# Security & control — Opelli

> Permissions, security and audit records for teams that need to know who can see what and what changed.

_Markdown edition of https://opelli.dev/features/trust — generated from the page itself on 2026-08-25._

---

[Home](https://opelli.dev/../index.html) › [Features](https://opelli.dev/index.html) › Security & control

_Area 04_

## Security & control

Permissions, security and audit records for teams that need to know who can see what and what changed.

### Ask for it — Your assistant can only use what you can access.

Connected assistants follow the user's permissions and the modules allowed for that connection. Requests outside that scope are refused.

### Access — Share the work without oversharing.

Every feature carries a permission level — none, read, write, delete — set per role or per person. Access can be limited to records from the projects a person is a member of.

![The Access console: features × roles grid with per-level pickers and an expanded 'what each level allows' capability matrix.](https://opelli.dev/../img/access.jpg)

- **Documented, not implied** — Each feature spells out what every permission level allows, right where you assign it.
- **Roles & overrides** — Admin, manager, member and guest out of the box; custom roles and per-person exceptions when you need them.
- **The guest boundary** — Customer-side guests are labelled everywhere, see only the wiki pages shared with them and can never enter CRM or Finance — no permission grant can change that.
- **Two money permissions** — What you pay someone and what you charge for their time are granted separately, so invoicing can be delegated without opening cost data.
- **Locked months** — An approved timesheet locks its month — no silent edits after sign-off.
- **Personal connections** — Scripts and assistants connect through personal, module-scoped keys that act only as their owner. Revoke any connection at any time.

### Security — Built for audits.

The commitments that matter when you buy: where your data lives, how it is protected and how sign-in works.

- **Isolated by organization** — Each customer's data is kept in a separate environment.
- **Protected in transit and at rest** — Application data and files are encrypted and processed in the EU.
- **Use your identity provider** — Sign in with Google, or Microsoft Entra under an enterprise arrangement, and keep 2FA under your control.
- **Recoverable by design** — Automated backups support recovery from accidental loss.

The GDPR machinery you'd ask about — consent records, subject requests on a 30-day clock, a map of where personal data sits — is in the product itself.

### Compliance & Audit — Everything on the record.

Two modules for the questions customers, auditors and investors eventually ask: what your legal texts say and who agreed to which version — and what actually happened here last month.

#### Compliance — Your GDPR posture, run like the rest of the company.

Terms, a privacy policy, consent texts — drafted in Markdown and published as immutable versions to a Privacy Center at your own address. The exact text someone agreed to stays reproducible forever, and old versions stay linkable.

- A consent ledger: who agreed to what, which version, when — every consent with its own withdraw link
- Data-subject requests with the 30-day clock counting down, from the public portal or logged by hand
- A locator that finds a person's email across CRM contacts, mailing lists, form responses and accounts
- "Manage my data": a private link listing someone's consents and requests — no account, no way to probe who's in the system
- Each document belongs to a project and picks the look of its public page

![A published privacy policy on the Privacy Center: the document title and version, a sticky table of contents built from its headings, and numbered sections.](https://opelli.dev/../img/privacy-center.jpg)

#### Audit — What happened, and the report of it.

Every notable thing lands in one org-wide activity log — tasks closed, deals moved, people added to projects, pages published, campaigns sent. Read it as a day-by-day stream, or render the same range as one Markdown document and mail it.

- Everyone sees their own slice, filtered by the permissions they hold and the projects they belong to
- Lose access to a project and its history goes with it, immediately
- Summaries name things, never values — no deal amounts, no phone numbers
- An admin-only security trail: roles, permission changes, keys minted and revoked
- A delivery record of everything Opelli sent, in the same stream
- The same document a connected assistant asks for when it wants to know what changed

![The Audit activity stream: events grouped by day with a module label per row, range and module filters, and a security-trail toggle.](https://opelli.dev/../img/audit.jpg)

…and the same range, rendered as one Markdown document you can copy or mail.

![The Report view: a summary with per-module tallies and tracked hours, then the detail grouped by project, above Copy markdown and Email report buttons.](https://opelli.dev/../img/audit-report.jpg)

### Signing — Counter-sign the contract they sent.

Sign a PDF with your own certificate, including one the other side has already signed — their signature stays valid, and Opelli never holds your key.

- **Their signature survives** — A signed document is only ever appended to, never rewritten, so a qualified signature the other party put on it stays intact — the check every recipient's reader makes.
- **Nothing is stored** — The document, your .p12 certificate and its passphrase travel through one request and the signed PDF comes straight back. No key ever rests on the platform, so a hijacked session has nothing to sign with.
- **Timestamped, optionally visible** — Every signature carries a trusted RFC 3161 timestamp, and you can place a "Signed by … via Opelli" mark on the page of your choice.
- **Inspect before you sign** — The screen first lists the signatures already on the document and whether each is still intact. What remains afterwards is an audit entry — the document's fingerprint and the certificate's identity, never key material.

### Ask for it — It can read the signatures. It cannot sign.

Ask your assistant to counter-sign and it checks the signatures already on the document, then hands it over: the certificate and its passphrase never pass through an assistant or the platform, so the one who signs is you.

### See it on your own operations.

Opelli runs in the cloud on an `opelli.dev` address or your own domain. Leave your email and we will show you how it fits the way your team works.

Previous

← Sales & finance

Next

AI & assistants →
