Protection across the workflow
Workspace boundaries
Leads, customers, deals, activity, inventory and reporting are associated with the relevant organisation workspace.
Membership checks
A signed-in identity must have an active membership before entering a company workspace.
Tenant-aware requests
Authenticated application requests carry the selected organisation context so server-side rules can enforce the correct boundary.
Separated administration
Company administrators manage their own users, settings and operational records within their tenant.
Actions customers should take
- Confirm the selected company before entering or importing business data.
- Do not add external people to a tenant unless they are authorised by the organisation.
- Use exports only for approved business purposes and protect downloaded files.
- Notify support if a workspace name, membership or record ever appears incorrect.
Visible signs and normal behaviour
- Users with more than one membership select the company they intend to work in.
- Changing tenants changes the business context visible to the user.
- Cross-organisation access is not granted merely because two users share an email domain or device.
Controls reduce risk; they do not eliminate it.
No single control guarantees protection against every threat. Secure use also depends on accurate access decisions, protected devices, appropriate staff training and prompt reporting. We avoid claiming certifications that have not been independently verified.
