RBAC overview
ReadyRole inventory covers founder, enterprise, customer, partner, vendor, auditor, inspector, security, finance, and operations users.
Production requirement: Map roles to customer IdP groups and enforce route/action scopes server-side.
Tenant isolation status
Security review in progressTenant isolation model is defined with tenant IDs, subsidiaries, departments, locations, and credential metadata.
Production requirement: Enforce row-level security and tenant-scoped secrets in production database and API server.
SSO readiness
Customer access requiredSSO configuration is represented in implementation wizard and schema.
Production requirement: Customer must provide SAML/OIDC metadata, group claims, logout URL, and test users.
Audit logging
Security review in progressWORM audit records, activity feed, and audit-event schema are modeled.
Production requirement: Append immutable records from API actions, connector syncs, exports, and user decisions.
WORM status
Security review in progressWORM records show hashes, previous hashes, chain status, actor, and event type.
Production requirement: Use customer-approved immutable storage and retention controls.
Encryption status
Security review in progressSchema and runtime configuration reference encryption key secret IDs.
Production requirement: Confirm KMS provider, key rotation, field-level encryption requirements, and backup encryption.
Secret storage status
Security review in progressConnector skeletons reference secret IDs only and do not store plaintext credentials.
Production requirement: Configure AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, or customer vault.
API access policy
Security review in progressAPI access is documented as scoped, signed, tenant-aware, and audited.
Production requirement: Implement rate limits, IP allowlists, mTLS where required, and audit logs.
Connector permission policy
Customer access requiredConnector activation center lists required permissions by system.
Production requirement: Customer IT must approve least-privilege scopes for each connector.
Data retention policy
Security review in progressRetention is represented for evidence, WORM records, audit exports, and customer data.
Production requirement: Align retention with customer legal, compliance, and DPA requirements.
Evidence chain integrity
Security review in progressEvidence records include SHA hashes, chain-of-custody, duplicate status, and tenant references.
Production requirement: Hash real uploaded evidence at ingest and bind every decision to WORM audit.