Enterprise-grade control, from day one.
Access is determined by roles and groups -- never by exception. Every record, every field, every API call, and every AI answer runs through the same permission model, with a complete audit trail underneath.
Who sees what, decided once.
Four access levels -- all, team, own, none -- per entity, assembled into roles and inherited through groups. Auditable from the role definitions alone: no hidden bypasses, no special-cased admins.
- Per-entity granularity with team-aware scoping
- Field-level permissions for sensitive data
- Row-level data filters stack with roles
Sign in your way -- with MFA that isn't optional theater.
Local passwords with bcrypt, SSO via Google, Microsoft, Apple, LinkedIn, or any OIDC provider, passkeys, TOTP, recovery codes, and trusted devices. Suspending a user closes the login surface without destroying their history.
Who changed what, when, and why.
Field-level audit history on every record and a security audit log for sign-ins and permission changes. Jules operates inside the same boundary -- AI answers are governed by the asker's permissions and logged like any other access.
- Field-level change history on every record
- Security event log for compliance review
- AI calls logged and evaluated
Operational control


Bring your security questionnaire.
We'll walk it line by line -- and show you the Trust Center while we're at it.


