Trust

Data sovereignty

Where your data lives and who can see it is not a setting in roleALPHA but a property of how it is built. This page explains what that means in practice.

Operation

Three operating models — you choose

The control layer always runs at roleALPHA. You decide where the domain data lives — per domain, not as a blanket choice.

The boundary between domains is verified, not promised

Each domain manages only its own tables. No domain reads another's data directly — it asks through an interface, and the request carries the requester's authorisation. This rule is not merely documented: it is checked mechanically on every change to the software, and a violation fails the build.

Access has three axes

Whether someone sees a piece of information is decided in three steps: does it belong to their tenant, is it visible to them, and do they hold the permission for this action. The order is binding — a visibility check alone is not enough, because administrative roles would skip it.

The rehearsal room forms groups, not people

Rehearsing a planned announcement before you make it works on archetypes: each stands for at least five people, smaller groups are never formed and are reported as dropped instead. Names and personnel records never enter, the result has no effect back on the model and states no approval rate. The minimum size is not a setting anyone could turn down — it sits in the translator that forms the groups, and it is checked on every change to the software.

Legal

What we commit to is in writing

The following documents apply. They are published from the same body of material the software is checked against — a commitment the code does not honour shows up in that check.

Legal →

Your data, your rules.

We will show you which operating model fits your requirements.