Choose who can touch your Odoo, and see what they did
Give each person the access their job needs, and nothing more. Every login to Odoo from the dashboard is recorded, and your secrets stay hidden.
Who can do what
Three roles
A User can look but not change things. A Developer works on test branches only. An Admin runs the whole project, backups too.
Developer access for contractors
A developer gets full control of test branches. They can't see your live data, your settings or your backups. They only see the env vars for test branches.
Groups for your teams
Put people in a group and give the group access to many projects at once. Take someone out, and they lose access to all of them.
Invitations that expire
Invite people by email. Only that email can accept, and the link stops working after 7 days. You can take an invitation back before it's used.
Always one admin
A project can't lose its last admin. Nobody gets locked out of their own project by mistake.
Sign-in and audit log
Two-factor sign-in
Turn on two-factor sign-in for your Skysize account. A password alone is then not enough to get in.
Log in to Odoo as any user, on the record
Admins can open Odoo as one of its users to check a problem. That works for your staff, and for portal users like the customers who log in to your portal. No password is needed. The Audit tab logs who did it, as which user, where, and when.
A named record on risky changes
An admin can turn off the safety copy made before updates. If they do, the dashboard shows their name and the date on each update after that.
Secrets and data
Hidden environment variables
Mark an env var as secret, and the dashboard hides its value. Values are stored encrypted.
Keys stored encrypted
Storage keys for your backups and your Odoo Enterprise token are stored encrypted. After you save them, they're never shown again.
Database logins that stay on your server
If you use your own managed PostgreSQL, you type its login on your server. It stays there, and we never see it.
AI agents that can only read
An AI agent linked to Skysize can read logs and charts. It can't change a thing, and it never sees your env vars.
Your servers and your network
HTTPS on every domain
Every custom domain gets an HTTPS certificate, and we renew it for you. There's no switch to forget.
Protection from attacks
On our managed cloud, traffic goes through Cloudflare by default. That blocks attacks that try to flood your site.
No open port for us
Our agent on your server calls out to us over an encrypted link. You don't open any port for us to come in. Its certificate renews on its own.
Your server runs only your projects
A server you connect is tied to your account. No other customer's Odoo is ever placed on it. Our own platform keys are never sent to it.
Red Hat family with SELinux on
Run on RHEL, Rocky Linux or AlmaLinux 9 and later. The installer keeps SELinux turned on and adds the rules Skysize needs. It never turns SELinux off.
Your Odoo keeps running if you stop paying
If your subscription ends, we never reach in to shut anything down. Your Odoo and your data stay up on your server.
API tokens with limits
Tokens for scripts can have an end date. You can limit each one to the API or to AI agents. You can also make it read only.
Checks on your Odoo
Default admin password
Every hour, we check whether your production admin still uses the password "admin". We never try to log in, and the password never leaves the server.
Many failed logins
If many logins fail in a short time, the Health tab tells you. Someone may be guessing passwords.
ISO 27001 certified, as a company
Skysize holds ISO 27001 as a company. You can see the certificate and our security facts in our Trust Center.
Visit the Trust Center →Where each feature works
Frequently asked
Can a contractor see our production data?
Do you need access to my server?
Who can log in to our Odoo from the dashboard?
Where can I see your ISO 27001 certificate?
What happens to my server if we stop the subscription?
Need to fill in a security form?
Send us your questions. We'll answer them for your setup, with the facts your IT team needs.