Security & Compliance

IP Allowlisting

Restrict platform access to approved IP addresses per role or tenant — office-only for admin roles, open for field agents — with override workflows.

Get Started Free

IP Allowlisting adds a network-layer access control to your platform — ensuring that sensitive admin and finance functions can only be accessed from approved office locations or trusted network ranges. Field agents on dynamic mobile IPs are handled separately with role-specific rules, so you can enforce tight controls for high-privilege roles without blocking your frontline staff from doing their jobs.

Per-role IP restrictions CIDR range support Mobile agent exemptions Override request workflow Blocked access alerts Access attempt logging
What's included

Everything you need, nothing you don't

Per-Role IP Rules

Define allowed IP addresses or CIDR ranges per role — Super Admin can only log in from the head office IP range; Agents are unrestricted; Branch Managers can access from both the branch and home networks.

CIDR Range Support

Specify IP allowlists using individual IPs or CIDR notation — e.g. 196.x.x.0/24 for an entire office subnet — making it easy to manage access for organisations with multiple office locations.

Dynamic IP Exemptions for Agents

Mark agent-facing roles as IP-unrestricted — allowing agents on mobile data connections with dynamic IPs to log in without being blocked, while office-based admin roles remain IP-restricted.

Override Request Workflow

Users blocked by IP restriction can submit an override request from the login screen. The request routes to the security admin for approval — with a one-time access token issued on approval.

Blocked Access Alerts

Security admins receive automatic alerts when a login attempt is blocked by IP restriction — with the user's identity, attempted IP, and timestamp — for investigation.

Access Attempt Logging

Every login attempt — successful, failed, and blocked by IP restriction — is logged in the security event log with the source IP, user identity, and outcome.

Tenant-Level IP Rules

In multi-tenant deployments, each tenant can configure its own IP allowlist rules independently — applying the security policy appropriate for their specific network environment.

IP Rule Testing

Test a proposed IP rule against a list of IP addresses before activating it — confirming that it will allow the expected addresses and block the unexpected ones.

Who uses this module

Built for your team

IT & Security Teams

Enforce network-based access controls that prevent credential-theft-based access from unauthorised locations — adding a layer of protection beyond passwords and 2FA.

Compliance Officers

Demonstrate that access to sensitive financial functions is restricted to controlled environments — a common requirement in financial sector information security frameworks.

Organisations with High-Risk Roles

Protect Super Admin, Finance Director, and Compliance Officer accounts with strict office-only IP restrictions — while keeping operational staff's access unrestricted.

Ready to activate IP Allowlisting?

Sign up free and configure IP Allowlisting in minutes — or book a demo and we'll walk you through it live.

Get Started Free