Roles, permissions, sessions and policies decide who can do what — and every user and every Flow-Cognition Agent action runs inside them, with a full, immutable audit trail. ISO 27001 certified, DPDP Act 2023 compliant, encrypted in transit and at rest, with all data stored only in India.
ISO 27001 · DPDP Act 2023 · Data in India · RBAC & field-level · Audit trails
Office24by7 is secure by default, not by add-on — the same controls protect your data across all seven pillars.
Our information security management system is certified to the ISO 27001 standard and reviewed on an ongoing basis.
Built for India's Digital Personal Data Protection Act, with retention policies as the operational face of consent and deletion.
All customer data is stored only in India, with no cross-border transfer by default.
Data residency →Role-based access control down to the individual field, so people and agents see only what their job needs.
Roles & permissions →Data is encrypted on the wire and in storage, with session, API key and token controls layered on top.
Every action — by a person or a Flow-Cognition Agent — is logged with who, what, when and why.
Audit trails →Who may do what, and under which rules — enforced on every action.
The essentials your teams reach for every day — each backed by real objects in the platform.
Roles, permission sets and IP allowlists grant exactly the access each person needs.
Manage user sessions, API keys and tokens, and record every security incident.
Password, access, approval and data-retention policies enforced across the platform.
10 objects power Security & Policies. Filter by department or search to find exactly what you need.
Define a named bundle of permissions that users inherit, so access is granted by job, not by person.
Group object- and action-level permissions so they can be granted, audited and revoked as one unit.
Track every active and past login session so anomalous access can be spotted and revoked.
Log, triage and close security events so nothing is noticed and then forgotten.
Issue, scope, rotate and revoke machine credentials so integrations never share a human login.
Restrict where the platform can be reached from, per role or per key.
Set and enforce credential rules — length, rotation, reuse, MFA — across the tenant.
Rules that decide who may reach what, under which conditions — time, location, device.
Define thresholds and approver chains so high-value actions cannot be taken unilaterally.
How long each kind of record is kept before deletion or archival — the operational face of DPDP.
Build table and pivot reports on any object, group and aggregate, then schedule them to land in inboxes automatically.
Flat rows-and-columns grid — one row per record. Best for record-level auditing, raw data review, and exports.
Cross-tabulated matrix with Fields, Columns, and Rows axes. Best for management summaries and cross-dimensional comparison.
A real loop on your Security & Access data — sense, decide, act — grounded in your records and governed by default.
Watches access patterns, sessions and field-level activity across the platform.
Scores risk, spots anomalies and checks policy, permissions and data residency.
Enforces guardrails, flags violations and writes an immutable audit entry.
Five-tier model routing · field-level permissions · full audit trail. See the AI layer →
Every object and report above is live in the platform. Start free, or let us map it to how your team works.
The node categories and agents that power Security. Explore them all in the node catalog.