Isolation by design
Each third party's workspace is isolated from every other one: its own connected accounts, its own users, its own Security Score history. A contracting organization managing many third parties reviews them side by side without their evidence ever mixing.

Invitation, roles and scope
The responsible contact at the third party is invited by email and self-registers into the workspace. Roles and scopes then decide who can connect a new account, who can open a case, and who can only view the report.
- Invitation-based onboarding for the third party's own team
- Role and scope assignment per user in the workspace
- Every configuration change recorded in the activity log

Everything traceable
Every action inside a workspace — a new connection, a case opened, a false positive marked, a role changed — is recorded in an activity log, which is what makes the workspace defensible in front of an auditor or a committee.
