Security & trust

Access Control

Give each person and connection the access they need.

Scoped data access

Organisation and library access checks govern which service designs and submissions a team member can work with. Roles distinguish design, deployment and live-data responsibilities, while service authentication and sharing settings control access within the respondent journey.

Apply permissions around the tasks people need to perform. For a review or multi-party service, test access using the intended participant and reviewer roles, including attempts to open records outside their scope.

  • Assign the smallest role that supports the person’s responsibilities.
  • Review service sharing and reviewer access as part of the journey design.
  • Keep QA testing separate from live submission access.
Read service authentication and user access

Password protection

Builder passwords have length and complexity requirements, known-compromised-password checks and lockout after repeated failed attempts. Library administrators can also require MFA for Builder access.

Customer identity-provider and respondent password policies are configured separately. If your service uses organisation-controlled sign-in, work with the identity team to choose the access, recovery and additional-factor policies appropriate for those users.

  • Use individual accounts and prepare an approved account-recovery route.
  • Require Builder MFA where your library’s access policy calls for it.
  • Test sign-in failure, reset and recovery for your chosen service provider.
Read library authentication settings

Access and activity logs

Application activity and infrastructure records help investigate access and operational issues. Service audit views can show journey events, integration results and relevant user context, while platform records support the team’s infrastructure investigations.

Access to live audit information follows the relevant library roles and settings. Restrict these views because diagnostics can contain personal information or details about connected systems, and narrow searches to the incident or question being investigated.

  • Use the relevant submission, user, event type and time period to focus a review.
  • Give audit access to people with an operational need.
  • Consider logging and diagnostic access alongside exports and live-data permissions.
Explore monitoring and audit information

Control programmatic access and exports

API keys and data exports create additional routes for authorised information use. Library API keys have their own endpoint permissions and optional network restrictions. Library security settings can control live CSV and JSON exports independently of interactive data views.

Review these routes alongside user roles. Once information is exported or passed to another system, that destination’s access, retention and device controls become part of the operating arrangement.

  • Use a separate, narrowly scoped API key for each integration.
  • Decide which roles and workflows need live exports.
  • Assign owners for exported files and downstream data handling.
Read library security settings
Build with confidence

Secure services start with a conversation.

Talk to our team about your organisation’s security requirements, hosting choices and the services you want to deliver.