Login & roles
Platform — Login & roles is authentication and authorization: users, roles and permissions, so each person sees and does only what their role allows.
All modulesBORA Systems is a ferry operations platform built in Tallinn, Estonia — 33 modules across 6 functional categories, each on its own microservice with a local API. Certified to ISO/IEC 27001 and GDPR-compliant. As of 2026, in daily service across three regions: the Baltic, the Channel Islands and the Persian Gulf.
What does it do?
Login & roles is who-can-do-what across the platform — authentication of users, the roles they hold, and the permissions those roles grant. Every module checks against it, so access is consistent everywhere.
Because access is defined once and enforced everywhere, a role change — a new desk supervisor, a withdrawn permission — takes effect across every module at once.
How does it work?
Authenticate
Users sign in through one authentication layer.
Role
Each user holds one or more roles.
Permit
Roles grant permissions every module checks.
Change
A role change applies across the platform at once.
What does it connect to?
Login & roles is checked by every module and integrates with e-Government integration for Estonian e-identity sign-in.
Login & roles exposes a local API and supports single sign-on with an operator's identity provider.
What are its limits?
What it deliberately does not do:
- Login & roles authenticates and authorizes; it is not the passenger booking identity — that is a booking, not a login.
- Login & roles grants rights; what each right permits is defined in the module that owns the action.
Frequently asked questions
How is access controlled?
By roles and permissions every module checks against one layer.
Does a role change take effect everywhere?
Yes, at once across every module.
Can it use our identity provider?
Yes — single sign-on is supported.
See Login & roles on live data
A 30-minute walkthrough, from a web booking to the ramp closing.
Akadeemia tee 15a, 12618 Tallinn, Estonia