Access & security
built into Configuration.
The same controls customers manage under Access & Security in the product — org isolation, profiles, positions, marketplace rights, and record shares.
Org isolation
Each organization’s data and packages stay in that tenant. Users enter only the orgs they’re invited to; partners can work across organizations without mixing records.
- ✓Tenant separation — business data stays in your workspace.
- ✓Controlled invitations — admins decide who joins.
- ✓Multi-org — switch workspaces without cross-tenant leakage.
Profiles, permissions & marketplace rights
Profiles define capability groups. Permissions cover module CRUD. Meta permissions cover schema/admin, and marketplace permissions control install vs publish.
- ✓Permission matrix — create, read, update, delete per module.
- ✓Meta permissions — modules, fields, and platform settings.
- ✓Marketplace permissions — who can install or publish packages.
Positions & people
Org seats (positions) bind users to profiles; hierarchy and org reporting keep manager chains clear.
- ✓Positions — seats with auth levels and assigned users.
- ✓Hierarchy — roles, units, territories as needed.
- ✓Record shares — grant access to specific records without opening modules.
Platform safeguards
Session seat checks, rate limiting, and audit-friendly workflows (approvals, operations, exports) are part of the engine.
- ✓Secure sign-in & seats — active position validation on requests.
- ✓Rate limiting — abuse protection on sensitive APIs.
- ✓Export & jobs — structured trails when reviewers need evidence.