People and access
A. Chen · Field
Assignment filter on · J-5521 only
Office · North
Triage, dispatch, verify
Trust and security
Governance you can put in front of an auditor.
Isolation, least-privilege access and an audit trail are the foundation, not a later add-on.
Platform controls
Access is authenticated, authorised and audited.
Three controls apply to every user and every module on the platform.
Authentication
All users must authenticate before accessing any platform resource, with secure session management behind it.
Authorisation
Role-based access control with contextual rules. Every action is checked against role, scope and assignment.
Audit logging
Security-relevant events are logged and retained centrally: authentication, access and changes alike.
Multi-tenancy
Isolation between clients is enforced, not assumed.
Running multiple clients on one platform demands controls that keep each tenancy to itself. These are enforced at the application and data layers on every request.
Tenant context enforcement
Every request executes within an authenticated tenant context. Cross-tenant access is denied by default.
Domain-level segmentation
Data objects are segmented by domain and evaluated at every access check, preventing lateral movement across portfolios, sites and tenants.
Contractor isolation
External contractors access only the job-scoped data explicitly assigned to them, with no portfolio or tenant traversal.
Access governance
Least privilege and segregation of duties.
Access follows the principles auditors expect to find, applied across every role on the platform.
- User permissions follow least privilege principles, with role-based assignment and scoped access.
- Roles are designed to prevent conflicting duties, with approval workflows where separation matters.
- Role definitions, access reviews and permission change history are available as audit artefacts.
Standards
Aligned with recognised frameworks.
The platform control framework is designed in alignment with ISO 27001 and SOC 2 principles: accountability, traceability and least-privilege access. Evidence artefacts such as role matrices, access logs and retention policies are maintained against each control.
- Data encrypted in transit and at rest.
- Regional data residency options where regulation requires it.
- Private deployment available for strict data governance environments.
Detailed control documentation is available to clients and partners under the appropriate agreements. Request it through our team.
Put your security questions to us directly.
Bring your assurance, procurement or governance requirements and we will walk through how the platform meets them.