Security guidance
Access and tenant isolation
Understand how organisation membership, roles and server-side controls scope access.
- FOR
- Organisation administrator, Auditor, Everyone
- OUTCOME
- Use RAQOZ to understand how organisation membership, roles and server-side controls scope access.
Before you begin
- Access only to the organisation and records you are authorised to review.
Guidance
- 1
Use a separate authenticated identity for every person; never share passwords or one-time codes.
- 2
Confirm membership and role changes are made in the intended organisation.
- 3
Treat hidden navigation as usability only; server-side and data-layer checks are the security boundary.
- 4
Report suspected cross-tenant or unauthorised access immediately and avoid redistributing exposed data.
Evidence RAQOZ retains
- Organisation membership
- Role and access events
- Tenant-scoped source records
Common issues
Unauthorised or cross-tenant access is suspected.
Stop sharing or exporting the affected data, preserve the relevant time and record details, and report the incident through the authorised support or security channel.
A document must be sent outside RAQOZ.
Use the organisation's approved export and secure-transfer process. Protect the file after download and retain the review purpose.
Related articles
Last reviewed 2 September 2026. Review against the current production release before relying on exact screen behavior.