Access to a defined assignment
Being invited to participate should not expose unrelated deals or documents. Access follows the scope and actions granted to the person.
Security
A shared deal does not mean shared access to every document. Our design separates customer information and checks each person’s current permissions when they work.
Being invited to participate should not expose unrelated deals or documents. Access follows the scope and actions granted to the person.
A user working for several organisations should enter the right customer context each time. Information from one customer must not appear in another customer’s work.
The source, version and responsible person matter when a decision is reviewed later. The design keeps those references with the work.
Customer access is not open. Access controls, document handling and recovery are still being implemented and tested. This page describes the design; it does not claim certification or readiness to hold customer data.
A practical example
The adviser needs the documents for an assigned review. That should not expose another deal, another customer or decisions outside the assignment.
This is the boundary the access design must maintain — including when someone’s role changes or an invitation is withdrawn.
Current permission must be checked again when information is requested or a change is saved. An earlier view of a page is not continuing permission.
An interrupted connection must not turn an unconfirmed action into a success message. The person needs a clear way to check the outcome and keep unfinished work.
Document access, backup and recovery need verification in the actual operating environment. Those release checks remain open.