Roles, limits and a full audit trail.
Multi-tenant governance: nine roles, per-account permissions, feature flags in a three-level cascade, and an audit log with diffs.
Roles and permissions
Nine roles across platform and tenant scope, with per-account customisation of what each role may do. Deny by default, enforced on the server for every request — not hidden in the interface.
Plans, flags and limits
Feature flags resolve system → plan → account. Per-account limits cover users, candidates, assessments, concurrent sessions, storage and API rate.
Audit
Every significant action is recorded with a diff of what changed, who changed it and when.
Support access is granted, not assumed
A platform support engineer cannot enter your account unless you grant an explicit window, which expires on its own. Every impersonation is audited. Most vendors cannot offer you this.
Your own portal address
Brand name and logo on candidate-facing screens, and a self-service vanity subdomain so your candidates sign in at your institution’s own address.
