Trust by design

Shared software, strong organizational boundaries.

WorkBox combines centralized control with explicit tenant, module and business-scope enforcement.

A controlled foundation

Trust at every layer of the operation

Identity, isolation and authorization work together so users see and change only what belongs to their organization and responsibilities.

Microsoft Entra ID

Primary identity with explicit tenant membership and active organization selection.

Database per tenant

Each customer organization has its own bounded application database.

Dedicated tenant storage

Operational files remain within a dedicated container resolved from the trusted tenant catalog.

Roles and permissions

Access is checked by organization, module, role, permission and applicable business scope.

Module entitlements

Capabilities are enabled centrally and enforced consistently across the interface, APIs and jobs.

Audit and managed secrets

Relevant actions remain traceable while credentials stay outside source code and ordinary settings.

Defence in depth

Boundaries stay explicit from sign-in to background work

The same trust model applies across user interactions, APIs, jobs and operational files.

Identity before access

Authentication establishes the user; tenant membership determines the organizational context.

Entitlement before capability

A module must belong to the organization before its roles and permissions can grant access.

Scope before data

Business-level scope narrows access within the active organization and module.

Audit after action

Relevant changes remain attributable and reviewable across operational workflows.

Want to discuss your security requirements?

We can explain how WorkBox boundaries map to your organization.

Request a technical discussion