Access & permissions

Everyone sees exactly what they should.
Including your AI.

Role- and division-scoped permissions for every person — and every agent. Least privilege by default, and every action stays on the record.

Per-client isolation Every action audited

The worry

One system. Every client. The wrong eyes are a risk you can’t carry.

“We run five clients out of one place. I need to know — for certain — that the wrong person, or the wrong automation, can’t open the wrong client’s file.”
— What we hear from agency owners

16%

of organisations can actually govern what their AI touches

2026 CISO AI Risk Report

40%

of business apps will have an AI agent inside by end of 2026

Gartner

Every action

on the record — person or agent

How it works

See exactly what someone can do — and why.

Not a wall of checkboxes. A role, a division, and a traceable answer for every person.

Roles, your way

Owner, admin, member — or a custom role. Permissions are action-level: view, create, edit, delete, export.

Divisions = client isolation

Group people and work by client or team. Acme’s division can’t see Globex’s — by default.

Effective permissions, with the receipt

One view shows what a person can actually do, and the role or division each permission came from.

Least privilege by default

New people start with the minimum. You grant up — you don’t walk back.

Your AI, governed

Connekz is scoped like a teammate — not a backdoor.

Put the AI on a task and it works inside the same access rules as a person: it can only touch what that work needs, everything it does lands on the audit log, and you still review and merge.

  1. 1Task assigned to Connekz

    On a project, like any teammate

  2. 2Scoped to that project only

    Same role + division limits as a person

  3. ConnekzEvery action logged · you review

    It opens a PR — you merge

Same rules as people

Role and division scope apply to the agent, too.

Only what the task needs

No standing access to everything — just the resources for the job.

Every action on the record

You can always see what it did, and where.

You can always answer “who did what?”

Every meaningful action — by a person or an agent — is logged with who, what, and when. Searchable when you need it.

Verifiable, not theater

Security we can actually show you.

No badge soup. Here’s what’s true today:

Role + division scoping

Enforced on every resource — for people and agents alike.

AES-256-GCM secret vault

Credentials encrypted at rest and scoped per organisation and per project.

Scoped credentials for the AI

Connekz gets the keys for the job — not the whole keychain.

Full audit trail

Who did what, when — person or agent. Always answerable.

We publish what we actually do — and we’ll add certifications when we’ve genuinely earned them, not before. What Connekz can’t do

Built in. Not a second product to buy.

No identity vendor to wire up, no auth project, no extra seat cost. Access control is part of CNEX-Flow from the first login — for your team and your AI.

On day one

Roles, divisions and audit are there from your first login.

No dev work

No SSO project or authorization layer to build and maintain.

No extra bill

It’s part of the platform — not a separate line item.

Most teams bolt access on later — and pay for it twice.

Three hard rules

Connekz lives by three rules.
Not policy. Code.

You decide what Connekz handles and what needs your sign-off. It works inside your existing rules — never around them.

01Control
Enforced

Only does what you ask.

PR · #t4291
4 min ago

Refactor payment webhook handler

+312 / -48 · 18 tests passing

Awaiting your approval

Review every change, or let the work you trust ship on its own. You set the rules — Connekz follows them.

02Access
Enforced

Only sees what your role sees.

Connekzrunning as your seat
  • Read projects
  • Create tasks
  • Draft emails
  • Approve invoicesowner-only
  • Delete prod datalocked
  • Read other teamsscoped

Sign in and Connekz acts with your exact permissions — if your login can't see it, neither can Connekz. Every teammate gets their own scoped Connekz.

03Honesty
Enforced

Pauses and asks when unsure.

ConnekzConnekz · 2 min agoon #t9821

Need: which Stripe webhook secret to use here? The vault has stripe_webhook_prod and stripe_webhook_test. Reply with the env and I'll continue.

Awaiting your reply

Tuned to ask instead of assume. Hit something ambiguous? Connekz comments on the task and waits.

Want the longer version? Read the build story →

Connekz

Ready when
you are.

Start your free month. See what your team does with Connekz working alongside.

  • 30-day free trial
  • Cancel anytime
Or talk to the team
Re-watch Connekz ship a PR