Platform & admin

CRM security where everyone sees exactly what they should

CRM security in DigiPix Flow starts with roles, which decide what a person can do; data scope decides whose records they see, and an append-only audit trail records who changed what. Sign-in is protected with multi-factor authentication, and you can hold access to the offices and networks you trust.

  • Custom roles, permission by permission
  • Own, team or everything — scope per role
  • An append-only audit trail you can export
An example of the DigiPix Flow Roles and access settings page for Deepak Kulkarni, listing the Org admin, Sales manager, Sales rep and Finance roles. The Sales rep role is open, and its permissions are shown one per row. Export contacts is turned off, the role's data scope is changed from Everything to Own records, and multi-factor sign-in is then enforced for everyone in the workspace. Each change appears in the append-only audit trail beneath, with who made it and when.
available on every plan, and enforceable
MFA
data scopes: own records, the team's, everything
3
audit trail, append-only, exportable to CSV
1

What access is built from

  • RolesStandard roles, or your own built permission by permission
  • Data scopeOwn records, the team's records, or everything
  • Multi-factor sign-inA second factor at sign-in, enforceable for everyone
  • Audit trailEvery change recorded, and nothing overwritten
  • IP restrictionsHold sign-in to the networks you trust
  • Erasure and retentionDelete a person's data, keep what law requires
THE PROBLEM

What one level of access costs

See how it's fixed
  1. Everyone can see everything

    A new rep joins and, on day one, can open every deal in the company, export the whole contact list and change a price that finance signed off. Nobody intended it — it is just what happens when a CRM has one level of access.

  2. Nobody can say who changed it

    A deal's value is different from the number in last week's report, an owner has moved, and a contact is marked do-not-contact. Three people say it was not them, and there is no record that settles it.

  3. A leaver still has the keys

    Someone leaves and their sign-in still works, their records still sit under their name, and the export they took last month is on a laptop nobody controls. Deactivating them is only half the job.

ROLES AND PERMISSIONS

Build the role, permission by permission

Start from the standard roles and change what you need, or build your own. Each permission is a separate switch — viewing, creating, editing, deleting, exporting and approving are all decided on their own, so the person who can send a proposal is not automatically the person who can discount it.

  • Standard roles for owner, admin, manager and rep
  • Custom roles, with every permission set on its own
  • Export held separately from view, so reading is not taking
  • A role change takes effect the next time the person acts
WHO SEES WHAT

Own records, the team's, or everything

Permissions say what someone may do; scope says which records they may do it to. A rep works on their own leads and deals, a manager sees their whole team's, and an admin sees everything — with the same role definition behind all three.

  • Scope set per role: own, team, or everything
  • Managers inherit the records of the team beneath them
  • Lists, search and reports all respect the same scope
  • A record outside your scope is not in your export either
SIGN-IN

Two-factor authentication, and the networks you trust

Multi-factor authentication is available on every plan and can be enforced for everyone in the workspace, so a password on its own is never enough. Sign-in can also be held to the IP addresses you name, which keeps the workspace on your office network and off an unknown one.

  • MFA on every plan, and enforceable workspace-wide
  • IP restrictions checked when someone signs in
  • Sessions can be ended for a person who has left
  • Sign-in attempts are recorded, successful or not
AUDIT TRAIL

Append-only, so the record settles it

Every change worth arguing about is written to the audit trail: who did it, what it was before, what it became and when. Entries are appended and never edited, and the trail can be exported to CSV when someone outside the team needs to see it.

  • Record changes, role changes and exports all recorded
  • Entries appended, never rewritten or removed
  • Filter by person, by record or by date
  • Export to CSV for an auditor or a customer's review
RETENTION AND ERASURE

Keep what you must, delete what you should

Data you can export whenever you want, retention that follows your plan rather than a support ticket, and a real erasure path when a customer asks to be forgotten — with the records law requires you to keep held back deliberately rather than by accident.

  • Export your records at any time
  • Customer-visible audit retention set by plan
  • Erasure removes a person's data across the workspace
  • Consent history and billing records kept as law requires
How data deletion works
HOW IT WORKS

Setting it up

  1. STEP 01

    Decide the roles

    Start from the standard roles and change only what your team needs.

  2. STEP 02

    Set the scope

    Give each role its own, the team's, or every record.

  3. STEP 03

    Turn on MFA

    Require a second factor for everyone, not just the people who opt in.

  4. STEP 04

    Watch the trail

    Check the audit trail when a number changes, and export it when asked.

THE DIFFERENCE

Against a CRM with one level of access

What it coversA CRM with one level of accessDigiPix Flow
What a rep can seeEvery record in the companyTheir own, or their team's, by role
Exporting the databaseAnyone who can view can exportA separate permission, off by default
Who changed a dealNobody knowsRecorded, with before and after
A person leavesThe account lingersDeactivate, end sessions, keep the record
An auditor asksScreenshotsFilter the trail and export CSV
INTEGRATIONS

The same rules outside the app

The same permissions apply outside the app: API clients and webhooks act with the access you grant them, and nothing else.

Security questions

Do you support SAML single sign-on?

Not yet. Sign-in today is email and password with multi-factor authentication, which can be enforced for everyone in the workspace. SAML SSO and SCIM provisioning are planned for Enterprise but are not available, and we would rather say so than let you plan around them.

Can we stop people exporting the database?

Yes. Exporting is its own permission, separate from viewing, so a role can read the records it is scoped to without being able to take them out. Exports are written to the audit trail with who ran them.

What is recorded in the audit trail?

Changes to records, role and permission changes, exports, and sign-in activity — each with the person, the time, and what the value was before and after. Entries are appended and never edited, and the trail can be exported to CSV.

Can we limit where the workspace can be used from?

You can restrict sign-in to the IP addresses you name, which keeps access on your own networks. The check runs when someone signs in rather than on every request, so treat it as a boundary at the door, not a lock on every drawer.

How long do you keep our data?

Your records stay while your workspace is active, and you can export them whenever you want. Customer-visible audit retention depends on your plan. Consent history, data-erasure records and billing records follow legal retention instead, so they outlive a plan change.

What happens when someone leaves the company?

Deactivate them: their sign-in stops working and their sessions end, while their records, notes and history stay on the workspace under their name. Their seat is freed for the next person, and the change is in the audit trail.

Something we haven't covered? Talk to an expert

Give everyone exactly the access they need

Talk to us about roles, scope and what your auditors ask for.

  • MFA on every plan
  • Custom roles and data scope on Advanced
  • Audit export and IP restrictions on Enterprise
Talk to an expert