Admin without a change request.
Invite people, hand out roles, and promote configuration from a sandbox to production. All of it from settings, and all of it on the record.
Stand the workspace up once. Domain, sign-on, directory and roles are four screens in settings. After that, people arrive and leave on their own.
Verify your domain.
Add the domain your people sign in with and the DNS records that prove you own it. Every address on it then resolves to your workspace.
Connect single sign-on.
Point Riska at your identity provider over SAML or OIDC. Members sign in with the credentials they already carry, with no second password to reset.
Sync the directory.
User and group changes flow in on their own, and you can map directory attributes onto Riska fields. Remove someone from the directory and their access goes on the next sync.
Hand out roles.
Eight roles ship with the platform, including underwriter, auditor, broker and capital partner. Settings is admin only. The rest of the app opens by role.
“Adding a role used to be a statement of work and a release window. Now it is a dropdown, and I can see who used it.”
Everyone who touches the book. Members, teams, the contacts already in your records and the systems that call your API are all granted access from the same place.
Members
One table of every person in the workspace and the role each one carries. Invite, change a role, revoke access, and see it reflected the next time they load a page.
Teams
Teams are a native part of the platform rather than a tag someone invented on a record. Create one, describe it, add and remove members, and use it everywhere else in the product.
People without logins
A broker or an insured contact is a record in your book long before anyone needs an account. When that changes, one action on the record creates the login, adds the membership and links the two together.
Machines
Systems that call Riska get their own credentials over the standard client-credentials flow. They are listed, rotated and revoked next to the humans, so nothing runs on a shared login.
Nothing changes quietly. The same log drives the Activity tab on every record, and the whole stream can be forwarded to the tooling your security team already runs.
Who, what, when
Every insert, update and delete lands with an actor and a timestamp. Filter by person, table, operation or date.
Before and after
Open an entry to see the two versions of the row side by side, keyed to the fields that actually moved.
Agents leave a trace
When the assistant or a background job makes the change, the entry names it instead of leaving the actor blank.
Change it in a sandbox first. Configuration is versioned like software. You edit a working copy, cut a numbered version when it is right, and deploy that version to an environment.
Edit the working copy.
Objects, programs, dashboards, rate books and document types all live in one editable working release. Nothing you change there reaches production until you deploy it.
Cut a version.
Publishing stamps a semantic version across every commit it contains. A release is one number that names the exact configuration behind it, and the list shows what went into each.
Deploy to an environment.
Every workspace runs in dev, uat or prod and is pinned to one release, shown in the header on every page. Rolling back is the same action pointed at the earlier number.
Configured, not customised.
The rest of the platform runs on the same settings, the same releases and the same audit trail.
Bring your open change request.
The one sitting with your policy vendor. We will make the same change in settings on the call and show you the audit entry it leaves behind.
Usually 30 minutes, with an admin on the call.