Security
MarginTrace connects to production revenue, product, cost, and support systems. These are the controls that apply to that access.
Least-privilege connections
Every connector requests the narrowest scope that supports the advertised result. Help-desk access begins read-only. Write access is granted per action and only after an authorized user approves it.
Workspace isolation
Connected records, identity maps, and computed outputs are scoped to the workspace that connected them. Row-level access rules are enforced in the database, not only in the application.
Support Operator separation
Support Operator runs on a separate application and database from the analytics products. It has separate help-desk OAuth credentials, connector secrets, action-policy engine, ticket content, audit events, usage meter, and permissions. Only aggregate commercial events enter the shared marketing analytics layer.
Audit trail
Every automated resolution retains retrieved sources, account observations, tool calls, policy decisions, confidence, the final response, and any human correction. Every analytics change retains the rule, the operator, and the timestamp.
Emergency stop
Support Operator exposes a persistent control bar with mode, eligible issue classes, allowed actions, confidence threshold, escalation owner, and an emergency stop that halts automated responses immediately.
Reporting a vulnerability
Send findings to security@margintrace.com.