SECURITY & ACCESS

The right context.
The right permissions.

Discuss access responsibilities, data handling and deployment requirements for your team.

ACCESS & RESPONSIBILITY

Controls with a defined purpose.

01

Organization and role boundaries

Server-side controls scope data to the company and enforce role restrictions. Admin, Manager, Contributor and Viewer responsibilities differ.

02

Financial visibility

Monetary fields are omitted from contributor-facing responses where role rules require it. Project assignment alone is not a private project access list.

03

Identity and sensitive actions

Discuss session security, multi-factor authentication, account activation and protection for sensitive actions. Confirm the controls enabled for your deployment.

REVIEW & ACCOUNTABILITY

Controls around changes.

Time approval permissions, correction reasons, revision records and self-review restrictions help establish context. Leave review uses the employee-manager relationship rather than the accountability hierarchy.

Confirm the audit events, retention period and operational monitoring available for your deployment.

DUE DILIGENCE

Confirm the deployment you’ll use.

Request the current hosting location, data handling agreement, access administration process, backup and recovery arrangements, incident handling, retention policy and support terms.

Security certifications, uptime commitments, data residency and recovery targets should be agreed as part of your deployment requirements.

Request security information →
MAKE THE CONNECTION

Start with the way
your company works.

Bring a real workflow to the conversation.
We’ll explore where MCT Orbit fits.

Request your walkthrough Have a specific question? Get in touch →