AG module

Trustworthy access control for the whole platform

AccessGuard governs roles, fine-grained permissions and Segregation-of-Duties rules across every iDataEngine module.

Roles & SoD Field-level Security Audit Trails
What it does

Security that travels with data

One policy engine across REP, SQL, API, MF, TSAP, BI and CTM.

Roles & Hierarchies

Model business roles, delegation chains and approver hierarchies in minutes.

Field & Row Masking

Mask salaries, costs or PII at row and column level without rewriting reports.

Segregation of Duties

Detect and block conflicting permissions before they reach production.

Cross-module Policies

One policy for REP, SQL, API, MF, TSAP, BI and CTM. No more silos.

Audit Trails

Every grant, revoke and policy change is captured for SOX or ISO audits.

Compliance Reports

Pre-built role catalogues, who-has-access and SoD violation reports.

SoD
Conflicts caught at design time
100%
Field-level masking
Audit
Ready for SOX / ISO
Use cases

Real governance wins

From finance SoD to safe partner access.

Scenario

Finance SoD

Stop "create vendor + pay invoice" combinations before they go live.

  • SoD rule library
  • Approval workflow
  • Compliance reports
Scenario

Sensitive Data Masking

Hide salary, cost or PII fields from analysts while still letting them slice data.

  • Field-level masking
  • Role-based unmask
  • Audit visibility
Scenario

Partner Access

Give partners narrow, time-bound access to specific BI pages or APIs.

  • Time-bound tokens
  • Tenant isolation
  • Auto revoke
Part of the platform

AG shares its cockpit with eight more modules

Same authorisation model, same logs, same release cycle. Add the next module when the next requirement lands — nothing needs rebuilding.

See it live

Lock down access in days, not months

We will translate your existing role catalogue into AccessGuard policies together.