One organization's work
stays one organization's work.
Axgenta holds meeting minutes, contracts, performance ratings and strategic objectives — some of the most sensitive material a company produces. This page describes how that boundary is actually enforced, in enough detail that your security reviewer can argue with it.
Isolation is enforced at the data layer, not at the screen
A tenant is one organization's private area — its users, tasks, meetings, files and configuration. Every major record carries its organization's identity, and that context is resolved on every single request. Isolation is not a filter applied to a query that could be forgotten; it is a property of the data itself.
The practical consequence is the sentence we tell every user during onboarding: if you can't access something, it is usually policy, not a bug — because there is no accidental path to another organization's data to begin with.
Exactly two channels cross between organizations.
There is no third.
Working with a contractor or an agency is the one thing that has to span a boundary. Most tools answer it by selling you a guest seat, which puts an outsider inside your workspace. Axgenta's answer is narrower and, we would argue, considerably safer.
Door 01
An allowlisted status sync
Status, progress and completion time flow back to your task. That is the entire payload — not a subset that happens to be sent today, but the only fields the channel is capable of carrying.
Door 02
A dedicated shared comment thread
A channel that exists only for the two of you. Authors appear as display name and email — never a user ID, never your company's internal identifiers.
| What stays inside your workspace | What the external party gets |
|---|---|
| Internal notes and thread comments — never shared | A branded public task page: title, description, due date, status |
| Attachments — never mirrored, they stay in their own tenant | An isolated copy in their own workspace, if they choose to add it |
| Projects, approvals, reviewers and OKR links | Not available on their copy, by design |
| Your task IDs and your org chart | No ability to browse your tenant or address your task by ID |
The product actively refuses shadow objects. Invite an address that already belongs to one of your own people and Axgenta rejects the external path and tells you to assign them normally. Name a member of a different Axgenta organization as a meeting decision-maker and it refuses that too — because creating a record inside someone else's workspace is not a thing this system is willing to do.
Three independent layers decide what a person can do
They stack, and each answers a different question. Least privilege is reachable by an administrator in an afternoon, with no engineering involvement.
Layer 1
Tenant role
Eight roles from Admin down to Junior Member decide which menus can appear at all.
Layer 2
Module permission
Read, Write and Delete granted per module across ten modules — tasks, reports, settings, governance and the rest.
Layer 3
Task-party role
Inside one task, your capability comes from being its owner, reviewer or assignee — not from your seniority.
Layer 3 is the one that surprises people. A Director who is merely an assignee submits status requests like anyone else, and a Junior Member who owns a task holds full owner authority over it. Authority follows responsibility rather than hierarchy — which is precisely what stops seniority from quietly overriding process and rendering the audit trail meaningless.
What protects the data once it's in
Encrypted storage, isolated per tenant
Files live inside your organization's boundary and are encrypted at rest. No shared bucket, no cross-tenant path to them.
Malware scanning on upload
Every uploaded file is scanned automatically before it is available to anyone. A team member's infected attachment does not become your team's problem.
File access logging
File reads are logged, so “who opened the contract?” is a question with an answer rather than a discussion.
Email sends links, never attachments
Notifications carry a link, so the recipient authenticates before they see anything — and a document that changed after the email went out can never circulate in its old form.
OTP on sensitive flows
One-time codes gate the actions worth gating, alongside login-attempt tracking, session management and token management.
Configurable retention
Your retention window is yours to set, rather than ours to assume.
The AI cannot surface anything you couldn't already open
Retrieval respects authorization. The assistant and the semantic search share the same permission-aware hydration as the rest of the product, so a question put to the AI returns exactly what the person asking was already entitled to see — and nothing else.
This matters more than it sounds. In most products, adopting an AI assistant quietly creates a brand-new way for information to leak across internal boundaries. Here, turning it on does not widen anyone's access by a single record.
“Why can't I see this?” is a documented question
A system that locks things down creates support tickets. We would rather your admin could answer them without us.
| A module is missing from my menu | Your tenant role lacks Read on that module |
| I can see a screen but can't create or edit | You have Read but not Write |
| I can't update a task I'm assigned to | You're the performer — submit a status request (that's the design, not a bug) |
| My role changed but the screens didn't | Permission changes apply at next login — sign out and back in |
Admin safety rails are documented too: never remove your own RBAC write access during a live session, always keep one active administrator with full permission rights, and test a permission change on one user before rolling it to a whole role group.
What sits behind a plan, stated plainly
Single sign-on and audit log access are Galaxy-tier entitlements — everything else on this page applies to every workspace on every plan, including the free trial. Tenant isolation, the two-door boundary, the permission model, encryption, scanning and permission-aware AI are not features you upgrade into. They are how the system is built.
A Data Processing Addendum, including Standard Contractual Clauses where required, is available on request at [email protected]. Our Privacy Policy covers GDPR, UK GDPR, CCPA/CPRA and PIPEDA obligations, and the Terms of Service govern the contractual side.
