> ## Documentation Index
> Fetch the complete documentation index at: https://oximy.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Access and governance

> Product entitlements, workspace roles, manager scope, approvals, and auditability across Oximy.

Oximy applies access at several layers so authentication alone does not grant unrestricted product or data access.

## Access layers

<Steps>
  <Step title="Workspace membership">
    The authenticated person must belong to the active organization and Oximy workspace.
  </Step>

  <Step title="Product entitlement">
    The workspace must have access to the requested Visibility, Sidekick, or Relay capability.
  </Step>

  <Step title="Role">
    Administrative changes require the appropriate workspace role. Many configuration, billing, access, and policy actions are administrator-only.
  </Step>

  <Step title="Organization scope">
    Managers receive department-scoped views where supported, while company-wide operations remain restricted.
  </Step>

  <Step title="Resource policy">
    Product-specific grants, approvals, budgets, connector access, and policy rules apply to the requested action.
  </Step>
</Steps>

## Product-specific control

* **Visibility** scopes organization data and financially sensitive fields.
* **Sidekick** applies sharing, tool grants, approvals, execution policy, and workspace configuration.
* **Relay** restricts project, key, provider, routing, and limit changes to authorized administrators.

## Fail-closed behavior

Oximy denies access when the workspace, product, organization scope, or required role cannot be established. Product services do not treat successful authentication as sufficient authorization.

## Auditability

Successful administrative and public API mutations are attributed to the actor and recorded in the workspace audit history. Product activity produces additional evidence within Visibility, Sidekick, and Relay.

<Card title="Review audit history" icon="scroll-text" href="/docs/platform/audit-history">
  Learn what the shared audit log records and how administrators inspect it.
</Card>
