+91-40-4033-4444 hello@office24by7.com Hyderabad, Telangana, India

Secure and compliant by default

Roles, permissions, sessions and policies decide who can do what — and every user and every Flow-Cognition Agent action runs inside them, with a full, immutable audit trail. ISO 27001 certified, DPDP Act 2023 compliant, encrypted in transit and at rest, with all data stored only in India.

ISO 27001  ·  DPDP Act 2023  ·  Data in India  ·  RBAC & field-level  ·  Audit trails

Trust & compliance

The controls your security team asks about

Office24by7 is secure by default, not by add-on — the same controls protect your data across all seven pillars.

ISO 27001 certified

Our information security management system is certified to the ISO 27001 standard and reviewed on an ongoing basis.

DPDP Act 2023 compliant

Built for India's Digital Personal Data Protection Act, with retention policies as the operational face of consent and deletion.

Data stays in India

All customer data is stored only in India, with no cross-border transfer by default.

Data residency →

Role & field-level access

Role-based access control down to the individual field, so people and agents see only what their job needs.

Roles & permissions →

Encrypted in transit & at rest

Data is encrypted on the wire and in storage, with session, API key and token controls layered on top.

Full audit trail

Every action — by a person or a Flow-Cognition Agent — is logged with who, what, when and why.

Audit trails →
Products & applications

Four building blocks of a secure workspace

Who may do what, and under which rules — enforced on every action.

Key capabilities

What you can do with Security & Policies

The essentials your teams reach for every day — each backed by real objects in the platform.

Precise access control

Roles, permission sets and IP allowlists grant exactly the access each person needs.

Sessions & keys under control

Manage user sessions, API keys and tokens, and record every security incident.

Govern by policy

Password, access, approval and data-retention policies enforced across the platform.

Object explorer

Every object, one search

10 objects power Security & Policies. Filter by department or search to find exactly what you need.

10 objects

Role

13 fields

Define a named bundle of permissions that users inherit, so access is granted by job, not by person.

Role NameRole CodeParent RoleScopeUsers AssignedOwner+7 more

Permission Set

16 fields

Group object- and action-level permissions so they can be granted, audited and revoked as one unit.

Set NameRoleObjectCreateReadUpdate+10 more

User Session

15 fields

Track every active and past login session so anomalous access can be spotted and revoked.

Session IDUserIP AddressDeviceLocationStarted+9 more

Security Incident

15 fields

Log, triage and close security events so nothing is noticed and then forgotten.

Incident IDTitleSeverityCategoryReported ByOwner+9 more

API Key / Token

14 fields

Issue, scope, rotate and revoke machine credentials so integrations never share a human login.

Key IDLabelOwnerScopeIssuedExpires+8 more

IP Allowlist

12 fields

Restrict where the platform can be reached from, per role or per key.

Entry IDCIDRApplies ToRoleOwnerAdded+6 more

Password Policy

14 fields

Set and enforce credential rules — length, rotation, reuse, MFA — across the tenant.

Policy NameMin LengthRotation DaysReuse BlockedMFA RequiredApplies To Role+8 more

Access Policy

13 fields

Rules that decide who may reach what, under which conditions — time, location, device.

Policy NameRoleConditionEffectResourceOwner+7 more

Approval Policy

14 fields

Define thresholds and approver chains so high-value actions cannot be taken unilaterally.

Policy NameObjectThresholdApproverEscalation HoursOwner+8 more

Retention Policy

14 fields

How long each kind of record is kept before deletion or archival — the operational face of DPDP.

Policy NameObjectRetention DaysAction at ExpiryLegal BasisOwner+8 more
No objects match — try another search or department.
Reports & dashboards

Turn Security & Policies data into decisions

Build table and pivot reports on any object, group and aggregate, then schedule them to land in inboxes automatically.

Table Report

Flat rows-and-columns grid — one row per record. Best for record-level auditing, raw data review, and exports.

Group Count onlyExport: CSV, Excel

Pivot Report

Cross-tabulated matrix with Fields, Columns, and Rows axes. Best for management summaries and cross-dimensional comparison.

Group Count, Avg, Max, Min, Sum, Per (%)Export: CSV, Excel

Dashboards you’ll live in

Access & permission matrix
Who can do what, by role and permission set
Table
Sign-in audit & anomalies
Every session and unusual login activity
Table
Incident log & resolution
Security incidents and time to resolve
Pivot
Policy exceptions
Where password, access or approval rules were overridden
Table
Aggregate:Group CountAvgMaxMinSumPer (%)Schedule:DailyWeeklyMonthlyOnce
The platform

Explore the seven pillars

AI at work

How the Flow-Cognition Agent works in Security & Access

A real loop on your Security & Access data — sense, decide, act — grounded in your records and governed by default.

Sense

Watches access patterns, sessions and field-level activity across the platform.

Decide

Scores risk, spots anomalies and checks policy, permissions and data residency.

Act

Enforces guardrails, flags violations and writes an immutable audit entry.

Five-tier model routing · field-level permissions · full audit trail. See the AI layer →

See Security & Policies in your workflow

Every object and report above is live in the platform. Start free, or let us map it to how your team works.

AI nodes inside

The AI nodes inside Security

The node categories and agents that power Security. Explore them all in the node catalog.