Connect the company without losing control of it.
Give teams one connected system for work, clients, people, finance and communications, with central identity, policy, audit and data controls.
Reduce fragmentation without creating a larger risk.
A connected platform is valuable because it can relate work across teams. That same connection demands stronger boundaries. nineloops lets administrators manage organisation policy, identity and usage without automatically reading confidential workspace content.
- One system, many modules
- Spaces, Docs, CRM, People, Finance, Distribute, Studio and Monitoring run on shared identity and data, with Chat, Automations, WhatsApp and company Search across the top.
- Central control, local autonomy
- An organisation can standardise policy while each workspace still manages its own projects, records and operations day to day.
- Boundaries by design
- Administrators govern the company without inheriting a right to read every document, deal or message inside it.
Structure the company the way it actually runs.
Model the parent organisation, the teams beneath it and the workspaces where work happens, then apply policy from the top.
- Organisation and units
- Manage a parent organisation, subsidiaries and business units, with workspaces nested underneath so structure mirrors how teams report.
- Domains, billing and entitlements
- Verify domains, run central billing and assign module entitlements so each workspace gets the modules it needs and nothing it does not.
- Groups and delegated admins
- Apply regional policy, manage shared groups and delegate administration so large organisations stay governed without a single bottleneck.
Give people the access their role requires.
nineloops evaluates every request against identity, membership, role, group, entitlement, record visibility and field sensitivity. A hidden menu is not a security control. The database, files, realtime events, Search and server actions enforce the same decision.
- Enterprise identity
- Sign in with SAML SSO or OpenID Connect, provision and deprovision through SCIM, and map directory groups to roles so leavers lose access automatically.
- Session and lifecycle policy
- Enforce MFA, set session policy, review active sessions, run service accounts for connections and keep break glass administration for emergencies.
- Layered authorisation
- Access is decided across organisation and workspace membership, module entitlement, role, group, resource relationship, record state and any billing restriction.
Explain access, govern data and prove what happened.
Authorised security teams can see why access exists, control the data lifecycle and trace every action, without the explorer revealing the restricted content itself.
- Permission explorer
- Answer why a user can see a record, which group grants it, which guest links remain active, who can approve an action and what would change if a person moved teams.
- Data governance
- Apply classification, retention and legal hold, manage exports and deletion, control downloads and watermarking, and choose regional storage with published subprocessor information.
- Audit and support access
- Audit records capture actor, action, record, previous and new state, time, workspace and session. Support access is customer approved, time limited, scope limited, visible, revocable and audited.
Roll out with confidence and run with assurance.
Test changes safely, deploy with approval and follow a structured rollout so the platform lands cleanly across the organisation.
- Sandbox and change management
- Use sandbox workspaces, clone configuration, draft policy changes, preview permissions, simulate automations, require deployment approval and roll back from change history.
- Reliability commitments
- A public status page, service health, incident severity, customer communication, backup monitoring, restore testing, defined recovery objectives, change management and release notes.
- Structured implementation
- Discovery, data and process mapping, identity setup, permission design, workspace structure, migration, integrations, templates, pilot, training, governance handover and a success review.
Questions
- Can administrators read confidential workspace content?
- No. nineloops separates organisation administration from content access. Administrators manage identity, policy, entitlements and usage, but seeing a document, deal or message still requires the same authorisation as everyone else.
- How does single sign on and provisioning work?
- Sign in with SAML SSO or OpenID Connect, and provision or deprovision people through SCIM. Directory groups can map to roles, so access updates automatically as people join, move or leave.
- Is a hidden menu treated as security?
- No. Hiding an option in the interface is not a control. nineloops enforces the same access decision in the database, files, realtime events, Search and server actions.
- What does support access look like?
- Support access is customer approved, time limited, scope limited, visible to you, revocable and recorded in the audit trail, so no one reaches your data without your consent and a record.
Bring one cross team process to the enterprise demo.
We will map the people, systems, approvals and data boundaries, then show how nineloops can connect the process without removing control.