Process Center · Stage 9 of 20

Access Without Giving Away the Keys

Agents get exactly the access the task requires. You keep the ability to revoke it instantly.

This page exists because "we take security seriously" is a sentence, not a control. Here is what access management actually consists of.

The controls

  • Individual accounts — named per agent wherever your platform supports it, not shared logins
  • Least privilege — access limited to the specific functions the campaign requires, not administrative rights by default
  • Role-based access, where supported — a defined agent role rather than an ad hoc grant
  • Client-controlled permissions — you create the accounts; we do not create our own access into your systems
  • Multi-factor authentication — used wherever your platform offers it
  • Password-manager usage — credentials are not shared over unencrypted channels or written into plain text documents
  • Access logging, where the platform provides it — activity attributable to the individual account
  • Revocation — access removed the moment an agent leaves the campaign or the engagement ends
  • Offboarding — a defined process, not a hope that someone remembers

The access setup checklist

A working document for planning exactly what access a new campaign needs, at the permission level it actually needs it — useful for scoping any outsourced team, not only ours.

Client Access Setup Checklist

Plan exactly what access a new team needs, at the permission level it actually needs it.

Related questions

FAQs on this stage

How is customer data handled?

Agents access only the systems and data the campaign requires, using accounts you create and can revoke. Access is scoped to least privilege, credentials are not shared between agents where your systems support individual accounts, and access is removed when an agent leaves your campaign. Full detail is on our security page.