Home / Access governance
Access governance
We govern our own access the way the platform governs your gates: named people, explicit approval, and a record of who signed.
Effective September 19, 2026 · Quest 2 Excel, Inc., dba Propelon
Identity
Access to Propelon systems runs through centralized single sign-on with multi-factor authentication. Accounts are individual — no shared credentials — and service accounts are inventoried, owned, and scoped.
Least privilege by role
Permissions are granted by role, sized to the job, and default to none for production customer data. Broad standing access is the exception we design out, not the convenience we default to.
Elevation is a gate
Production access beyond a role’s baseline is requested for a stated purpose, approved by a named owner, time-bound, and logged — a human attestation on the record with its lineage — who granted it, on what basis, for how long — exactly like a gate review in the product. When the window closes, the access closes with it.
Reviews and offboarding
Access is recertified on a schedule by the owners of each system, and removed the day a role ends. Reviews leave a record of who confirmed what, and when.
From answers to actions
As agents move from answering questions to taking actions, the central risk shifts from a wrong answer to an unauthorized action. The gate is where authority is granted, bounded and revoked — for people and for agents alike — and every grant leaves a record of who allowed what, for how long, and why.
Customer-side access
Inside the platform, customers govern their own users: role-based permissions over portfolios, gates, and value figures, with administrative actions logged. Propelon personnel access a customer environment only for support the customer requests or operations the agreement covers — and that access follows the elevation rules above.