Access layers
1
Workspace membership
The authenticated person must belong to the active organization and Oximy workspace.
2
Product entitlement
The workspace must have access to the requested Visibility, Sidekick, or Relay capability.
3
Role
Administrative changes require the appropriate workspace role. Many configuration, billing, access, and policy actions are administrator-only.
4
Organization scope
Managers receive department-scoped views where supported, while company-wide operations remain restricted.
5
Resource policy
Product-specific grants, approvals, budgets, connector access, and policy rules apply to the requested action.
Product-specific control
- Visibility scopes organization data and financially sensitive fields.
- Sidekick applies sharing, tool grants, approvals, execution policy, and workspace configuration.
- Relay restricts project, key, provider, routing, and limit changes to authorized administrators.
Fail-closed behavior
Oximy denies access when the workspace, product, organization scope, or required role cannot be established. Product services do not treat successful authentication as sufficient authorization.Auditability
Successful administrative and public API mutations are attributed to the actor and recorded in the workspace audit history. Product activity produces additional evidence within Visibility, Sidekick, and Relay.Review audit history
Learn what the shared audit log records and how administrators inspect it.