Skip to content

Security · Policies, approvals, and audit history

Security

Control access, route sensitive decisions, and preserve the evidence behind every change.

Read the technical documentation
Policy and access controls in a Norbital workspace

Policies

Policies decide which records, fields, actions, and apps each team can use. Row-level conditions and field redaction make access specific enough for real operations, and the same rules apply in every interface and server action.

Approvals

Approval gates hold sensitive changes under review until the right reviewer decides. A rejection records the decision but does not rewrite history or restore prior values: the changed record remains locked with the written values until revised. A request for change keeps the decision and its context visible.

Audit history

Every mutation leaves a durable trail of who changed what and when. Operational records stay easy to use while audit events and record revisions preserve the evidence behind them.

  • Reusable grants for collection actions, fields, and app visibility
  • One governing policy per team, evaluated on every request
  • Versioned records that make approval and rollback defensible

Continue through the product

Logic

Keep business rules and connected actions inside the governed runtime.