Back to home
    Security First

    Pillars of Uniportal Security

    Every layer of Uniportal is designed with security at its core. Here's how we keep your data and operations safe.

    Admin Controlled Tool Permissions

    Granular integration control

    Admins define exactly which tools and actions an Agent can access. Unused integrations stay locked, and permissions can be adjusted per role or team at any time.

    • Per-action enable/disable controls
    • Access group scoping per action
    • Role and team scoping
    • Default-deny policy
    Action
    Access GroupStatus
    Read Ticket
    Helpdesk-All
    On
    Create Ticket
    Helpdesk-All
    On
    Update Ticket
    Helpdesk-L3
    Off

    Human-in-the-Loop Oversight

    Every write action needs approval

    Every action that modifies data requires explicit human confirmation before execution. This is enforced in code, not just policy. The assistant physically cannot bypass it.

    • Mandatory approval for mutations
    • Full audit trail of decisions
    • Actions logged to ticket with ID
    • Code-enforced, not policy-based

    Assistant proposes action

    ToolEntra ID
    ActionBlock Sign-in
    ClientContoso Ltd
    Userjdoe@contoso.com
    Awaiting human approval

    Execution

    Blocked until approved

    Audit Log

    Fine Grained Access

    Permission inheritance by design

    Assistants inherit the exact permissions of the technician who invokes them. If a technician can't access a client, neither can the assistant. No escalation, no exceptions.

    • Client-level access boundaries
    • End-user level access boundaries
    • Device-level access boundaries
    • Tool-level access boundaries
    Resource
    GroupAccess
    Contoso Ltd
    All Technicians
    Fabrikam Inc
    Senior Techs
    Woodgrove Bank
    Restricted

    Assistant inherits invoking user's group permissions

    Access Token Isolation

    Credentials the agent never sees

    The agent never stores or sees raw credentials or API keys. Instead, it requests tool calls through the Uniportal backend, which validates permissions and executes the call using securely stored credentials. If the agent can't see the credentials, it can't reveal them.

    • Agent calls backend for tool execution
    • Backend validates permissions before acting
    • Credentials stored and managed server-side
    • Zero credential exposure to the agent
    Assistant requests tool callGET /tickets?client=contoso
    Backend validates permissions
    Backend executes with stored credentials
    Response returned to assistant

    Assistant never sees or handles raw credentials

    The platform

    Enterprise-grade controls, built in from day one.

    Human-in-the-Loop by Design

    The assistant cannot execute any action without explicit technician approval. Start locked down and expand autonomy as trust develops.

    SSO & Role-Based Access

    Single sign-on and granular role and group based access controls scope what each technician can do.

    Permission Inheritance

    The AI assistant inherits the permission scope of the technician driving it, scoped by customer, user, device, and action type.

    Full Audit Trail

    Every technician and AI action is logged with timestamp, actor, client context, and outcome. Nothing hidden.

    AI Chat Oversight

    Admins can review every AI chat across all technicians, to see where teams get stuck, spot training gaps, and run quality control.

    Full Agent Reasoning Traces

    Every session maintains a complete trace of the assistant's reasoning. Unexpected decisions can be fully investigated.

    Encrypted Credential Storage

    All credentials and API keys are encrypted at rest. The assistant never has direct access to secrets.

    Credential Isolation

    All tool calls route through a backend proxy that validates authorization before execution. No credentials exposed to the model.

    Multi-Tenant Data Isolation

    Client data is strictly isolated. No cross-tenant data access is possible at the application or database layer.

    Security

    Security-first by design.

    Every action Uniportal takes is scoped, approved, and logged. A human signs off on every write, and the assistant only ever inherits the permissions of the technician using it.

    Human-in-the-loop on every write
    Permissions inherited from the technician
    Credentials the agent never sees
    Full audit logs on every action
    Have a security questionnaire?
    We'll walk your team through our controls and complete your due-diligence review.