Security and governance

Evidence that stands up to scrutiny.

Capability data is people data. It is held per organisation, exposed by role, and every decision that changes it leaves a record.

Tenant isolation

Every organisation's data sits behind row-level access rules keyed to the tenant. There is no cross-organisation read path, including for benchmarks, which are aggregated and anonymised before they are shown.

Role-based access

Super admin, organisation admin, manager, capability lead, reviewer, learner and read-only auditor. Navigation, records and exports are all filtered by the permissions attached to the signed-in role.

Approval chains

Workflows move from draft to review to approved. A named reviewer must sign off, and organisations can require a second approval for entries classified as high risk.

Versioning and review dates

Each published change creates a version with full history. Review dates are enforced: content past its date is flagged in the library and excluded from recommendations until it is re-approved.

Restricted data categories

Admins define categories — customer identifiers, health data, unreleased financials — that block publication and warn authors during drafting.

Audit trail

Assessments launched, results moderated, workflows approved, permissions changed and exports generated are all written to an append-only trail available to auditors.