Roles and rights
Permissions follow job descriptions instead of blanket access. A sales rep should not be able to pull the full contractor database in one click.
Every application is treated twice over: as a store of your data and as a possible exit route for it.
Permissions follow job descriptions instead of blanket access. A sales rep should not be able to pull the full contractor database in one click.
Each connection, whether BaseLinker, a payment gateway or the accounting sync, receives a separate account or Entra ID app registration holding precisely the permissions it uses.
Secrets move from config files into a vault, are pinned to known IP addresses and rotated on schedule. KSeF tokens carry only the scope their task demands.
We list the third-party apps employees have authorised against Microsoft 365 or Google Workspace data and introduce stricter approval for future ones.
A record of who altered prices, exported client lists or raised their own privileges. Without it an investigation has nothing to work on.
A fixed update routine tested on staging, plus monitoring of third-party components in custom-built software.
Department managers decide who needs what. We convert those decisions into configuration.
Every application in use, its users, the data inside and the places it sends that data.
Managers and we agree the roles and their contents, captured in a spreadsheet that is simple to maintain.
Roles applied, integrations moved to their own identities, secrets tidied and logging enabled.
Regularly, for example every six months, rights are matched against current positions, because staff change teams and their access tends to follow them.
An integration account is frequently the strongest identity in the company. It has full rights, a password that never changes and sign-ins nobody reviews. Steal its key and an attacker has everything at once, with no employee involved.
Common, but avoidable. Access to a handful of modules is usually enough, and full rights can be granted temporarily for a specific upgrade. We change the password after each such session.
In a secrets vault or inside the system that uses it, never in a desktop file or an email. It should carry only the permissions the integration needs and be replaced when the person who generated it leaves.
This service covers configuration, permissions, integrations and dependencies. A full vulnerability hunt in the code is a penetration test, available separately in the testing and QA area.
Yes, above all where someone could change a supplier's bank account number or export data. If the system supports sign-in via Entra ID or Google Workspace, we connect it to the company identity with MFA, and access ends automatically when an employee leaves.
Name the systems your business relies on and how they connect. We will suggest where to begin.
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.