Skip to main content
Oximy applies access at several layers so authentication alone does not grant unrestricted product or data access.

Access layers

1

Workspace membership

The authenticated person must belong to the active organization and Oximy workspace.
2

Product entitlement

The workspace must have access to the requested Visibility, Sidekick, or Relay capability.
3

Role

Administrative changes require the appropriate workspace role. Many configuration, billing, access, and policy actions are administrator-only.
4

Organization scope

Managers receive department-scoped views where supported, while company-wide operations remain restricted.
5

Resource policy

Product-specific grants, approvals, budgets, connector access, and policy rules apply to the requested action.

Product-specific control

  • Visibility scopes organization data and financially sensitive fields.
  • Sidekick applies sharing, tool grants, approvals, execution policy, and workspace configuration.
  • Relay restricts project, key, provider, routing, and limit changes to authorized administrators.

Fail-closed behavior

Oximy denies access when the workspace, product, organization scope, or required role cannot be established. Product services do not treat successful authentication as sufficient authorization.

Auditability

Successful administrative and public API mutations are attributed to the actor and recorded in the workspace audit history. Product activity produces additional evidence within Visibility, Sidekick, and Relay.

Review audit history

Learn what the shared audit log records and how administrators inspect it.