Customer-managed access
Employees do not create public accounts. Access begins with customer administrator invitations and the roles configured for the tenant.
AlchemyWorkflow is delivered through managed enterprise access and a scoped implementation. The security design connects user roles, integration permissions, workflow controls, human approvals and execution records.
This page describes the intended control model and areas reviewed during implementation. It does not claim certifications, hosting locations, encryption specifications, recovery objectives or identity features that have not been confirmed for the production service.
Employees do not create public accounts. Access begins with customer administrator invitations and the roles configured for the tenant.
Data sources, allowed actions, approval boundaries and operational owners are defined during discovery and recorded in the implementation scope.
Workflows should access and move only the records and fields required for the agreed process.
Customer-facing, financial, legal or otherwise sensitive actions can remain subject to review and approval.
Workflow runs can preserve triggering context, decisions, connected actions, owner assignments, exceptions and completion status.
AlchemyWorkflow configures and operates the service within the agreed scope; customers remain responsible for their users, source data, connected-system authority and business decisions.
Identify the systems involved, data categories, process owners, risk points and required approvals.
Define administrators, workflow owners, operators, reviewers and users who only need visibility.
Confirm authentication method, permission scope, fields used, actions permitted and failure behavior.
Validate normal paths, duplicates, missing data, permission errors, unavailable systems and manual escalation.
Publish the approved configuration and provide customer administrators with the agreed operating controls.
Review access changes, workflow revisions, exceptions and integration behavior as the operating model evolves.
Administrator invitation; role allocation; removal of access when users leave or change responsibility.
Customer administrator with implementation support.
Named ownership; controlled editing and publishing; testing before production release.
Authorized workflow owner and customer administrator.
Tenant-specific authorization; minimum required permissions; documented read and write actions.
Customer system owner and implementation team.
Named reviewer or group; decision status; escalation when approval is delayed or rejected.
Customer-designated business owner.
Trigger context; path selected; action status; exception and assigned owner.
Operational owners according to role.
Retention, export and deletion requirements documented in the applicable agreement and tenant design.
Customer and AlchemyWorkflow under the contract.
Customers should not submit regulated or sensitive categories unless the applicable agreement, architecture and controls expressly support that data.
This website does not claim either certification. Current assurance materials and any customer-specific security requirements should be discussed during the sales and security review process.
Authentication requirements should be confirmed during discovery. They are not represented here as generally available features until the deployment and identity design are agreed.
The exact isolation model must be documented in the order, SOW or security documentation for the customer. The term dedicated tenant does not, by itself, promise a separate cloud account, database or infrastructure stack.
Hosting region, infrastructure provider and any data residency requirement must be confirmed for the actual production deployment and reflected in the agreement and DPA.
No blanket claim is made on this page. Any AI provider, input handling, retention and model-improvement terms must be documented for the services actually enabled in the customer tenant.
Incident contacts, notification commitments and responsibilities should be stated in the signed agreement and the operational procedures applicable to the production service.
We will identify the controls that must be confirmed before the implementation scope is finalized.
Contact Sales