Three ways in
Password, Google, or Microsoft. Single sign-on honours the same multi-factor requirements as a password login. An identity provider is not a way around your own policy.
Every restriction in VCMS is enforced by the API that serves the data. The console reflects those rules; it does not implement them, and it cannot be talked out of them by anybody with a browser console open.
Append-only and hash-chained. A verify run reports a failed check differently from a broken chain, because conflating them either raises a false alarm or hides a real one.
80 granular capabilities across 9 console roles. Routes gate on the permission, so an organisation can move a capability between roles without a code change and without a route quietly staying open.
These are the roles in the product. Every one of them is a permission set you can edit. The names are a starting point, not a constraint.
Contractors and visitors are not console roles. They reach the system through invitation links and a self-service portal with its own, much narrower, authorisation.
Multi-factor that does not punish somebody for using the same laptop every day, and does not wave through a session appearing from somewhere new.
Password, Google, or Microsoft. Single sign-on honours the same multi-factor requirements as a password login. An identity provider is not a way around your own policy.
A verified device on a known network is not challenged again for 24 hours. A different device, or the same device on a different network, is challenged again.
Ending a session or resetting somebody’s MFA revokes every trusted device with it, so a lost laptop is one action rather than a hope.
Append-only was a property of how the code happened to behave. It is now a rule that something enforces, which is a different claim.
Every consequential action is written to a hash-chained log. Each entry chains to the hash before it, and a verify endpoint answers whether the chain is intact. It reports a failed check differently from a broken chain, because conflating the two either raises a false alarm or hides a real one.
The subtle part is deletion. A chain where each row references the previous hash value survives having a row removed: the surviving links still line up. So append-only is enforced at two levels rather than assumed, and a missing afternoon is detectable.
The log exports to CSV, and read access to it is itself a permission. The auditor role holds it and holds almost nothing that writes.
Password, Google or Microsoft, with multi-factor that remembers a device for a day.
59 branded message templates, with the channels for each under your control.
Say how long you keep personal information, and have the platform actually do it.
Send events where your organisation already looks.
VCMS carries a residency register: for a running deployment it computes which services are carrying data where, and can refuse egress to a destination outside the region you declare. That is a real, checkable mechanism. It is not the same as a finished guarantee. Where a deployment depends on a third party that cannot be pinned to your region, the register names it rather than glossing over it. We would rather show you that register than make a claim you cannot verify.
We would rather answer it against the actual mechanisms than send back a document. Ask about the parts that are not finished, too.