BankID is the Swedish standard for strong electronic identification, and OptiTech supports it in two places: signing in to the workspace, and e-signing policies so employee acknowledgments carry identity-grade proof. BankID login is available on all plans.
Enable BankID login
- In the OptiTech Console, go to Settings > Identity > Login methods.
- Enable BankID. Users with a Swedish personal identity number linked to their account can now sign in with BankID on web and mobile.
- Optionally, set BankID as required for specific roles. Many organizations require it for Owner and Admin accounts while leaving email-plus-MFA for viewers.
Users link BankID to their account at first use: they sign in with their existing method, go to My profile > Login methods, and complete a BankID verification.
Combine BankID with SSO
BankID and SSO through your identity provider coexist:
- SSO required, BankID for step-up: your team signs in through Okta or Entra ID, and OptiTech asks for BankID on sensitive actions, like confirming an authority submission in the incident flow.
- BankID as the primary method: common in smaller organizations without a central IdP. No passwords exist at all.
Step-up rules are configured under Settings > Identity > Sensitive actions.
Policy e-signing with BankID
When you publish a policy that requires acknowledgment, you can require BankID signing instead of a click-through:
- On the policy's publish dialog, select Require BankID signature.
- Employees get the standard acknowledgment task, but completion requires a BankID signature.
- The signature record (who, when, which document version) lands in the evidence log.
Use BankID signing for the documents where proof matters most: the information security policy NIS2's management duties lean on, and anything your auditor samples for acknowledgment evidence. For routine documents, click-through acknowledgment keeps friction low. Documents can also be routed through Kivra for signing outside the platform.
What this feeds in your compliance program
- Access control evidence: login method policy and its enforcement are verifiable settings, exportable for your auditor.
- Acknowledgment strength: BankID-signed policies answer the "how do you know employees actually signed?" question conclusively.
- Incident audit trail: step-up authentication on authority submissions puts a strong identity behind the most consequential actions in the workspace.
Troubleshooting
- User can't link BankID: the personal identity number must match an active BankID; test with the person's bank app first.
- Step-up prompt loops: usually a stale session; sign out fully and retry.
- Non-Swedish employees: they keep email-plus-MFA or SSO. BankID requirements apply per role, and you can exempt accounts without a Swedish personal identity number.
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.