Mensara checks who is asking and what they want to do before it opens anything in your Mind.
Person or agent asks
who they are and what they want
Check their access
zone and action
Show or change it
only when allowed
Refuse and record
who asked, the action and the zone
What a zone is
Zones keep different parts of the company separate. Payroll can sit in Finance, interview notes in Hiring and account plans in Customers.
People see the zone names. They don't need to know where the files sit on the server.
One account for each person
Every team member signs in with their own account. Their connected agents work within that person's access, never more.
That lets your Mind record who asked for information or tried to change it.
Choose what they can do
Reading a zone, suggesting a change and approving a change are separate permissions. You can let someone read Finance without letting them change it, or let them suggest changes that someone else approves.
Save it as an access profile. A Sales profile, for example, gives everyone on the sales team the same access to customer information.
When access is refused
Mensara checks access in software before a file is searched, read or changed. No model decides who sees what.
Searches leave out zones a person can't read. A direct request for a protected file is refused and recorded. The record shows who asked, what kind of action it was, the zone and that it was refused. It doesn't store the request text or the protected information.
Related
Practical guides for people and agents