Adyen

Adyen

Corma connects to Adyen to control Customer Area users and roles, revoke access on departure and run the access reviews that PCI DSS v4 expects.

The Corma and Adyen integration brings your Adyen Customer Area users under Corma's identity governance, so finance, payments and security teams know who can see transactions, issue refunds or change payment settings, and can prove it to an assessor. Adyen is a global financial technology platform for payments, data and financial products, used by businesses to accept payments online, in app and in store.

Key takeaways

  • Adyen charges per transaction, not per user, so every extra Customer Area account adds risk without adding a cost anyone notices.
  • Adyen access combines roles with account scope: a user can be granted the company account or only specific merchant accounts.
  • PCI DSS v4 requires revoking access of terminated users immediately and reviewing all user accounts at least once every six months.

How does access work in the Adyen Customer Area?

In Adyen, users receive roles, which are sets of permissions, plus access to the company account or to selected merchant accounts. Admin roles can create users and hand out the roles they hold themselves. Multifactor authentication is mandatory unless the user signs in through SAML single sign-on, and offboarding means deactivating the user. Access granted on the company account is the broadest grant Adyen offers, so it deserves the closest review.

Adyen also recommends keeping at least one admin user who does not sign in through SSO. That break-glass account is legitimate, but it should be documented, owned by a named person and reviewed like the others.

Finally, Adyen relies on API credentials, the identities your systems use to call Adyen. They are separate from human users: these non-human identities belong in the same review scope.

Which PCI DSS requirements does Corma help with?

  • Requirement 8.2.5, access for terminated users is immediately revoked: Corma deactivates the Adyen user inside the offboarding workflow of its identity governance platform.
  • Requirement 8.2.6, inactive user accounts are removed or disabled within 90 days: Corma monitors Customer Area usage and flags accounts that have gone quiet.
  • Requirement 7.2.4, user accounts and access privileges are reviewed at least once every six months: Corma runs automated access review campaigns and keeps the evidence.

These requirements come from the PCI DSS standard published by the PCI Security Standards Council. Corma supports the controls, and your assessor still validates your overall compliance.

Frequently asked questions

How do I connect Corma to Adyen?

An Adyen administrator authorizes Corma through a secure OAuth flow in about a minute, with no code or configuration files. Corma then starts syncing Customer Area users.

Do we still need Adyen single sign-on?

Keep it if you use it. SSO controls how users log in, while Corma controls whether each Customer Area user, and each role, should still exist.

How is our payment data protected?

Corma requests only the permissions needed to manage access, encrypts data in transit and at rest, hosts it in France on AWS and is ISO/IEC 27001:2022 certified.

Preparing your next PCI DSS assessment? Book a Corma demo.

Related Integrations

Check out other integrations that could help you on managing your software licences and accesses!