New: Automated Design is live

IT For IT & Security

Fits the Stack You Run

SSO and SCIM through your IdP. Lake connectors and legacy import. Full audit. MCP when your AI program is ready.

PetroBench Admin assign roles across products and organization scopes
SSO-ready roles, scoped by product and org level
Audit Full Activity Trail

Every Action Lands in the Audit Log

Simulations, agent runs, role changes, and approvals, recorded with who did what and when. One trail for auditors. No second logging system.

Identity and access

Logins, role changes, and permission updates.

Simulations

Simulation inputs and outputs on the well record, with who ran the sim and when.

Agent approvals

Vector inputs, outputs, and engineer sign-off in one trail.

PetroBench Admin audit logs with searchable chronological security events
Searchable audit log across identity, sims, and approvals.
Data Connectors and Import

Connect the Lakes. Import the Wells

PetroBench pulls from the systems that already hold your wells. Engineers design on current field data, not a rebuild project before the first sim.

Lake connectors

Snowflake, Databricks, Azure, AWS, and WellView. Pull wells, surveys, and production into a simulation in one fetch.

Legacy file import

Bulk import for common desktop formats. Bring the well library in without rebuilding every string by hand.

Same credentials as the platform

Connectors and import run under the org roles and scopes IT already controls.

  • Snowflake
  • Databricks
  • Azure
  • AWS
  • WellView
  • REST API
Identity SSO and SCIM

Your IdP Stays the Source of Truth

Engineers sign in with credentials IT already manages. SCIM provisions and deprovisions users, no second user directory to maintain.

Identity providers
  • Microsoft Entra ID Azure AD
  • Okta Workforce Identity
  • SAML / OIDC Any compliant IdP

Single sign-on

SAML 2.0 and OpenID Connect through the IdP you already run.

SCIM provisioning

New hires get accounts automatically. Deprovision revokes access.

No parallel directory

IT keeps one source of truth. PetroBench consumes it.

Access Roles and Permissions

Role-Based Access Per Product

Define who can view, simulate, edit, and approve, by product and by place in the org tree.

Per product

Separate permissions for RodSim, Dynamics, Automated Design, and Vector.

Per org level

HQ, division, region, and group scopes who can view, edit, simulate, and approve.

Recorded changes

Role assignments and denied access land in the security log.

PetroBench Admin role permissions by product and organization scope
Role permissions scoped to product and org level.
Agents When AI Is on the Roadmap

Ready When Your AI Program Is

If the company is standing up agents, PetroBench already exposes rod-lift wells over MCP and REST. IT keeps the scopes. Engineers keep signoff on writes.

Hosted MCP server

Claude, Cursor, and other MCP clients call the same wells and RodSim tools under your scopes.

Same credential as REST

One org-scoped token. Same permissions as the UI. No separate agent identity store.

Vector inside PetroBench

In-product chat on the open well. Live-well writes stay behind engineer signoff and the audit log.

FAQ For IT

Questions IT Asks First

What platform owners ask before approving a rollout.

PetroBench federates through your identity provider via SAML or OIDC. SCIM provisions and deprovisions users automatically. Role-based access scopes mirror your org tree. Every action lands in an audit log.

Your data stays in your PetroBench cloud tenant with organization-level isolation. Wells, simulations, and audit records remain inside your boundary on multi-tenant cloud infrastructure.

Native connectors for Snowflake, Databricks, Azure, AWS, and WellView. Pull wells, dyno cards, surveys, and production data into a simulation in one fetch. For legacy desktop tools, bulk import handles the common formats.

Every Vector run logs who ran it, what well it touched, the inputs it read, and what it proposed. Approvals stay in the audit log so you can show which engineer signed off before anything wrote to the well.

No. PetroBench federates through the IdP you already run: Azure AD, Okta, or any SAML / OIDC provider. Engineers keep one login.

SCIM deprovisioning revokes their PetroBench access when you deactivate them in your directory. Role changes and access events stay in the audit log.

Yes. Roles attach to your org tree: HQ, division, region, and group. Engineers open only the wells and products their role allows.

No. Roll out RodSim and the platform first. When Vector is enabled, live-well writes stay behind engineer approval and every agent run is audited.

Yes. The audit log is searchable in Admin and available for compliance review, identity events, simulations, agent runs, and approvals in one trail.

Connect SSO, map initial roles for one division or region, and import a pilot well set. Expand scopes as leadership rolls out the next business unit.

See PetroBench with Your IdP Connected

Walk SSO, connectors, and audit logs on a pilot well set, with IT in the room.