Security & access
Access is a property of the record, not a setting on the screen
A partner logging in should be structurally incapable of seeing another partner's revenue — not merely unlikely to, because a filter was applied. The same holds for PII, for approvals and for anything already settled.
- Roles
- 8
- Permission scopes
- 10
- Portals
- 6
- Audit trail
- Append-only
- PII by default
- Masked
across six portals
two reserved to super admin
one permission model
actor, action, before and after
every reveal is logged
Roles, scopes and the audit schema are the platform’s own; the entry count is what this dataset holds.
Role-based access
Eight roles, and the two actions nobody else can take
Roles are cut along the lines the work actually divides on — operations, finance, analysis, partner, creator — and the destructive actions are named individually rather than bundled into an admin flag.
Super Admin
The whole network, including the two actions nobody else holds: a retrospective move, and an override on the audit trajectory.
Ops Manager
Channel lifecycle, approvals, novations and bulk operations across the network, with partial PII reveal.
Ops Executive
Day-to-day channel and video work. No PII reveal, no bulk ingestion, no ownership execution.
Finance Manager
Invoices, payouts, agreements and commercials, plus the Finance stage of every approval chain.
Finance Executive
Preparation and reconciliation inside finance, without the approval authority that sits above it.
Analyst
Read across the network's analytics, with no write path into channels, money or PII.
Partner Admin
One partner's own tenant: their channels, agreements, commercials and payouts, and nobody else's.
Creator
One creator's own catalogue inside a partner: uploads, moderation outcomes, performance and earnings.
Permission scopes
10 scopesGlobal dashboard & lifetime cards
Channel onboarding approval & linking
Prospective transfer execution
Retrospective move execution
Super Admin only
Bulk ingestion & batch operations
Video privacy write-back
Partner novation approval
GDPR PII unmask
Super Admin full, others partial
Video API scheduler & quota settings
Audit trajectory manual override
Super Admin only
The matrix is rendered in the product as full, partial or none per role, so a permission question is answered by looking rather than by asking an engineer.
What a tenant can reach
Reaching for a record outside your tenant returns a “not in your catalogue” state, which does not confirm that the record exists.
Tenant isolation
A partner sees their own network and nothing beyond it
The partner and creator portals are scoped to a tenant at the data layer, not by hiding navigation. Search, exports and deep links all inherit the same boundary.
- Every list, detail page, report and export in the partner portal is filtered to that partner’s own records before it is rendered.
- Command search inherits the tenant, so a partner cannot find another partner’s channel by typing its name.
- Deep-linking to a record outside the tenant resolves to a not-in-your-catalogue state rather than a permission error that confirms the record exists.
- Ownership changes move the boundary itself, which is why a Move — carrying all history to a new partner — is a super-admin action with an explicit statement of what happens to historical revenue.
PII
Masked by default, revealed on the record
Email, phone, PAN, GSTIN and bank details are stored as identifying data and displayed as masked data. Seeing them in full is an action, and actions are logged.
- 1
Masked in the render
Contact and tax identifiers are masked at the point of display across users, partners, entities, notifications and the partner’s own company profile.
- 2
Unmask is a scoped action
Only roles holding the GDPR unmask scope can reveal, and the product states plainly on the page who holds it.
- 3
Every reveal is written down
An unmask is recorded against the user who performed it, with the record they revealed.
- 4
It re-masks itself
Leaving the page returns the view to masked. A reveal is a moment, not a mode somebody forgets to turn off.
Audit entry
append-only- actor and roleWho acted, and under which role at the time
- actionWhat was done, in the product's own vocabulary
- entity and idExactly which record it happened to
- before / afterThe value that was there, and the value that replaced it
- channelUI, API, bulk import or the system itself
- timestampWhen, to the minute, in a fixed timezone
Entries are never edited or deleted. A correction is another entry, and the pair reads as the history it actually was.
Audit and versioning
Nothing commercial is overwritten in place
An agreement, a rate, a commercial term and a settled period all share one behaviour: the new value takes effect from a date, and the old value stays legible underneath it.
Agreements are versioned
Every agreement carries a version, its effective window, its signatories and when each of them signed, bound to the enterprise CLM record and the e-signature envelope that produced it.
Commercials are effective-dated
A change to a commercial term applies from its effective date. The term that governed last quarter is still readable next to the one that governs this quarter.
Rates lock on settlement
Once a period settles, the rate rows that produced it are frozen. Editing one is refused with the reason; correcting it means superseding it from a future date.
Approvals record their chain
Each step keeps its order, role, approver, decision, comment and SLA — including the steps that breached, which stay visible rather than being cleared.
Ownership carries its history
Novations and ownership changes hold their own audit trail, so a channel that has moved partners can be read back to the day it arrived.
The log is filterable
Entries can be filtered by entity, actor and channel, sorted, and opened to a before-and-after view of the exact change.
- Notifications go out over email, WhatsApp and in-app, and what was sent is part of the record rather than a side effect.
- Every approval names the role it waits on and the SLA it runs against, so an authorisation is never simply pending with nobody attached to it.
Check it in the product
Users and roles, the permission matrix, the masked partner directory and the activity log are all open in the admin portal.