Skip to the content

Know exactly who can see what, and prove it in a morning

Access controlled to the person and the record, every change recorded, and your answer ready the day an auditor, a client or a regulator asks for one.

Typically costs
£32k–£85k
Live in
820 weeks
Price yours properlyThree minutes, and it asks for nothing

Access and audit

3 parts

01Where this usually starts

Right now, the honest answer to who can see your customer records is that somebody would have to go and look. Permissions were set years ago by a person who has left, shared logins are still in use, and a client security questionnaire costs you a fortnight and three people.

02What changes

What you end up holding.

  • 01Permissions set by role and by record, so people reach the accounts they work on and nothing else
  • 02Every view, change and deletion recorded against a named person and readable without a translator
  • 03Your people signing in with the account they already have, and losing access the hour they leave
  • 04Client security questionnaires answered from the system instead of assembled by hand
  • 05ISO 27001, Cyber Essentials and SOC 2 evidence that is a report rather than a project

The next security questionnaire takes an afternoon, and the answers come out of the system rather than out of memory.

03The pieces

What a system like this is usually made of.

You will not want all of it on day one, and you should not pay for all of it on day one. The estimator lets you choose, and shows what each one adds.

Who can see what

Permissions by role and by record, so people see the accounts they work on and nothing else.

A record of who did what

Every change kept and attributed, readable without a technical explanation.

The audit pack

Whatever period is asked for, produced in minutes rather than a fortnight.

04How it would run

8 to 20 weeks, in five phases you approve one at a time.

  1. 01

    Getting to the truth

    A written account of how your work really runs today, what the current way is costing you, and what your new system has to do about it.

  2. 02

    Shaping it

    Every screen and every decision your system will make, in front of you and signed off, with your live date fixed at the end of it.

  3. 03

    Building it

    Your system takes shape week by week in your own account, with something you can click on and try at the end of every fortnight.

  4. 04

    Proving it

    Your own people put it through real work with real records, and everything they find is fixed before anybody depends on it.

  5. 05

    Going live

    Your team moves across trained, with their history intact, on the date fixed months earlier.

What happens in each of them

05Asked most often

The questions that come up.

Is this the same as a penetration test?

No. This builds the controls: who reaches what, what gets recorded, how access is granted and removed. Attacking those controls to test them is a separate speciality, and you will get an introduction to a firm that does it properly rather than a claim that it is us.

We are going for ISO 27001. Does this get us there?

It hands you a large part of the evidence as a standing report instead of a scramble before each audit. The certification itself involves policy work beyond the software, and your system will be built to feed whoever is guiding you through it.

Can we see who looked at a record, not just who changed it?

Yes. Where records are sensitive enough to justify it, reading is recorded alongside writing, and you can pull every person who opened a given record and when.

06The rest of it

Most projects are two or three of these at once.

Put a date on it.

Half an hour with whoever would build it gets you the shape of the work, a figure you can take to your board, and the week it could start. No deck, no discovery fee, no follow-up sequence.