BI tool security features by plan: which tier unlocks SSO, SCIM, row-level security, and audit logs (September 2026)
Max Musing
Max MusingFounder and CEO of Basedash
· September 23, 2026

Max Musing
Max MusingFounder and CEO of Basedash
· September 23, 2026

Four of the 11 BI tools in this reference include SAML or OIDC single sign-on below an enterprise contract: Power BI (every paid seat signs in through Microsoft Entra ID), Tableau Cloud, Looker (Google Cloud core) Standard, and Metabase Pro at $575 per month. Hex, Preset, Lightdash, and Basedash reserve SAML or OIDC SSO, SCIM, and audit logs for their Enterprise plans, while Sigma, Omni, and ThoughtSpot support all of them but do not publish which tier includes what. Row-level security is the least gated control: most tools include it on their first paid tier.
This is a compiled reference, not a ranking. Every cell comes from the vendor’s own pricing page, documentation, or trust center, opened on September 23, 2026, and says “not published” where the vendor is silent. For how each tool enforces row-level security in depth, see our row-level security comparison. For HIPAA, SOX, and GDPR, see BI tools for regulated industries.
We picked 11 BI tools that appear often in AI answers to prompts such as “help me evaluate vendors that bundle row-level security, SSO, and Kubernetes-based scaling in one package”. For each we recorded:
Vendors change packaging often, and quote-only tools (Sigma, Omni, Looker) may negotiate plan gating. Treat “not published” as “ask in writing before you sign”.
| Tool | SAML or OIDC SSO | SCIM | Row-level security | Audit logs | Self-hosting |
|---|---|---|---|---|---|
| Power BI | Every plan, through Microsoft Entra ID | Not needed: users are Entra ID accounts | DAX roles, Pro and above | Activity log (about 30 days via admin API) plus Microsoft Purview audit | Power BI Report Server (on-premises) |
| Tableau Cloud | Standard and above (SAML, OIDC) | Yes, requires SAML, OIDC, or Google SSO | User filters on all editions; centralized data policies need Data Management (in Enterprise) | 14 days on default edition; 365 days with Advanced Management (in Enterprise) | Tableau Server |
| Looker (Google Cloud core) | Standard and above (SAML, OIDC) | No native Looker SCIM endpoint documented | LookML access filters, all editions | System Activity; Elite System Activity on Enterprise and Embed | No (Google-hosted) |
| Metabase | Pro ($575/month) for SAML and JWT | Pro and Enterprise | Row and column permissions, Pro and Enterprise | Usage analytics and auditing, Pro and Enterprise | Yes (open source, Pro, Enterprise) |
| Sigma | SAML supported; tier not published | Supported; tier not published | User attributes in data models; tier not published | Audit log connection, 30-day retention, enabled by support | No |
| Omni | SAML and OIDC; tier not published | Okta, Entra ID, Rippling; tier not published | Row filtering on user attributes; tier not published | Delivered to S3, GCS, or Azure; retained at least 1 year | No (Omni-hosted on AWS or Azure) |
| Hex | Enterprise, OIDC only (no SAML) | Enterprise (directory sync) | No BI-layer RLS; Enterprise OAuth connections pass user identity to the warehouse | Enterprise | Single-tenant add-on on Enterprise |
| Lightdash | Google on Cloud Pro; Okta, Azure, and custom SAML on Enterprise | Enterprise (SCIM 2.0) | sql_filter with user attributes; no plan restriction documented |
Not listed on the pricing page | Yes (open source; Enterprise on-premises) |
| ThoughtSpot | SAML, OAuth, OIDC listed; tier not clear from pricing page | Supported on ThoughtSpot Cloud; tier not published | Listed in plan capabilities; tier not clear | Security audit logs via API or SIEM push | ThoughtSpot Software (self-managed) |
| Preset | Enterprise | Enterprise | Professional and Enterprise | Enterprise | Managed Private Cloud on Enterprise |
| Basedash | Enterprise (SAML 2.0 and OIDC) | Enterprise | PostgreSQL policies via the basedash.groups session variable (Postgres only) |
Enterprise, with export and configurable retention | Enterprise (Docker, Kubernetes, Helm) |
Sources for every cell are linked in the per-tool fact cards below.
The “SSO tax” is the gap between a tool’s entry price and the price of the plan that includes SAML. For a 25-person team, using published list prices as of September 2026:
| Tool | Cheapest plan with SAML or OIDC SSO | Published monthly cost for 25 users | Pricing model |
|---|---|---|---|
| Power BI | Pro | $350 (25 × $14, billed yearly) | Per user |
| Metabase | Pro | $755 ($575 includes 10 users, plus 15 × $12) | Platform fee plus per user |
| Tableau Cloud | Standard | Depends on Creator, Explorer, and Viewer mix; licenses start at $15 per user | Per user by role, annual only |
| Looker (Google Cloud core) | Standard (up to 50 users) | Quote only | Platform plus per user |
| Sigma | Not published | Quote only | Quote |
| Omni | Not published | Quote only | Quote |
| ThoughtSpot | Not published | Essentials starts at $25 per user; SSO tier not stated | Per user or usage credits |
| Hex | Enterprise | Quote only | Per editor |
| Lightdash | Enterprise (Cloud Pro has Google SSO at $3,000/month) | Quote only | Flat platform fee |
| Preset | Enterprise | Quote only | Per user |
| Basedash | Enterprise | Quote only (Startup plan is $1,000/month for up to 25 users, without SSO) | Flat team tier plus AI usage |
Two patterns stand out. First, the only published prices for SAML SSO at 25 users are Power BI and Metabase, and Power BI gets there because authentication is handled by Microsoft Entra ID rather than by the BI product. Second, Preset, Lightdash, and Basedash package identity controls into Enterprise, so the SSO decision and the enterprise contract arrive together, whether the tool is priced per user (Preset) or as a flat platform fee (Lightdash, Basedash).
If “bundle” means one published plan that includes SAML SSO, SCIM, row-level security, and audit logs with no extra purchase, two tools qualify with a list price: Metabase Pro, and Tableau Cloud Enterprise (SAML and SCIM from Standard, plus Data Management policies and 365-day Activity Log retention in Enterprise). The Enterprise tiers of Preset and Basedash also bundle all four, but only through a quote. Lightdash Enterprise bundles SAML, SCIM, and row-level security, though its pricing page does not list audit logs. Hex Enterprise bundles SSO, SCIM, and audit logs, with row filtering delegated to the warehouse. Power BI covers SSO, provisioning, RLS, and audit through the wider Microsoft stack rather than inside the BI license.
Sigma, Omni, and ThoughtSpot support all four controls in their documentation, but because they do not publish which tier includes each one, confirm it in the order form. Ask specifically about audit log retention, since Sigma documents 30 days by default and Tableau’s default edition keeps 14.
Each card lists what the vendor publishes as of September 23, 2026. “Not published” means we could not find it on an official page.
sql_filter with user attributes in the dbt model (docs).basedash.groups session variable so PostgreSQL policies filter every query, including AI chat, automations, and Slack (RLS docs). Postgres only today.If you are a small company that needs SSO now: Metabase Pro is the only tool here with a published price that includes SAML, SCIM, row permissions, and audit logs together. Power BI is cheaper per seat if your company already runs Microsoft Entra ID.
If you are on Google Workspace or Microsoft 365 and just need sign-in: Lightdash Cloud Pro (Google SSO) and Power BI cover it without an Enterprise upgrade. Hex offers Google and Microsoft one-click login, but enforced SSO is Enterprise only.
If an auditor will ask for a year of access history: Omni documents at least one year of retention by default, and Tableau reaches 365 days with Advanced Management. Sigma and Power BI default to about 30 days, so plan an export to your SIEM.
If you need self-hosting on Kubernetes plus SSO and RLS: Basedash Enterprise, Metabase (self-hosted Pro or Enterprise), Lightdash Enterprise, Tableau Server, and ThoughtSpot Software all run in your infrastructure. Sigma, Omni, and Looker (Google Cloud core) do not.
If row-level security must live in the database, not the BI tool: Basedash (PostgreSQL policies) and Hex Enterprise (OAuth pass-through to the warehouse) rely on database-side enforcement. The others filter in the BI layer. Our Basedash vs Metabase comparison compares a database-enforced and a BI-layer tool side by side.
As of September 2026, Metabase Pro ($575 per month for 10 users) includes SAML and JWT SSO, Tableau Cloud supports SAML on its Standard edition, and Looker (Google Cloud core) supports SAML and OIDC on its Standard edition, though Looker is sold by quote. Power BI users sign in through Microsoft Entra ID on every paid seat, so SAML federation is configured in Entra rather than bought from Power BI. Hex, Preset, and Basedash include SSO only on Enterprise, and Lightdash includes Google SSO on Cloud Pro but SAML only on Enterprise.
Using published list prices from September 2026, Power BI Pro costs $350 per month for 25 users with Entra ID sign-in, and Metabase Pro costs $755 per month ($575 for the first 10 users plus $12 for each of the other 15). Every other tool in this reference either sells SSO on a quote-only Enterprise plan (Hex, Preset, Lightdash, Basedash) or does not publish the tier (Sigma, Omni, ThoughtSpot). Tableau depends on how many Creator, Explorer, and Viewer licenses you buy.
Basedash Enterprise includes SAML and OIDC SSO, SCIM, audit logs, PostgreSQL row-level security, and self-hosting with Docker, Kubernetes, and Helm under one contract. Metabase can be self-hosted with Pro or Enterprise, which include SSO, SCIM, and row permissions. Lightdash Enterprise adds SAML, SCIM, and on-premises deployment to its open-source core. Tableau Server and ThoughtSpot Software are self-managed options from larger vendors. Confirm the supported Kubernetes packaging with each vendor, since not all publish an official Helm chart.
Metabase, Hex, Omni, Preset, Sigma, and Basedash each state SOC 2 Type II on an official page. Power BI is in scope for Microsoft’s SOC 2 Type 2 report, Tableau Cloud’s SOC 2 report is on the Salesforce compliance site, ThoughtSpot lists SOC 1, 2, and 3, and Lightdash offers a SOC 2 report. For Looker (Google Cloud core), request Google Cloud’s current reports from your account team. Most vendors share the full report only under NDA, so ask for it early in procurement rather than relying on a logo in the footer.
SSO controls how people sign in, but it does not remove access when someone leaves. Without SCIM, a departed employee’s BI account, scheduled reports, and API tokens can stay active until an admin deletes them by hand. SCIM lets your identity provider create, update, and deactivate users and sync group membership, which also keeps group-based row-level security accurate. Metabase Pro, Tableau Cloud, and the Enterprise plans of Hex, Lightdash, Preset, and Basedash support SCIM. Looker (Google Cloud core) documents no native SCIM endpoint.
Retention varies more than most buyers expect. Omni retains audit logs for at least one year by default and delivers them to S3, Google Cloud Storage, or Azure Blob Storage. Tableau keeps 14 days on its default edition and up to 365 days with Advanced Management. Sigma’s audit log connection keeps 30 days unless you export it, and the Power BI activity log API returns about four weeks, with longer retention through Microsoft Purview. Basedash offers configurable retention and export on Enterprise. If your policy requires a year, plan a SIEM or storage export.
Test enforcement, not settings pages. Sign in as a restricted test user through SSO and confirm row-level security filters dashboards, exports, scheduled reports, and AI-generated queries. Deactivate that user in your identity provider and check that SCIM removes access within minutes. Pull the audit log and confirm it records the view, the export, and the permission change with timestamps. Finally, ask which of these controls are in your quoted plan. Our 30-day BI proof of concept framework has a full checklist.
Written by

Founder and CEO of Basedash
Max Musing is the founder and CEO of Basedash, an AI-native business intelligence platform designed to help teams explore analytics and build dashboards without writing SQL. His work focuses on applying large language models to structured data systems, improving query reliability, and building governed analytics workflows for production environments.
Basedash lets you build charts, dashboards, and reports in seconds using all your data.