Security guidance

Access and tenant isolation

Understand how organisation membership, roles and server-side controls scope access.

FOR
Organisation administrator, Auditor, Everyone
OUTCOME
Use RAQOZ to understand how organisation membership, roles and server-side controls scope access.

Before you begin

  • Access only to the organisation and records you are authorised to review.

Guidance

  1. 1

    Use a separate authenticated identity for every person; never share passwords or one-time codes.

  2. 2

    Confirm membership and role changes are made in the intended organisation.

  3. 3

    Treat hidden navigation as usability only; server-side and data-layer checks are the security boundary.

  4. 4

    Report suspected cross-tenant or unauthorised access immediately and avoid redistributing exposed data.

Evidence RAQOZ retains

  • Organisation membership
  • Role and access events
  • Tenant-scoped source records

Common issues

Unauthorised or cross-tenant access is suspected.

Stop sharing or exporting the affected data, preserve the relevant time and record details, and report the incident through the authorised support or security channel.

A document must be sent outside RAQOZ.

Use the organisation's approved export and secure-transfer process. Protect the file after download and retain the review purpose.

Related articles

Last reviewed 2 September 2026. Review against the current production release before relying on exact screen behavior.