xMatix
Sign in Request demo
xMatix
PRODUCTS
SalesField SalesCRMRewardsClaimsInventoryProcurementWarehouse ManagementField ServiceServiceSupportTelephony & MessagingFinance & AccountingPayrollExpense ManagementCommercePortalsAnalytics & ReportingData StudioMobile AppSee all products →
PLATFORM
Platform overviewApp BuilderAutomationIntegrationsSecurity & GovernanceChange ManagementDevelopers
SENSE AI
Sense AI overviewSense AssistSense ControlSense VisionAI StudioTrust & governanceIn Claude & ChatGPTUse cases
SOLUTIONS
FMCG & DistributionManufacturing & Dealer NetworksAutomotive & DealershipsPharma & HealthcareConsumer DurablesAgri-InputsBuilding MaterialsService NetworksWarehousing & 3PLFinancial AccountingERP SoftwareIndia GST ComplianceUAE VAT & e-InvoicingSaudi ZATCA & VATAll solutions →
RESOURCES
Knowledge CenterDeveloper & CLIBlogGuidesWhat is xMatix?Company facts
COMPANY
AboutCareersPartnersContactAuthorsLegal
Sign in Request demo
PLATFORM · SECURITY & GOVERNANCE

Enterprise security that explains itself.

Not just locked down — legible. Ask why a user can see a record and get an answer, not a support ticket.

THE MECHANISM

"Why can this user see this record?" — drawn end to end.

Every read walks the same decision path — and the verdict can be explained at each step.

PROFILE
entity + field permissions
ROLE HIERARCHY
managers see their line
TEAM
shared work
BUSINESS UNIT
branch scope
ACCESS POLICY
per-entity default
SHARING
explicit exceptions
VERDICT
READ · granted via team share
Warranty claim · WC-2210
OutletApex Mart
Amount8,400
StatusUnder review
Customer phone•••• ••8841MASKED · FIELD-LEVEL SECURITY
HOW IT WORKS
GrantScopeShareExplainAudit
01 · TWO-LAYER ACCESS MODEL

What users can do. What users can see. Separated.

Profiles and field-level permissions govern actions. Record-access policies and ownership govern visibility. Two independent layers — so a permissions change never silently exposes data, and Sense inherits both.

LAYER 1 · CAN DO
Create ordersallowed
Edit price listsdenied
Field: credit limitread-only
LAYER 2 · CAN SEE
Own accountsvisible
Team's territoryvisible
Other regionshidden
National Sales
West BU
Pune team Port team
South BU
South hub team + Partner reps
role hierarchiesrecord sharinginternal vs external
02 · REAL-ORG STRUCTURES

Your org chart, not a permissions puzzle.

Role hierarchies, teams, business units, and record sharing that mirror how the company actually runs — including external audiences like partner reps and distributors, kept firmly outside internal data.

03 · ACCOUNTABILITY

"Why can this user see this record?" Answered.

A full audit trail on every object, a recycle bin with retention, and access diagnostics that trace the exact rule granting visibility — ownership, hierarchy, or share.

Access diagnostics· Record: Meridian Distributors — Invoice #4471
USERROLEACCESS VIALEVEL
Sara KhanFinance HeadRole hierarchy · West BUFull
Ravi K.Field RepRecord ownerEdit
Arjun P.Field RepTeam share · CentralRead
Distributor portalExternalNo matching ruleNone
audit: 214 events on this record · last change 2h ago by priya.sharma
04 · OPERATED FOR THE ENTERPRISE

Run like infrastructure, not a shared spreadsheet.

Isolated environments
Sandbox and production are separate worlds — test data never leaks into the real books.
Per-tenant data isolation
Your data lives in your tenant. Multi-tenant efficiency without multi-tenant exposure.
Immutable release promotion
Changes ship as versioned, promoted releases — auditable, repeatable, reversible.
FOR THE EVALUATORS

For the architects doing the review.

The details an RFP answer needs — all verifiable in a demo.

FIELD-LEVEL PERMISSIONS
Profiles govern entities and individual fields — a user can see the claim but not the customer's phone.
ORG STRUCTURES
Role hierarchies, teams and business units mirror the real org — access follows the chart.
RECORD ACCESS POLICIES
Per-entity defaults plus explicit record sharing for the exceptions.
INTERNAL VS EXTERNAL
Partner reps and distributors are a separate audience with separate default access — never incidental insiders.
DIAGNOSTICS & AUDIT
Access-explanation diagnostics trace the granting rule; a full audit trail and a recycle bin with retention cover the rest.
ISOLATION & LICENSING
Tenant isolation enforced at the data layer; product → feature → capability licensing with usage metering.
EVALUATOR FAQ

The questions your architects will ask.

How is tenant data isolated?+
Does the AI assistant bypass record access?+
How are changes promoted to production?+
What does the audit trail capture?+
How do external users access shared records?+
SENSE CONTROL · THE ADMIN COPILOT

Access changes, previewed before they exist.

Describe the change. See exactly who gains access. Approve. Nothing applies without you.

Sense Controlacting as Sara Khan · preview-first · audited
Give the new central service team read access to warranty claims — their own branch only.
Drafted a policy change, with a preview of exactly who gains access:
~ policy  Warranty claims · + read for team Central Servicescope: own business unit
preview  6 users gain read · 0 gain editno external audience affected
Approve & applyEdit firstApplied. Change recorded in the audit trail.
FEATURE HIGHLIGHTS

Everything in Security & Governance.

Profiles & field-level permissions
Down to the single field.
What a role can do and see, declared to the field level — and enforced on every channel.
Role hierarchies
Managers see their line.
Visibility flows down the reporting chain automatically — no per-user grants to maintain.
Teams & business units
Structure that matches the org.
Shared work through teams; hard scope through business units.
Record access policies
Defaults you set per entity.
Private, team, or unit-wide — each entity gets the default the data deserves.
Record sharing
Exceptions, on the record.
Share a specific record across the line — explicitly, visibly, revocably.
Access diagnostics ("explain why")
The verdict, traced.
See the exact rule granting a user access — ownership, hierarchy, policy or share.
Audit trail
Every change, attributed.
Who changed what, when, from where — on data and on configuration alike.
Recycle bin & retention
Deleted isn't destroyed.
Deleted records are held with retention — restorable, and auditable.
External-audience scoping
Outsiders stay outside.
Portal and partner users live in a separate audience with separate defaults.
License & capability metering
Entitlements you can read.
Product → feature → capability licensing, with usage metering per tenant.
MORE OF THE PLATFORM
Change ManagementAutomationDevelopersTrust Center
Platform overview →

See xMatix on your business.

A 30-minute demo, tailored to your industry.

Request a demo