Identity & MFA
Authenticate with configured sign-in methods and MFA policies.
Identity, actor type, permissions, data scope, and operational controls work together. Applications built on SmartWorx use that shared foundation.
Users and contacts have distinct roles and security profiles. Contacts work within their active account; machine access has its own identity and scope.
SmartWorx resolves the applicable configuration into effective access for the actor.
Each layer answers a different access question.
Authenticate with configured sign-in methods and MFA policies.
Keep internal users, external contacts, and their profiles distinct.
Scope work to permitted accounts, with read-only or standard access.
Limit which records each actor can reach for an operation.
Control field visibility, masking, and editability within a record.
Apply related-access rules to supported related record lists.
Control component access and supported application capabilities.
Share user-owned views with users, groups, teams, or business units.
Account access boundaries also cover stored files and folders.
Require AI permission and an assigned policy within organization controls.
Use enterprise identity through Microsoft Entra or configured SmartWorx password sign-in, with MFA and managed session controls.
Authentication policies shape sign-in requirements. Conditional access can apply supported request conditions.
Account, record, field, and application permissions work together.
Example actor: You · Service team · Operations
Control component visibility and supported operations; application configuration uses administrative permissions.
AI access combines organization controls, actor permissions, and an explicitly assigned policy. Supported authoring actions are checked against the destination’s permissions.
Keep the task, permitted context, and human review clear.
Explore AI and human reviewRecorded security activity supports investigation and review.
Illustrative eventTenant context is enforced beyond the application screen.
Cloud-native protections support the platform’s operating boundary.
Review event coverage, retention, monitoring, recovery, and enabled controls for the intended deployment.
Bring your access model, data classification, integrations, audit needs, and recovery objectives.
Compliance and authorization depend on the actual deployment and customer boundary. A cloud provider’s certifications do not automatically certify SmartWorx or a customer application.