Trustworthy access control for the whole platform
AccessGuard governs roles, fine-grained permissions and Segregation-of-Duties rules across every iDataEngine module.
Security that travels with data
One policy engine across REP, SQL, API, MF, TSAP, BI and CTM.
Roles & Hierarchies
Model business roles, delegation chains and approver hierarchies in minutes.
Field & Row Masking
Mask salaries, costs or PII at row and column level without rewriting reports.
Segregation of Duties
Detect and block conflicting permissions before they reach production.
Cross-module Policies
One policy for REP, SQL, API, MF, TSAP, BI and CTM. No more silos.
Audit Trails
Every grant, revoke and policy change is captured for SOX or ISO audits.
Compliance Reports
Pre-built role catalogues, who-has-access and SoD violation reports.
Real governance wins
From finance SoD to safe partner access.
Finance SoD
Stop "create vendor + pay invoice" combinations before they go live.
- SoD rule library
- Approval workflow
- Compliance reports
Sensitive Data Masking
Hide salary, cost or PII fields from analysts while still letting them slice data.
- Field-level masking
- Role-based unmask
- Audit visibility
Partner Access
Give partners narrow, time-bound access to specific BI pages or APIs.
- Time-bound tokens
- Tenant isolation
- Auto revoke
AG shares its cockpit with eight more modules
Same authorisation model, same logs, same release cycle. Add the next module when the next requirement lands — nothing needs rebuilding.