code until the next time window. The full list of responses and schemas is available on docs.tryriot.com.

👉 Processing history in Inbox

Each Inbox ticket keeps the full processing history of the reported email. See Understanding Inbox.

👉 Your identity provider's logs

With SSO, every sign-in to Riot goes through your identity provider and therefore appears in its own logs, alongside your other applications.

👉 Your workspace audit logs

You can request your workspace audit logs at any time by emailing [email protected], stating the time period and the format you need.

8️⃣ Getting help

Riot support can be reached through the chat built into the platform and by email at [email protected]. For any security matter, email [email protected]. Our security posture is detailed on the Trust Center.

Key takeaways

  • Security is shared: Riot secures the platform, you manage your users, their access and your data.

  • Connect Riot to your identity provider: your MFA policy then applies to Riot.

  • Leave magic link disabled on the admin platform if you do not need it.

  • Apply least privilege and watch the high-risk combinations: global admin, invitation at organisation level, developer role with an organisation API key.

  • Receive integration alerts immediately and deprovision admins who leave the company without delay.

  • Report any vulnerability to [email protected].

Version history

This guide is updated with every significant change to the platform and reviewed at least once a year.

Did this answer your question?