Roles & Security
Access is granted by role, not by exception. Every action is attributable, and the security posture is built for a regulated social housing provider.
Roles defined
6
Administrator through tenant
Staff accounts
17
Across compliance and field teams
MFA adoption
92%
Available for every account
Data residency
UK
UK South · UK West failover
Roles
What each role exists to do, and what it can reach
Administrator
3 usersSystem configuration, users and reference data.
- Manage users and roles
- Configure notification templates
- Maintain reference data
- View full audit trail
Compliance Manager
4 usersPortfolio-level compliance oversight and reporting.
- View every discipline and dashboard
- Approve certificates
- Own non-compliance escalation
- Export board reporting
Electrical Manager
2 usersDay-to-day operational oversight of the electrical programme.
- Manage the electrical programme
- Approve certificates
- Escalate contractors
- Rebalance QA workload
QA Officer
5 usersCertificate review, approval and escalation.
- Work the QA queue
- Raise, override and resolve findings
- Request corrections from contractors
- Hand off to manager approval
Engineer / Contractor
41 usersCertificate creation and on-site QR linking.
- Submit certificates
- Respond to findings
- Attach remedial evidence
- Link QR codes on site
Tenant
12,046 usersSelf-service certificate access via QR code.
- View own certificates
- Download own certificates
Permission matrix
Capability by role — the same rules the UI enforces
| Capability | Administrator | Compliance Manager | Electrical Manager | QA Officer | Engineer / Contractor | Tenant |
|---|---|---|---|---|---|---|
| Property record | Full | Full | Edit | View | View | — |
| Certificate repository | Full | Full | Full | Edit | Edit | View |
| QA workbench | View | Full | Full | Full | — | — |
| Manager approval | View | Full | Full | — | — | — |
| Non-compliance register | View | Full | Full | Edit | Edit | — |
| Audit trail | Full | View | View | View | — | — |
| Administration console | Full | — | — | — | — | — |
Security controls
Enterprise controls expected of a regulated provider
- Implemented
Role-Based Access Control
Every user sees only what their role permits, from tenant to executive.
- Implemented
Multi-Factor Authentication
Available for all user accounts.
- Ready
Azure AD / Microsoft Entra SSO
Built to integrate with LHP's existing identity provider.
- Implemented
Encryption
Data encrypted in transit and at rest.
- Implemented
Audit Logs
Every action logged and attributable, underpinning the Audit Trail module.
- Configurable
Password Policies
Configurable complexity, expiry and lockout rules.
- Implemented
Session Management
Automatic timeout and secure session handling.
- Implemented
Backups
Scheduled, tested backups with defined recovery points.
- Documented
Disaster Recovery
Documented recovery plan and recovery time objectives.
- Aligned
GDPR
Data handling aligned to UK GDPR requirements.
- Implemented
UK Data Residency
Hosted on UK-based infrastructure.
- Implemented
Secure APIs
All integrations authenticated and encrypted.
- Implemented
Monitoring
Ongoing security monitoring and alerting.
Posture at a glance
The numbers an auditor asks for first
- Encryption in transit
- TLS 1.3
- Encryption at rest
- AES-256
- Recovery point objective
- 15 minutes
- Recovery time objective
- 4 hours
- Last penetration test
- 12 June 2026
- Last restore test
- 3 July 2026
- Hosting
- UK South · UK West failover
Single sign-on through Microsoft Entra ID can be enabled without changing how roles are assigned — the platform maps directory groups onto the roles above.