OpenRouter AI identity, MFA & sign-in security checks
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
On OpenRouter AI, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the OpenRouter AI connector needs.
Checks (3)
severity: medium Excessive Org Admins fix difficulty: medium #
Reduce the number of organization admins
- Review who holds the org:admin role
- Downgrade members who do not need admin to member
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: medium Workspace Member Has Admin Role fix difficulty: medium #
Review workspace admins and downgrade where not needed
- Open the workspace's member settings
- Downgrade members who do not need admin to a lower role
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: medium SCIM Group Without Workspace Mapping fix difficulty: easy #
Map the SCIM group to a workspace, or remove it if unused
- Open Settings → SCIM in the OpenRouter dashboard
- Map the group to a workspace, or delete it if it is no longer needed
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6