Security and governance
Keep every project and environment secure with role-based access, single sign-on, secret management, guardrail policies, and audit logs, while developers self-serve within limits.
Access and policy are managed centrally and applied everywhere, so developers self-serve without security weakening as more teams and environments come online. These are the controls that keep every project and environment secure.
Role-based access control
Control who can do what with users, roles, resource groups, and user groups, one model across every project.
Authentication and SSO
Connect the identity provider you already use over SAML and OAuth for single sign-on.
Secret management
Store secrets securely in each environment's secrets backend, never in Git, with per-environment values.
Guardrail policies
Enforce your rules automatically on every release with Rego, so nothing non-compliant reaches production.
Audit logs
Every action is attributable to a real user, and the AUDIT_LOGS_VIEW permission controls who can review the log.
Account management
Govern the cloud and Git accounts Facets connects to, with account changes audited.
Praxis (Facets' AI agentic platform) runs inside these same controls. Agents act under the same roles, permissions, and audit trail as a person, so using AI never widens what anyone can access. See Do it all with AI.
Core capabilities
The core of Facets: build infrastructure, provision environments, ship changes, and operate what is running, all from one declarative model.
Extended capabilities
Extend Facets with your own agent skills, MCP servers, duties, modules, and UI, and build them with AI so the platform delivers what your infrastructure needs.