Features › Platform & Security

MOLI Authentication and Authorization

industry-standard identity and access for every context

MOLI Authentication and Authorization: a woman reads a code on her phone beside a laptop login screen

The Right Identity and Access Control for Everybody.

MOLI supports standard username and password + 2FA via TOTP, SMS, email, or voice code… alongside kiosk-native barcode, RFID, magnetic stripe, and employee ID options.

Robust authentication is supported by granular authorization controls, ensuring the right access is granted in the right way to the right people.

How It Works

  • Standard MOLI Access requires a username, password, and user-selected second factor: authenticator app (TOTP), email, sms, or voice call. During the login process, users will receive a code from their preferred medium and will need to enter the code to finish logging in.
  • Kiosk Access on the production floor can use a single-factor for login, such as barcode, keyfob (RFID), magnetic stripe card, or entering an Employee ID on the keypad.
  • Multiple Sessions may be active simultaneously, allowing sharing of a single screen by multiple people.

Reauthentication Workflow

Sensitive operations trigger a re-authentication workflow — requiring logged-in users to re-verify before their action can proceed.

For example: a Kiosk user may need to scan their badge; an admin might need to enter their password.

From Access To Authorization

Once a person is authenticated, attention shifts to authorization — What are they allowed to do?

Permissions are granular and can be granted to specific People, Roles, or Groups.

Kiosk "Explicit Mode" limits permission scope to only the permissions necessary to run the prescribed functions of each kiosk.

Logon Hours

Access can be time-boxed as well as permission-boxed. Any Person, Role, or Group can be assigned a weekly Logon Hours schedule, restricting exactly which hours logon is permitted. A Person's effective Logon Hours combine their own schedule with those of every active Role or Group they belong to.

Login attempts outside permitted hours are denied and logged, and the person is informed why.

Download the sheet (PDF) (opens in a new tab)

More in Platform & Security

Credit where it's due, access where it belongs.

Each person signs in as themselves, by badge at the kiosk or through your identity provider. Permissions set who may do what, and the record shows who did it.

Bring your IT team in The security overview