Controls

Enterprise-grade platform controls

Role-based access control

Permissions aligned to mandate, function and portfolio, with least-privilege defaults and periodic review.

Field-level permissions

Sensitive fields restricted, masked or made read-only according to role and supervisory context.

MFA and SSO readiness

Multi-factor authentication and integration with enterprise identity providers and directory services.

Encryption

Protection of data in transit and at rest, with governed key handling and configuration.

Immutable audit trail

Every status change, decision, document action and communication retained and attributable to a user.

Evidence integrity

Controlled upload, versioning, retention and tamper-evident handling of supporting evidence.

Export logging

Controlled export permissions with recorded requester, scope and purpose for each extract.

Maker-checker governance

Approval controls separate preparation from authorisation on sensitive and irreversible actions.

Data segregation

Separation across sectors, portfolios and functions wherever policy or confidentiality requires it.

Accountability

Compliance-grade reporting on platform activity

Administrators can evidence who accessed what, when and under which authority — supporting internal audit, oversight bodies and assurance reviews.

01

Access and permission reports

02

Configuration change history

03

Decision and approval logs

04

Export and disclosure logs

AI governance

Advisory AI, accountable officers

AI outputs are recorded as advisory suggestions with source data, rationale and confidence. Officer acceptance, edits, rejections and overrides are captured in the audit trail, and final regulatory decisions remain with authorised human officers.