Institution and branch permissions
Separate institution workspaces with multiple branches, users and explicitly scoped roles. Cross-institution and nested branch-data paths must be independently verified.
The new microfinance SaaS is being developed with server-enforced institution and branch boundaries. Production security must be demonstrated on the deployed service, not inferred from a login screen or functional test counts.
Separate institution workspaces with multiple branches, users and explicitly scoped roles. Cross-institution and nested branch-data paths must be independently verified.
No routine partner or CBSRM support access to financial, borrower or private working data. Temporary grants require institution approval, scope, expiry, revocation and an audit record.
Choose the approved hosting country and operating controls with each institution. Country configuration, currency and interface language are separate choices.
Agree the institutional identity policy and approval process, verify the hosting boundary, then evaluate scoped data import and risk workflows against documented acceptance cases.
Use approved sample inputs and a named review owner. Confirm the country, identity policy, data source and acceptance measures before enabling institution access.