Trustworthy access control for the whole platform
AccessGuard governs roles, fine-grained permissions and Segregation-of-Duties rules across every iDataEngine module.
Security That Travels With Data
One policy engine across REP, SQL, API, MF, TSAP, BI and CTM
Roles & Hierarchies
Model business roles, delegation chains and approver hierarchies in minutes.
Field & Row Masking
Mask salaries, costs or PII at row and column level without rewriting reports.
Segregation of Duties
Detect and block conflicting permissions before they reach production.
Cross-module Policies
One policy for REP, SQL, API, MF, TSAP, BI and CTM. No more silos.
Audit Trails
Every grant, revoke and policy change is captured for SOX or ISO audits.
Compliance Reports
Pre-built role catalogues, who-has-access and SoD violation reports.
Real Governance Wins
From finance SoD to safe partner access
Finance SoD
Stop "create vendor + pay invoice" combinations before they go live.
- SoD rule library
- Approval workflow
- Compliance reports
Sensitive Data Masking
Hide salary, cost or PII fields from analysts while still letting them slice data.
- Field-level masking
- Role-based unmask
- Audit visibility
Partner Access
Give partners narrow, time-bound access to specific BI pages or APIs.
- Time-bound tokens
- Tenant isolation
- Auto revoke
Lock down access in days, not months
We will translate your existing role catalogue into AccessGuard policies together.
Plan an AG rollout