Roles & Security

Access is granted by role, not by exception. Every action is attributable, and the security posture is built for a regulated social housing provider.

RBAC enforced

Roles defined

6

Administrator through tenant

Staff accounts

17

Across compliance and field teams

MFA adoption

92%

Available for every account

Data residency

UK

UK South · UK West failover

Roles

What each role exists to do, and what it can reach

Administrator

3 users

System configuration, users and reference data.

  • Manage users and roles
  • Configure notification templates
  • Maintain reference data
  • View full audit trail

Compliance Manager

4 users

Portfolio-level compliance oversight and reporting.

  • View every discipline and dashboard
  • Approve certificates
  • Own non-compliance escalation
  • Export board reporting

Electrical Manager

2 users

Day-to-day operational oversight of the electrical programme.

  • Manage the electrical programme
  • Approve certificates
  • Escalate contractors
  • Rebalance QA workload

QA Officer

5 users

Certificate review, approval and escalation.

  • Work the QA queue
  • Raise, override and resolve findings
  • Request corrections from contractors
  • Hand off to manager approval

Engineer / Contractor

41 users

Certificate creation and on-site QR linking.

  • Submit certificates
  • Respond to findings
  • Attach remedial evidence
  • Link QR codes on site

Tenant

12,046 users

Self-service certificate access via QR code.

  • View own certificates
  • Download own certificates

Permission matrix

Capability by role — the same rules the UI enforces

CapabilityAdministratorCompliance ManagerElectrical ManagerQA OfficerEngineer / ContractorTenant
Property recordFullFullEditViewView
Certificate repositoryFullFullFullEditEditView
QA workbenchViewFullFullFull
Manager approvalViewFullFull
Non-compliance registerViewFullFullEditEdit
Audit trailFullViewViewView
Administration consoleFull

Security controls

Enterprise controls expected of a regulated provider

  • Role-Based Access Control

    Every user sees only what their role permits, from tenant to executive.

    Implemented
  • Multi-Factor Authentication

    Available for all user accounts.

    Implemented
  • Azure AD / Microsoft Entra SSO

    Built to integrate with LHP's existing identity provider.

    Ready
  • Encryption

    Data encrypted in transit and at rest.

    Implemented
  • Audit Logs

    Every action logged and attributable, underpinning the Audit Trail module.

    Implemented
  • Password Policies

    Configurable complexity, expiry and lockout rules.

    Configurable
  • Session Management

    Automatic timeout and secure session handling.

    Implemented
  • Backups

    Scheduled, tested backups with defined recovery points.

    Implemented
  • Disaster Recovery

    Documented recovery plan and recovery time objectives.

    Documented
  • GDPR

    Data handling aligned to UK GDPR requirements.

    Aligned
  • UK Data Residency

    Hosted on UK-based infrastructure.

    Implemented
  • Secure APIs

    All integrations authenticated and encrypted.

    Implemented
  • Monitoring

    Ongoing security monitoring and alerting.

    Implemented

Posture at a glance

The numbers an auditor asks for first

Encryption in transit
TLS 1.3
Encryption at rest
AES-256
Recovery point objective
15 minutes
Recovery time objective
4 hours
Last penetration test
12 June 2026
Last restore test
3 July 2026
Hosting
UK South · UK West failover

Single sign-on through Microsoft Entra ID can be enabled without changing how roles are assigned — the platform maps directory groups onto the roles above.