Control follows the data
Security
Identity, permissions, audit, secrets, and environment controls for business-critical systems.
The direct answer
Security in Bondi is applied across the system’s data, screens, actions, APIs, automations, agents, and external access paths.
Operational outcomes
What changes when the system fits.
01
Give each person and process only the access it needs
02
Keep an auditable record of sensitive operational change
03
Separate human, agent, automation, API, and portal identities
Inside the system
Built around the work—not a generic template.
- Role-, action-, screen-, record-, and field-level controls
- Secret and API key management
- Audit history and service accounts
- Enterprise SSO/SCIM, IP allowlists, and dedicated infrastructure
Plan fit
Foundational role/screen/action permissions are Standard. Record/field controls and Service Accounts are Pro. SSO/SCIM is Enterprise.