01 · Identity
The user and tenant are resolved before the record is loaded.
Permission in Genedar is applied at the record, not at the page. A user sees the part of the client record their tenant, role, business unit and commercial visibility allow.
Every user-initiated write leaves evidence. Every grant and revocation stays on file, turning an access review into a matter of reading rather than remembering.
The user and tenant are resolved before the record is loaded.
The requested capability is checked against the configured access matrix.
Business-unit and commercial visibility narrow the accessible records.
The write is attributed to the user and recorded in the audit history.
An MCP token belongs to exactly one user and inherits that user’s scope, so connecting a model never widens access. Raw tokens are shown once, stored hash-only, can be revoked and show their last use.
Agent writes travel through the same permission-aware services as human writes and produce the same audit evidence. There is no separate, unlogged automation channel.
An audit entry that names the application instead of the person proves that something happened, and nothing else. A write made on somebody's behalf carries their name, including where it leaves the platform.
A write that leaves the platform used to arrive as the application. Saves from the Markdown editor, the real-time collaboration session and the AI document tools are now written in the editing user's own Microsoft identity, so SharePoint's own "Modified by" names the person rather than genedar, and PDF and DOCX exports are credited to whoever asked for them. Where a user has not signed in with Microsoft, the save goes through under the app identity, which is the honest answer rather than a borrowed name.
Leaving is a permission event, not a directory edit. Deactivating a genedar user removes their consultant profile from the People directory and from staffing searches in the same step, so somebody who no longer works here cannot be offered to a customer. Restoring the user brings the profile back, unless it had already been removed separately.
The moment a system writes an assessment of a colleague, the question stops being who can open the screen and becomes who can read the sentence.
The automatic intake writes an opinion about people: how well a consultant covers a request, which must-have is only partly met, what the evidence for that reading was. Those assessments are not stored as a flag some screen remembers to hide. They live behind commercial visibility, which means the note and the field are simply not returned to a caller outside it.
The consequence is the one that matters: the consultant being proposed can hold access to the deal, read the request and work the engagement, and still never read the assessment of them. The same rule is applied in the list, on the record, in the assistant and over MCP, because all four go through the same permission-aware services.
Pick a role in your agency and we will show exactly what that person can see, change and leave behind in the audit log.