Every read walks the same decision path — and the verdict can be explained at each step.
Profiles and field-level permissions govern actions. Record-access policies and ownership govern visibility. Two independent layers — so a permissions change never silently exposes data, and Sense inherits both.
Role hierarchies, teams, business units, and record sharing that mirror how the company actually runs — including external audiences like partner reps and distributors, kept firmly outside internal data.
A full audit trail on every object, a recycle bin with retention, and access diagnostics that trace the exact rule granting visibility — ownership, hierarchy, or share.
The details an RFP answer needs — all verifiable in a demo.
Your data lives in your own tenant, and isolation is enforced at the data layer — every query the platform runs is scoped to the tenant it serves, so multi-tenant efficiency never becomes multi-tenant exposure. Sandbox and production are separate worlds, so test data never reaches the real books. Production runs in cloud data-centre regions in India, with encrypted backups replicated to a second Indian region; the mechanics are on the Trust Center and the hosting commitments in the Data Processing Addendum.
No. Sense runs as the signed-in user, through the platform's own data services, so record-access policies, field-level permissions, team and role boundaries and tenant isolation apply to it exactly as they apply to that person in the application. There is no privileged AI service account and no side door. When Sense proposes an action it drafts the change and waits for the user's approval, and the tool calls, approval decisions and resulting changes are logged with user and conversation context. How Sense Assist works · Responsible AI.
Configuration changes start in a sandbox clone and ship as reviewed, versioned change sets — promoted to production with undo and drift detection, so a release is auditable, repeatable and reversible. The same discipline governs the admin copilot: Sense Control authors changes inactive and activates them only on your approval. Sandboxes and promotion.
Every object carries a full audit trail — data and configuration — recording who changed what and when. A recycle bin with retention keeps deleted records restorable and auditable, and access diagnostics answer "why can this user see this record?" by tracing the exact rule that grants visibility: ownership, hierarchy or an explicit share. AI activity is on the same trail — tool invocations, approval decisions (grants and refusals) and the changes that followed. Record security.
Partner reps, distributors and customers are a separate audience with their own default access — never incidental insiders. They reach the records you choose through customer, commerce and employee portals on your domain, governed by the same security engine: profiles decide what they can do and see down to the field, record sharing extends access explicitly, visibly and revocably, and nothing they do escapes the audit trail. Roles, teams and business units.