xMatix
Sign in Request demo
xMatix
PRODUCTS
SalesField SalesCRMRewardsClaimsInventoryProcurementWarehouse ManagementField ServiceServiceSupportTelephony & MessagingFinance & AccountingPayrollExpense ManagementCommercePortalsAnalytics & ReportingData StudioMobile AppSee all products →
PLATFORM
Platform overviewApp BuilderAutomationIntegrationsSecurity & GovernanceChange ManagementDevelopers
SENSE AI
Sense AI overviewSense AssistSense ControlSense VisionAI StudioTrust & governanceIn Claude & ChatGPTUse cases
SOLUTIONS
FMCG & DistributionManufacturing & Dealer NetworksAutomotive & DealershipsPharma & HealthcareConsumer DurablesAgri-InputsBuilding MaterialsService NetworksWarehousing & 3PLFinancial AccountingERP SoftwareIndia GST ComplianceUAE VAT & e-InvoicingSaudi ZATCA & VATAll solutions →
RESOURCES
Knowledge CenterDeveloper & CLIBlogGuidesWhat is xMatix?Company facts
COMPANY
AboutCareersPartnersEventsContactAuthorsLegal
Sign in Request demo
PLATFORM · SECURITY & GOVERNANCE

Enterprise security that explains itself.

Not just locked down — legible. Ask why a user can see a record and get an answer, not a support ticket.

THE MECHANISM

"Why can this user see this record?" — drawn end to end.

Every read walks the same decision path — and the verdict can be explained at each step.

PROFILE
entity + field permissions
ROLE HIERARCHY
managers see their line
TEAM
shared work
BUSINESS UNIT
branch scope
ACCESS POLICY
per-entity default
SHARING
explicit exceptions
VERDICT
READ · granted via team share
Warranty claim · WC-2210
OutletApex Mart
Amount8,400
StatusUnder review
Customer phone•••• ••8841MASKED · FIELD-LEVEL SECURITY
HOW IT WORKS
GrantScopeShareExplainAudit
01 · TWO-LAYER ACCESS MODEL

What users can do. What users can see. Separated.

Profiles and field-level permissions govern actions. Record-access policies and ownership govern visibility. Two independent layers — so a permissions change never silently exposes data, and Sense inherits both.

LAYER 1 · CAN DO
Create ordersallowed
Edit price listsdenied
Field: credit limitread-only
LAYER 2 · CAN SEE
Own accountsvisible
Team's territoryvisible
Other regionshidden
National Sales
West BU
Pune team Port team
South BU
South hub team + Partner reps
role hierarchiesrecord sharinginternal vs external
02 · REAL-ORG STRUCTURES

Your org chart, not a permissions puzzle.

Role hierarchies, teams, business units, and record sharing that mirror how the company actually runs — including external audiences like partner reps and distributors, kept firmly outside internal data.

03 · ACCOUNTABILITY

"Why can this user see this record?" Answered.

A full audit trail on every object, a recycle bin with retention, and access diagnostics that trace the exact rule granting visibility — ownership, hierarchy, or share.

Access diagnostics· Record: Meridian Distributors — Invoice #4471
USERROLEACCESS VIALEVEL
Sara KhanFinance HeadRole hierarchy · West BUFull
Ravi K.Field RepRecord ownerEdit
Arjun P.Field RepTeam share · CentralRead
Distributor portalExternalNo matching ruleNone
audit: 214 events on this record · last change 2h ago by priya.sharma
04 · OPERATED FOR THE ENTERPRISE

Run like infrastructure, not a shared spreadsheet.

Isolated environments
Sandbox and production are separate worlds — test data never leaks into the real books.
Per-tenant data isolation
Your data lives in your tenant. Multi-tenant efficiency without multi-tenant exposure.
Immutable release promotion
Changes ship as versioned, promoted releases — auditable, repeatable, reversible.
FOR THE EVALUATORS

For the architects doing the review.

The details an RFP answer needs — all verifiable in a demo.

FIELD-LEVEL PERMISSIONS
Profiles govern entities and individual fields — a user can see the claim but not the customer's phone.
ORG STRUCTURES
Role hierarchies, teams and business units mirror the real org — access follows the chart.
RECORD ACCESS POLICIES
Per-entity defaults plus explicit record sharing for the exceptions.
INTERNAL VS EXTERNAL
Partner reps and distributors are a separate audience with separate default access — never incidental insiders.
DIAGNOSTICS & AUDIT
Access-explanation diagnostics trace the granting rule; a full audit trail and a recycle bin with retention cover the rest.
ISOLATION & LICENSING
Tenant isolation enforced at the data layer; product → feature → capability licensing with usage metering.
EVALUATOR FAQ

The questions your architects will ask.

Your data lives in your own tenant, and isolation is enforced at the data layer — every query the platform runs is scoped to the tenant it serves, so multi-tenant efficiency never becomes multi-tenant exposure. Sandbox and production are separate worlds, so test data never reaches the real books. Production runs in cloud data-centre regions in India, with encrypted backups replicated to a second Indian region; the mechanics are on the Trust Center and the hosting commitments in the Data Processing Addendum.

No. Sense runs as the signed-in user, through the platform's own data services, so record-access policies, field-level permissions, team and role boundaries and tenant isolation apply to it exactly as they apply to that person in the application. There is no privileged AI service account and no side door. When Sense proposes an action it drafts the change and waits for the user's approval, and the tool calls, approval decisions and resulting changes are logged with user and conversation context. How Sense Assist works · Responsible AI.

Configuration changes start in a sandbox clone and ship as reviewed, versioned change sets — promoted to production with undo and drift detection, so a release is auditable, repeatable and reversible. The same discipline governs the admin copilot: Sense Control authors changes inactive and activates them only on your approval. Sandboxes and promotion.

Every object carries a full audit trail — data and configuration — recording who changed what and when. A recycle bin with retention keeps deleted records restorable and auditable, and access diagnostics answer "why can this user see this record?" by tracing the exact rule that grants visibility: ownership, hierarchy or an explicit share. AI activity is on the same trail — tool invocations, approval decisions (grants and refusals) and the changes that followed. Record security.

Partner reps, distributors and customers are a separate audience with their own default access — never incidental insiders. They reach the records you choose through customer, commerce and employee portals on your domain, governed by the same security engine: profiles decide what they can do and see down to the field, record sharing extends access explicitly, visibly and revocably, and nothing they do escapes the audit trail. Roles, teams and business units.

SENSE CONTROL · THE ADMIN COPILOT

Access changes, previewed before they exist.

Describe the change. See exactly who gains access. Approve. Nothing applies without you.

Sense Controlacting as Sara Khan · preview-first · audited
Give the new central service team read access to warranty claims — their own branch only.
Drafted a policy change, with a preview of exactly who gains access:
~ policy  Warranty claims · + read for team Central Servicescope: own business unit
preview  6 users gain read · 0 gain editno external audience affected
Approve & applyEdit firstApplied. Change recorded in the audit trail.
FEATURE HIGHLIGHTS

Everything in Security & Governance.

Profiles & field-level permissions
Down to the single field.
What a role can do and see, declared to the field level — and enforced on every channel.
Role hierarchies
Managers see their line.
Visibility flows down the reporting chain automatically — no per-user grants to maintain.
Teams & business units
Structure that matches the org.
Shared work through teams; hard scope through business units.
Record access policies
Defaults you set per entity.
Private, team, or unit-wide — each entity gets the default the data deserves.
Record sharing
Exceptions, on the record.
Share a specific record across the line — explicitly, visibly, revocably.
Access diagnostics ("explain why")
The verdict, traced.
See the exact rule granting a user access — ownership, hierarchy, policy or share.
Audit trail
Every change, attributed.
Who changed what, when, from where — on data and on configuration alike.
Recycle bin & retention
Deleted isn't destroyed.
Deleted records are held with retention — restorable, and auditable.
External-audience scoping
Outsiders stay outside.
Portal and partner users live in a separate audience with separate defaults.
License & capability metering
Entitlements you can read.
Product → feature → capability licensing, with usage metering per tenant.
MORE OF THE PLATFORM
Change ManagementAutomationDevelopersTrust Center
Platform overview →

See xMatix on your business.

A 30-minute demo, tailored to your industry.

Request a demo