Skip to content
Orbance
Orbance / Security

Access should be clear before it is powerful.

Orbance keeps the everyday interface calm while workspace, role, subscription and tenant context remain explicit behind it.

Access boundaries

Each surface has a different job.

Access becomes more specific as work moves from public information to authenticated and operator-controlled contexts.

Selected surface / Authenticated workspace

Staff

Tenant-scoped work behind authenticated roles.
  1. AuthenticationAuthenticated SaaS

    Workspace, subscription and tenant context are resolved after authentication before protected product work begins.

  2. Tenant scopeTenant-scoped work

    Customer data, workflows, files and permissions are treated as workspace-scoped product concerns.

  3. Role / permissionRole-led access

    Navigation and actions can reflect plan access and role permissions while server-side authorization remains authoritative.

  4. Server authorizationAuthoritative enforcement

    Interface visibility helps people understand access. Server-side authorization remains the authority.

Product design model

This trace explains intended separation and authorization principles. It is not a certification claim.

Control model

The right control at the right boundary.

These are product design and authorization principles, not certification claims.

  1. Separate public and product surfaces

    The website carries public product information. Workspace data and product state remain on the authenticated app.

  2. Authenticated SaaS

    Workspace, subscription and tenant context are resolved after authentication before protected product work begins.

  3. Tenant-scoped work

    Customer data, workflows, files and permissions are treated as workspace-scoped product concerns.

  4. Role-led access

    Navigation and actions can reflect plan access and role permissions while server-side authorization remains authoritative.

  5. Visible history

    Important product actions are designed to leave operational evidence for reviews and customer accountability.

  6. Permission-based email

    When sending is enabled, marketing safeguards keep identity, consent evidence and unsubscribe suppression connected to each campaign.

Email safety

Responsible sending is an operating control.

Orbance links sender identity, permission evidence, unsubscribe suppression and complaints to the sending workspace.

Review responsible email