Ceejay Intelligence logo
    What we build

    Users and permissions you can actually explain.

    Control exactly what customers, employees, managers and administrators can see and do, enforced in the database rather than hidden in the interface.

    • Role based access
    • Two factor authentication
    • Audit trails
    • Data isolation
    Users and permissions you can actually explain.

    Shared logins and hidden buttons are not security

    Plenty of systems control access by hiding menu items and sharing an admin password. Both approaches fail the first time somebody is curious, leaves the business or makes an honest mistake.

    • One admin account used by several people, so nothing is attributable.
    • Staff able to see salaries, margins or other customers' data by accident.
    • Leavers keeping access for months because nobody owns offboarding.
    • No record of who changed or deleted a record when it matters.

    How we build it

    We model the roles in your organisation, then enforce them at every layer, so what a user can reach is decided by the server and the database, not by the screen they are looking at.

    • Named accounts for every person, with roles rather than shared passwords.
    • Database level policies so unauthorised data never leaves the server.
    • Two factor authentication and single sign on where you need them.
    • Full audit trail of logins, changes and administrative actions.
    What you get

    Everything included, nothing bolted on

    No plugin marketplace, no upsells. Each point below ships with the plan.

    Role based permissions

    Role based permissions

    Define roles like staff, manager, finance, admin and client, and assign precisely.

    Per record access

    Per record access

    Restrict by team, branch, region or account so people see only their scope.

    Two factor authentication

    Two factor authentication

    Optional or enforced by role, with recovery handled properly.

    Single sign on

    Single sign on

    Sign in with Google or Microsoft accounts so access follows your existing directory.

    Joiners and leavers

    Joiners and leavers

    Invite, suspend and remove users in seconds, with sessions revoked immediately.

    Audit logging

    Audit logging

    Who logged in, what they changed and when, retained for as long as you need.

    Row level
    Security enforced in the database
    Named
    Accounts, never shared logins
    from £2,995
    One off build cost

    Enforced where it counts

    Hiding a button stops an honest user; it does not stop a crafted request. Our applications apply row level security policies in the database, so a query for another team's data returns nothing regardless of how it was made. The interface then simply reflects those rules.

    Roles that match how you actually work

    Real organisations rarely fit three tiers. Someone covers two roles, a branch manager needs their branch only, finance needs everything but should not edit operational records. We model those realities during discovery so permissions do not have to be worked around within a month of launch.

    Evidence for clients and auditors

    Access reviews, security questionnaires and incident investigations all need the same thing: a reliable record. Audit logging is built in from the start, covering authentication and data changes, so producing that evidence is a search rather than a scramble.

    Before you ask

    The questions people actually send us

    Need access control you can evidence?

    Tell us who needs to see what and we will design the permission model with you.