Security & Access
RBAC with entity-scoped permissions — data segregation enforced FDD-36 / FDD-52
SSO (SAML 2.0)
Operational · IdP: Entra ID · last sync 4 min ago
MFA Enforcement
100% of 214 staff accounts · TOTP + WebAuthn
Access Reviews
Q3 recertification — 12 of 18 role owners complete
DATA SEGREGATION PRINCIPLE Sec. 36
Entity-specific operational data (subscribers, network inventory, billing accounts) is never visible across entities except through explicitly shared modules like CRM and Finance.
RBAC Permission Grid — access level per module; entity scope limits data visibility
ROLE
ENTITY SCOPE
CRM
FINANCE
FIBER OPS
WIRELESS OPS
PROCUREMENT
{{ r.name }}
{{ r.users }} users
{{ r.scope }}
{{ p.label }}
Entity-scoped roles cannot read the other entity's customer, billing or network data — enforced at the data layer per Section 36.