Trust
Every step on record.
Nothing changes without a person.
What RoleAxis logs, what it never does on its own, and what it keeps of your data.
What is logged
- Every step of every action
- Drafted, waiting, approved, rejected, executed, reversed: each change of state is written to a log that is only ever added to. Each entry carries a hash of the one before it in your workspace, so an entry changed or deleted afterwards breaks the chain, and checking the chain finds where.
- Who acted
- A person signed in with their own account is logged by name. The shared workspace key is logged as the shared key. A reversal recorded by a RoleAxis operator is logged as a RoleAxis operator, with who.
- Why
- A rejection carries a note saying why, when your policy asks for one (it does by default). A reversal always carries a note.
- Changes to your policy
- Every change to the workspace policy is logged with who made it, when, and the policy before and after.
What never happens without a person
- Nothing is written to your system without approval
- An agent reads, checks and drafts. A hold, a transfer or an order is written only after the person your policy names approves it.
- Above your threshold, only a signed-in person
- An action worth more than the amount your policy sets (USD 2,000 by default) needs a person signed in with their own account. The shared key cannot approve it. An amount that cannot be read in USD counts as above.
- Tax, bank and master data are out of reach
- Tax rates, journal entries, bank and IBAN details, closed periods and the chart of accounts are never written. Actions of that kind are refused before a draft exists.
- An agent held at recommends stays there
- Your policy can keep any agent to recommendations only, and no agent can be set above what it is built to do.
Your data, in plain words
- What is stored
- The encrypted credential for each connector, each drafted finding with the records it points to (bill numbers, amounts, names), and the log. Stock and ledger tables are read when an agent runs, not copied.
- Workspaces are separate
- Each workspace sees only its own findings, actions and log.
- Disconnecting
- Ask us and we remove a connector and its credential. Your findings and log stay readable until you ask us to delete the workspace. Self-serve disconnect is not built yet.
- The assessment
- The free assessment reads nothing from your systems. It uses only what you type into it.