Skip to content

Security & access

Access is a property of the record, not a setting on the screen

A partner logging in should be structurally incapable of seeing another partner's revenue — not merely unlikely to, because a filter was applied. The same holds for PII, for approvals and for anything already settled.

Roles
8

across six portals

Permission scopes
10

two reserved to super admin

Portals
6

one permission model

Audit trail
Append-only

actor, action, before and after

PII by default
Masked

every reveal is logged

Roles, scopes and the audit schema are the platform’s own; the entry count is what this dataset holds.

Role-based access

Eight roles, and the two actions nobody else can take

Roles are cut along the lines the work actually divides on — operations, finance, analysis, partner, creator — and the destructive actions are named individually rather than bundled into an admin flag.

  • Super Admin

    The whole network, including the two actions nobody else holds: a retrospective move, and an override on the audit trajectory.

  • Ops Manager

    Channel lifecycle, approvals, novations and bulk operations across the network, with partial PII reveal.

  • Ops Executive

    Day-to-day channel and video work. No PII reveal, no bulk ingestion, no ownership execution.

  • Finance Manager

    Invoices, payouts, agreements and commercials, plus the Finance stage of every approval chain.

  • Finance Executive

    Preparation and reconciliation inside finance, without the approval authority that sits above it.

  • Analyst

    Read across the network's analytics, with no write path into channels, money or PII.

  • Partner Admin

    One partner's own tenant: their channels, agreements, commercials and payouts, and nobody else's.

  • Creator

    One creator's own catalogue inside a partner: uploads, moderation outcomes, performance and earnings.

Permission scopes

10 scopes
  • Global dashboard & lifetime cards

  • Channel onboarding approval & linking

  • Prospective transfer execution

  • Retrospective move execution

    Super Admin only

  • Bulk ingestion & batch operations

  • Video privacy write-back

  • Partner novation approval

  • GDPR PII unmask

    Super Admin full, others partial

  • Video API scheduler & quota settings

  • Audit trajectory manual override

    Super Admin only

The matrix is rendered in the product as full, partial or none per role, so a permission question is answered by looking rather than by asking an engineer.

What a tenant can reach

A partner adminTheir own partner
Channels visibleof the network'stheirs only
Videos, reports, payoutstheirs only
Another partner's channelnot found
A creatorTheir partner's catalogue
Ops, finance, analyticsthe whole network

Reaching for a record outside your tenant returns a “not in your catalogue” state, which does not confirm that the record exists.

Tenant isolation

A partner sees their own network and nothing beyond it

The partner and creator portals are scoped to a tenant at the data layer, not by hiding navigation. Search, exports and deep links all inherit the same boundary.

  • Every list, detail page, report and export in the partner portal is filtered to that partner’s own records before it is rendered.
  • Command search inherits the tenant, so a partner cannot find another partner’s channel by typing its name.
  • Deep-linking to a record outside the tenant resolves to a not-in-your-catalogue state rather than a permission error that confirms the record exists.
  • Ownership changes move the boundary itself, which is why a Move — carrying all history to a new partner — is a super-admin action with an explicit statement of what happens to historical revenue.

PII

Masked by default, revealed on the record

Email, phone, PAN, GSTIN and bank details are stored as identifying data and displayed as masked data. Seeing them in full is an action, and actions are logged.

  1. 1

    Masked in the render

    Contact and tax identifiers are masked at the point of display across users, partners, entities, notifications and the partner’s own company profile.

  2. 2

    Unmask is a scoped action

    Only roles holding the GDPR unmask scope can reveal, and the product states plainly on the page who holds it.

  3. 3

    Every reveal is written down

    An unmask is recorded against the user who performed it, with the record they revealed.

  4. 4

    It re-masks itself

    Leaving the page returns the view to masked. A reveal is a moment, not a mode somebody forgets to turn off.

Audit entry

append-only
  • actor and roleWho acted, and under which role at the time
  • actionWhat was done, in the product's own vocabulary
  • entity and idExactly which record it happened to
  • before / afterThe value that was there, and the value that replaced it
  • channelUI, API, bulk import or the system itself
  • timestampWhen, to the minute, in a fixed timezone

Entries are never edited or deleted. A correction is another entry, and the pair reads as the history it actually was.

Audit and versioning

Nothing commercial is overwritten in place

An agreement, a rate, a commercial term and a settled period all share one behaviour: the new value takes effect from a date, and the old value stays legible underneath it.

Agreements are versioned

Every agreement carries a version, its effective window, its signatories and when each of them signed, bound to the enterprise CLM record and the e-signature envelope that produced it.

Commercials are effective-dated

A change to a commercial term applies from its effective date. The term that governed last quarter is still readable next to the one that governs this quarter.

Rates lock on settlement

Once a period settles, the rate rows that produced it are frozen. Editing one is refused with the reason; correcting it means superseding it from a future date.

Approvals record their chain

Each step keeps its order, role, approver, decision, comment and SLA — including the steps that breached, which stay visible rather than being cleared.

Ownership carries its history

Novations and ownership changes hold their own audit trail, so a channel that has moved partners can be read back to the day it arrived.

The log is filterable

Entries can be filtered by entity, actor and channel, sorted, and opened to a before-and-after view of the exact change.

  • Notifications go out over email, WhatsApp and in-app, and what was sent is part of the record rather than a side effect.
  • Every approval names the role it waits on and the SLA it runs against, so an authorisation is never simply pending with nobody attached to it.

Check it in the product

Users and roles, the permission matrix, the masked partner directory and the activity log are all open in the admin portal.